Skip to main content
View Markdown ↗

Copy this page

Select and copy the Markdown below, then paste it into your LLM.

Run the platform in your environment

Follow a local appliance from first sign-in to signed test evidence and offline verification.

Jump to the written guide ↓

Follow along

Goal: start a local evaluation appliance, sign in, and record evidence against its configured trust services. This guide covers a local evaluation, not a production deployment. Authentication attributes a session to a principal; it does not prove physical biometric presence.

Before you start

Obtain the release archive for your operating system and a valid license through your TestifySec account. Verify the downloaded archive against its published release metadata. Read the deployment requirements before choosing storage, network, or identity settings.

The following commands assume a POSIX shell and an extracted archive containing judge-api and .env.example. On Windows, use the release's PowerShell instructions. Use the supported release and license provided for your evaluation.

1. Configure persistent local state

In the extracted archive, create the configuration once:

cp .env.example testifysec.env

Edit testifysec.env to set your license path and a writable persistent directory:

ENTITLEMENT_LICENSE_PATH=./your-license.json
STANDALONE_DIR=./judge-data
SELF_HOST_MINIMAL=true

Replace your-license.json with your actual file name. Keep both the license and the data directory out of source control. Without a persistent directory, the standalone temporary state is deleted on exit.

2. Start the appliance

./judge-api serve --standalone

Expected: startup succeeds and prints the local application URL. Keep the process running. Open that URL in your browser; do not expose this local evaluation endpoint directly to the internet.

3. Provision your administrator

In another terminal in the same directory, create a private password file using your password manager or editor. Restrict access to it, then replace the example email and name below with your own:

chmod 600 admin.pw
./judge-api bootstrap-admin \
  --email [email protected] --name 'Your Name' \
  --password-file admin.pw

Expected: the administrator is created. Sign in through the application and complete the identity setup offered by your release. Remove the temporary password file after provisioning according to your workstation's secret-handling policy.

4. Connect CI/lock

Use the exact origin printed at startup. For the default loopback evaluation endpoint:

cilock login --platform-url http://localhost:8080

Complete the browser approval as the intended user. An autonomous agent must use its own approved enrollment flow; it must not borrow the administrator's session. A session-bound credential does not prove that a human personally ran a subsequent command.

5. Record work and verify it

In a disposable Go repository with tests:

cilock run --platform-url http://localhost:8080 \
  --step test -o tests.json -- go test ./...

Expected: the command runs and produces an evidence envelope. Review the stored evidence in the appliance when storage is configured. To reproduce the final policy-verification portion, follow the policy walkthrough with your own policy signer and trusted roots.

Troubleshooting and cleanup

An invalid license or unwritable state directory must be fixed before continuing. Do not solve a certificate error by disabling TLS verification. Stop the foreground process with Ctrl+C when finished; retain the configured state directory if you want the same identities and evidence after restart. Review production TLS, backup, restore, and update procedures separately before using real workloads.

Browse the other walkthroughs