Skip to main content
← Resources

Open source

Evidence you can inspect.
Foundations you can build on.

Our work starts with open formats and shared tooling. TestifySec created Witness and Archivista to collect, store, and verify software supply chain attestations.

The projects

Capture the record. Make it available for verification.

Collect and verify

Witness

Capture metadata about a workflow and verify attestations against a policy using the in-toto specification.

Store and discover

Archivista

Store attestations and make them discoverable so a verifier can retrieve the evidence associated with an artifact.

An open specification

Built on in-toto.

in-toto describes a framework for recording and verifying steps in a software supply chain. It separates the evidence of what happened from the policy that defines what should happen.

CI/lock is TestifySec’s enterprise attestation tooling, built on the in-toto specification. The platform and Pushgate bring evidence into your team’s policy and repository workflows.

Research and standards

The thinking behind the tools.

Read the NIST and CNCF publications our team contributed to, alongside the in-toto project resources.

Read the publications ↗

Put it to work

Start with a real workflow.

Record your first attestation or explore how a repository gate uses evidence.

Find your starting point ↗