Collect and verify
Witness
Capture metadata about a workflow and verify attestations against a policy using the in-toto specification.
Open source
Our work starts with open formats and shared tooling. TestifySec created Witness and Archivista to collect, store, and verify software supply chain attestations.
The projects
Collect and verify
Capture metadata about a workflow and verify attestations against a policy using the in-toto specification.
Store and discover
Store attestations and make them discoverable so a verifier can retrieve the evidence associated with an artifact.
An open specification
in-toto describes a framework for recording and verifying steps in a software supply chain. It separates the evidence of what happened from the policy that defines what should happen.
CI/lock is TestifySec’s enterprise attestation tooling, built on the in-toto specification. The platform and Pushgate bring evidence into your team’s policy and repository workflows.
Research and standards
Read the NIST and CNCF publications our team contributed to, alongside the in-toto project resources.
Read the publications ↗Put it to work
Record your first attestation or explore how a repository gate uses evidence.