CI/lock
Write CI/lock in prose. Use cilock only for the CLI, package names, and URLs. Use the white mark on dark surfaces; keep the original navy and cyan mark on light surfaces.
Brand assets, logos, and resources for media and partners.
Everything you need to represent TestifySec accurately.
TestifySec is the platform for developer and agent trust.
TestifySec helps engineering teams verify the work behind human- and AI-written code. CI/lock records evidence, Pushgate checks repository pushes, and the platform manages gates and technical control evidence across the team.
TestifySec helps engineering and platform teams set requirements for software changes and inspect the evidence behind them. CI/lock captures signed evidence from existing builds, tests, and scans. Pushgate requires evidence before a push enters a repository through the gate. The TestifySec Platform manages repository gates, policies, identities, and evidence, and connects technical test results to compliance controls. Teams can also discuss running the platform in their own environment with the software appliance.
Signed execution evidence, repository gates, and technical control mappings built on open attestation standards.
CI/lock is TestifySec’s enterprise attestation tooling, built on the in-toto™ specification. Pushgate checks evidence at the Git push boundary. The platform manages gates and helps reviewers trace technical assessments to their source evidence.
CI/lock records configured development and CI workflows as signed attestations. Pushgate evaluates required evidence before accepting a push through its gate. The platform manages repository gates and their policy assignments, keeps evidence available for inspection, and maps scoped technical test results to compliance controls. Recovery rehearsals, remediation checks, and configuration tests can support an assessment; a passing check does not by itself establish compliance.
Help teams establish trust in software changes through verifiable work, clear requirements, and evidence they can inspect.
Developers and AI agents can produce changes faster than teams can review the work behind them. Teams need a consistent way to require evidence, inspect decisions, and demonstrate the technical controls they operate.
TestifySec was founded by Cole Kennedy and Frederick Kautz. The team contributes to open-source attestation tools and software supply-chain standards.
Engineering and platform teams shipping human- and AI-written code, including organizations that need technical control evidence or deployment within their own environment.
Capture the work.
Capture signed evidence from builds, tests, and scans on your compute or hosted infrastructure.
Check the push.
Require evidence before a push enters your repository through the gate.
Manage gates. Reuse the evidence.
Manage repository gates and connect technical test results to compliance controls.
Run the platform in your environment.
A software deployment option for the TestifySec Platform. Plan identity, storage, network access, availability, and support with the team.
Open-source attestation tooling
Witness creates and verifies signed software supply-chain attestations using the in-toto specification. It is an open-source project within in-toto.
Open-source attestation storage
Archivista stores and retrieves software supply-chain attestations, helping verifiers discover evidence for an artifact.
The product family
Use the official product identities wherever a product is named. Capability icons explain what it does; they do not replace its logo.
Write CI/lock in prose. Use cilock only for the CLI, package names, and URLs. Use the white mark on dark surfaces; keep the original navy and cyan mark on light surfaces.
Write Pushgate in prose. The official outlined wordmark reads Pushgate.dev; keep it unchanged. Use the supplied dark-surface variant rather than recoloring the artwork.
Use the full mark at 32 px or larger. Use the supplied small version below that size. The detailed kit includes clear-space and lockup-spacing specifications.
#000066Brand identity and links
#FFA624Restrained emphasis and primary actions
#020617Header and dark surfaces
#0F172AHeadings and primary text
#475569Supporting text
#FFFFFFContent surfaces and text on dark backgrounds
Primary font for headings and body text
Light 300
Regular 400
Medium 500
Bold 700
Monospace font for code and technical content
Regular 400
const evidence = “verified”;Complete brand identity guide
Company overview and key benefits
Remote Software Updates in Contested Environments
Coming SoonDeveloper and agent trust platform details
Coming SoonOpen source attestation framework
Attestation storage system
Coming SoonIf you need additional assets, have questions about brand usage, or require custom materials, please reach out to our team.
Contact Design Team