BenefitsCLI docsRoadmapOptions

Software traceability for regulated industries

You are accountable for your software.Back it up with verifiable evidence.

An audit, an incident, a supplier delivery: you need to explain how a software version was produced. Attest generates a signed receipt linking declared files, build steps and the delivered software. Your quality teams, security teams and auditors get a record they can check for integrity.

Start with one critical release, your technical team and the people responsible for reviewing it.

Evidence travels with your software

  1. 01Recorded build
  2. 02Signed receipt
  3. 03Independent review

The receipt links the build to the delivered software. Its integrity can be checked offline.

  • Prepare for audits with receipts produced alongside your releases.
  • Give customers and auditors a signed record they can check.
  • Verify receipts offline using approved trusted keys.

From release to evidence

Evidence your teams produce and a third party can check.

  1. 01

    Define the scope

    Your teams select a release and declare the files and steps to record within the existing build process.

  2. 02

    Record the build

    Attest records the steps, their results and fingerprints of declared inputs and outputs during execution.

  3. 03

    Sign the receipt

    With signing enabled, Attest seals this information in a receipt to keep with the release and include in your audit file.

  4. 04

    Verify the evidence

    The recipient checks receipt integrity using keys they approve. The review relies on trust in the signer and the build environment.

For your decisions

Evidence to support your release decisions

IT, security and quality leaders: work from a shared record to review a delivery, investigate a discrepancy and respond to an audit request.

Prepare your audit file

Keep a signed receipt with each release, recording the steps and fingerprints of declared files. Your teams can retrieve this evidence without reconstructing the history from scattered logs.

Investigate differences between versions

File fingerprints let your teams compare declared files across runs. An optional check runs the pipeline twice and compares the results to test reproducibility.

Verify in isolated environments

With the receipt and approved trusted keys, a reviewer can check the signature offline, without access to your build platform or an Attest service.

Document supplier deliveries

Request a receipt alongside delivered software and compare its fingerprint with the recorded one. in-toto export lets you pass provenance records to your partners’ compatible tools.

Sectors

When a release carries real accountability

An audit to prepare for, a version to accept, an incident to investigate: Attest serves organisations that need to document how their critical software was built.

Banking and insurance

Your IT leadership needs to document changes to a critical service, including supplier deliveries. During an audit or incident, identifying the version and its build history becomes a priority.

A signed receipt links declared steps and files to the delivered version. It provides a traceability record to accompany your approvals and change controls.

Healthcare and medical devices

Your quality team is preparing the file for a software version or model intended for a medical device. It needs to connect that version to retained build records and checks.

Declare the software, model and test reports as pipeline outputs. The receipt records their fingerprints to document the version reviewed in your quality file.

Defence

You accept a supplier delivery in a restricted environment. Your teams need to examine its provenance records without opening their network to an external service.

Transfer the receipt and approved keys under your own procedures. Verify the signature on an isolated workstation, without access to the supplier’s system or an Attest service.

Energy and critical infrastructure

Your operations leadership needs to retain software version records for installations with long service lives. Maintenance or an incident may require tracing their origin.

Keep each version’s receipt in your document management process. Recorded fingerprints and steps provide build traceability even after the original platform has changed.

Aerospace and embedded systems

Your programme lead needs to document the binary delivered to the customer and the materials used to build it. Multiple teams and subcontractors contribute to the delivery file.

Attach a signed receipt recording fingerprints of declared source files, configuration and outputs. It complements the records reviewed by your quality teams and customer.

Evaluate Attest

Start with a release that matters

Choose the software to trace, the records to produce and who will check them. Use this scope to evaluate Attest before expanding its use.

Technical evaluation

A focused scope

Your teams can add the CLI to an existing step and produce a first signed receipt. The public reference describes commands for signing, key management and verification.

Explore the integration path

Business use

Commercial licence

Discuss your environment, evidence requirements and usage terms with us. The repository licence covers non-commercial use; commercial use requires a separate licence.

Discuss your scope

Which release do you need to account for?

Start with an upcoming audit, critical software or a customer requirement. Identify the evidence needed and an initial scope to evaluate with your teams.

We will use your address to contact you about Attest.