BenefitsCLI docsRoadmapOptions

Roadmap

Attest capabilities and next steps

Review the capabilities recorded in the product and planned work to prepare your evaluation. Your teams will need to validate the usable scope in your environment.

5milestones implemented

Source inventory dated 14 September 2026. CLI version 0.1.0.

Detailed status in the dashboard

Implemented(5)

01

amber-drift

Every run becomes a reproducible fingerprint.

  • Step-by-step DAG pipeline execution
  • BLAKE3 hashing of declared inputs and outputs
  • Content-addressed local cache

02

paper-moon

The signed receipt, verifiable without going through us.

  • Ed25519-signed pipeline receipts
  • Trust store and offline verification
  • Wrap mode and execution capsules

03

copper-dawn

Your proofs travel across the ecosystem.

  • in-toto import and export
  • Image signing and verification
  • export, import and image commands

04

echo-garden

The hosted dashboard, isolated per organization.

  • Hanko login: PKCE, state, nonce, encrypted sessions
  • Organizations and memberships persisted in PostgreSQL
  • Member administration and audit trail

05

silver-dune

Documented paths to prepare integration and operations.

  • User, administrator and developer paths
  • Website and technical guides in English and French
  • Export validated in continuous integration

In progress(1)

06

neon-harbor

The HTTP service that will expose receipts.

  • Go server, configuration and health routes
  • Version route and optional OpenTelemetry tracing
  • Receipt and key ingestion contracts

Planned(7)

07

velvet-orbit

Receipts and keys, scoped to each tenant.

  • Organization-scoped API authentication
  • Receipt and key ingestion and retrieval
  • Receipts and Trust screens wired to those endpoints

08

opal-rain

Kubernetes, GitOps and policies qualified.

  • GitOps, Kubernetes, policy and monitoring modules
  • CRDs and Helm chart
  • OPA and Gatekeeper qualification

09

quiet-comet

Signed binary distribution.

  • Publication through Trunx
  • Signed download path
  • Publishing from the CLI, local verification staying independent

10

hollow-sun

A third party attests the date, not the machine that ran the job.

  • RFC 3161 client, token carried by the receipt
  • Configurable timestamping authority
  • Token checked offline

11

glass-ocean

The causal root published beyond your own reach.

  • Root published to a transparency log
  • Inclusion proof a third party can check
  • Rewrites of the local journal become visible

12

ember-sky

The signature bound to an entity, not to an anonymous key.

  • Keyless signing through OIDC and a short-lived certificate
  • X.509 path for internal PKI
  • Signer identity carried by the receipt

13

distant-bloom

Evaluate seal, timestamping and preservation services with a qualified provider.

  • Qualified trust service provider
  • Long-term preservation of evidence
  • Conformity and audit file