Skip to main content

Product reference

Explore the technical details.

Capabilities, example workflows, and integration foundations.

Back to features ↗

55 matching entries

Workflow examples use your tests and configured mappings. Tool and framework support depends on deployment and version.

Gates & policy

Set the requirements. Put them at the right checkpoint.

Platform

Multiple repository gates

Manage Pushgate connections across repositories from a shared control plane.

Platform

Versioned policy releases

Keep the exact signed policy release behind an evaluation or gate assignment.

Platform

Scoped policy bindings

Assign requirements to the relevant products and repositories.

Platform

Separate approval and activation

Keep policy publication separate from a human approving its gate assignment.

Pushgate

Checks before a push is accepted

Evaluate evidence when Git pushes pass through Pushgate, before forwarding them to GitHub.

Pushgate

Block and Warn modes

Choose enforcement or visibility for a configured repository connection.

Pushgate

Actionable refusal details

Show developers and agents which requirements need attention when a push is refused.

CI/lock

Local policy verification

Verify collected evidence against policy before it reaches the gate.

Evidence collection

Turn everyday engineering work into verifiable records.

CI/lock

Wrap existing commands

Capture evidence from builds, tests, scans, and scripts run on your compute or hosted infrastructure.

CI/lock

Signed attestations

Package execution evidence in signed, open in-toto and DSSE formats.

CI/lock

Keyless signing

Use supported identity-backed signing flows instead of distributing long-lived signing keys.

CI/lock

Trusted timestamps

Attach trusted signing-time evidence to support later signature verification.

CI/lock

Artifact and source binding

Associate evidence with the specific materials and subjects observed during the run.

CI/lock

Test and build evidence

Capture results from your existing test suites and build commands.

CI/lock

Security tool evidence

Collect results from supported vulnerability, secret-detection, and security-scanning tools.

CI/lock

SBOM and dependency evidence

Bring supported software bill of materials and dependency scan outputs into the evidence record.

CI/lock

Execution tracing

Inspect supported process, filesystem, and network observations from a run. Tracing capabilities depend on the host.

Evidence management

Keep a traceable path from a decision to its proof.

Platform

Shared evidence storage

Collect signed attestations from developer environments and automated workflows in one place.

Platform

Product and repository context

Review evidence in the context of the software and repository it belongs to.

Platform

Attestation inspection

Inspect signed subjects, predicate details, signatures, and associated metadata.

Platform

Policy evaluation records

See which requirements the supplied evidence satisfied and which failed.

Platform

Signed verification summaries

Retain signed verification summary attestations for policy evaluations.

Platform

Traceable evidence references

Follow an evaluation or control record back to its supporting attestation.

Technical assurance

Connect technical tests to the controls they support.

Platform

Policy-to-control mapping

Link a policy’s evaluation results to one or more controls in a selected catalog.

Platform

Control evidence views

Review the policies, per-product and per-repository verdicts, and attestations supporting a control.

Platform

FedRAMP 20x KSI mapping

Connect relevant technical evidence to Key Security Indicators using versioned framework mappings.

Platform

NIST control catalogs

Organize supporting evidence against controls from the configured NIST catalog.

Platform

Explicit evidence gaps

Distinguish a passing evaluation from a failed check, an unevaluated policy, or a control with no bound evidence.

Platform

Current-branch context

Keep inactive bindings and results from older or different branch heads distinguishable in control views.

PlatformWorkflow example

Vulnerability remediation verification

Map a signed rescan or remediation check to the controls it supports, with the tested scope retained.

PlatformWorkflow example

Disaster recovery rehearsal evidence

Map signed recovery-test results to relevant recovery controls and KSIs.

PlatformWorkflow example

Configuration verification evidence

Connect signed checks of configuration and drift to relevant control evidence.

Change impact

Keep the connection between code and controls visible.

Platform

Control watchpoints

Mark the repository paths, patterns, or code locations that a control depends on.

Platform

Changes that affect controls

Surface pull-request changes touching configured watchpoints for review.

Platform

Watchpoint context

Retain the label, reason, repository location, and linked controls behind a watchpoint.

Platform

Stale watchpoint visibility

Show when a line-based watchpoint needs review after its underlying code changes.

Identity & signing

Know who signed, what they can do, and what was observed.

Platform

Agent principals

Enroll agents with explicit identities rather than treating an observed tool name as authentication.

Platform

Scoped credentials

Limit service credentials by purpose, audience, and authorized scope.

Platform

Credential lifecycle

Manage agent access with credential expiry and revocation.

Platform

Workload identities

Support authenticated automated workflows through configured workload identity and signing flows.

Platform

Identity-backed signing services

Provide certificate issuance and timestamping services for supported signing workflows.

Platform

Distinct trust roles

Keep evidence signers, policy publishers, gate activation actors, and push signers distinguishable.

Tools & open foundations

Fit into the workflow your team already uses.

CI/lock

Developer and CI environments

Run supported checks on your compute or hosted infrastructure, including GitHub Actions, RWX, and Namespace; validate the selected runner and capture mode.

Pushgate

Git workflow integration

Use the Git push boundary as the enforcement point for connected GitHub repositories.

CI/lock

Existing security tooling

Use supported attestors and command execution to bring your current scanning tools into the evidence workflow.

CI/lock

Open attestation formats

Produce evidence based on in-toto and DSSE for machine-readable verification.

Platform

Platform APIs

Connect supported platform workflows through its API surfaces.

Platform

Versioned framework catalogs

Keep control identifiers and mappings tied to their source catalog.

Cloud & appliance

Choose where your evidence control plane runs.

Platform

TestifySec Cloud

Use the hosted platform for a shared team workspace.

Appliance

Self-contained software appliance

Run the platform UI, API, workflows, evidence storage, and signing services as one application.

Appliance

Local evidence storage

Keep appliance data on your host, with a configured persistent data directory.

Appliance

Local identity setup

Use an admin-provisioned deployment without requiring an external identity provider or email service.

Appliance

Offline license verification

Verify the appliance’s signed license locally without a license phone-home requirement.

Appliance

Multiple operating systems

Packages for Linux x86-64 and ARM64, macOS Apple silicon, and Windows x86-64.

Appliance

Single-host evaluation

Run the Platform as a container, single binary, VM image, or AWS Marketplace instance. Plan capacity and availability for your environment.