
Modern software isn’t built, it’s assembled. A typical enterprise application contains hundreds and sometimes thousands of third party components, and every open-source library, container base image, language runtime and build tool is a potential attack vector.
Modern applications rely on third-party libraries for 79% of their code. SBOMs alone are not enough, attestations are crucial for ensuring software integrity.
OpenSSF Summit 2025
Every deployment needs cryptographic proof that what you are shipping is exactly what you think you are shipping, unchanged and uncompromised from source through to production. The harder problem is not knowing what is in your software, or even proving it has not been tampered with, it is using that knowledge to make decisions in real time. Every component needs verification, and every test suite needs attestation.
GREEN MEANS GO! Complex security, simple decisions
Deploying software is a business decision. We can protect your supply chain, but we also need to think about the people making the call.
Your developers want to ship features, not become encryption experts. Your managers need to approve releases, not validate signature chains. So instead of examining cryptographic certificates, approvers get clear visual confirmation that every security requirement has been met. Green means go.
Behind that interface we are continuously validating cryptographically signed SBOMs for complete component transparency, build provenance proving artifact integrity and origin, real-time vulnerability scanning against multiple CVE databases, digital attestations meeting NIST SSDF and SLSA requirements, and certificate chains verified through Sigstore’s transparency logs.
If any check fails you see red, and the deployment stops. No ambiguity and no exceptions.
75% of organisations experienced a supply chain attack in 2023 to 24, at a global average cost of $4.4M per breach.
Approvers are shown only what they need in order to decide, and they can click into any attestation to read it in full or pull it for local validation. Guardrails in the portal will not allow a workload to be merged if it does not meet the required standard.
The same protection, everywhere
These are not just visual indicators for human approval. The identical cryptographic requirements that power that interface enforce themselves programmatically at your cluster boundaries, where Kyverno policies consume the same attestations, verify the same signatures, and apply the same standards automatically and continuously.
What you see in the portal is what protects your production. There is no gap between approval and deployment, and no window in which something could be substituted between a human review and the automated enforcement that follows it. One consistent posture from development through to production.
Provenance, and why it is about to matter more
Provenance is the mechanism underneath all of it. Each continuous integration step produces an attestation, the portal produces a human approval attestation, and when ArgoCD updates the cluster the Kyverno policy engine pulls the SBOM and the attestation suite for the updated workload and validates the set cryptographically.
The industry has the tools for this. SBOMs give you inventory transparency across every dependency, digital attestations create tamper-proof records of your build process and your security checks, and cryptographic signatures chain those artifacts together into a custody chain from commit to deployment.
What is changing is that being able to produce that chain is moving from good practice toward obligation. In July 2026 the Commonwealth announced an Office of AI inside the Department of the Prime Minister and Cabinet, along with a mandatory national standard for artificial intelligence intended to be legislated. National Cabinet is considering the approach, and the detail is still being designed, so nobody can honestly tell you today exactly what the obligations will be.
The direction, though, is not ambiguous. It is mandatory rather than voluntary, it is being drawn as a single framework rather than sector by sector, and it reaches into what models are trained on and where they run.
Organisations that already hold provenance for their software, their models and their prompts will be able to answer those questions when they are asked. Organisations that do not will be starting a discovery project under time pressure. We would rather you were in the first group, and the work is the same work either way.
The number of attacks detected in software supply chain doubled again in 2024, indicating that our industry is mainly defenceless against these growing risks.
Sonatype State of the Software Supply Chain
Assurance for inference
The same chain of custody thinking applies to machine learning, and almost nobody is applying it yet, but we have been building a standard for precisely this for some time. Models and prompts are artifacts like any other, and they deserve the same provenance, the same signing, and the same visibility as the code that calls them. We have created a standard in CycloneDX to support cyber security investigations, we expect our standard to become the benchmark for court ready evidence preparation in the Lachine Learning age.
This matters more as local inference moves closer to the things you actually care about. A model you cannot account for is a dependency you cannot account for. And we’ve been thinking about this problem since the beginning.
Green Means Go
Approvers get a clear visual answer, while the cryptography happens underneath.
Verified At The Boundary
The same attestations your people approve are enforced automatically by policy at your cluster edge.
Proven at enterprise scale across Energy, Banking and Cyber Security, and running today in our own products.
