Verifiable software lifecycles

Ship software you can prove.
Not just software you trust.

DevSecOps tells you a pipeline ran. TrustOps proves what it did. Every build, test, approval and deployment is signed inside trusted hardware, chained into a tamper-evident ledger, and verifiable by anyone you hand the evidence to — auditors, regulators, insurers, customers.

Built on open standards
in-toto SLSA Sigstore SPDX CycloneDX TPM 2.0 RFC 3161 OpenPolicyAgent

The problem

Every security tool makes your pipeline stricter. None of them make it provable.

Scanners, gates and dashboards produce claims. When an auditor, a regulator or a customer asks you to demonstrate what ran, who approved it and what went into the artifact, all you have is a screenshot and a log that anyone with write access could have edited.

TrustOps · verifiable development & operational processes

From commit to evidence

Three steps. Minutes, not audits.

Instrument once, attest on every run, verify whenever anyone asks. No change to how your engineers work.

1.Instrument

Point TrustOps
at your pipeline.

GitHub Actions, GitLab CI, Jenkins, Argo — one connector per pipeline. We read job metadata and write attestations. We never see your source, and signing keys never leave your hardware.

Connectors 4/5 active
GitHub Actionsorg/payments-api · 6 workflows
connected
GitLab CIgroup/ledger-core · self-managed
connected
Jenkinsbuild.internal · 42 agents
connected
HashiCorp Vaulttransit engine · key custody
connected
Slack#releases · #compliance
Connect
2.Attest

Every step signs
itself, as it runs.

Each job emits a signed in-toto statement bound to a hardware root of trust and anchored in an append-only transparency log. Nothing is written after the fact, and nothing can be rewritten later without breaking the chain.

Evidence stream payments-api · v4.12.0
09:41:02commit 4a91c2e received · 2 signatures ok
09:41:04enclave attested · Intel TDX quote valid
09:43:19build complete · reproducible digest match
09:43:26SBOM signed · SPDX 2.3 · 412 components
09:44:51policy dora-art28 awaiting sign-off
09:47:03signed off · @m.ruiz gate passed
09:47:08anchored in transparency log · entry 1,284,551
Awaiting next event
3.Verify

Hand over proof,
not paperwork.

Export a signed evidence bundle, or let an auditor verify it themselves with the open-source CLI. Verification is offline, deterministic and needs no access to your systems — and no trust in us.

auditor@ext — trustops verify
$ trustops verify payments-api@v4.12.0 --bundle evidence.tar.zst resolving attestation chain… 7 statements source commit 4a91c2e signature valid TDX quote measurement matches golden value artifact digest sha256:9f2c41ab…5a10cf37 SBOM integrity 412/412 components resolved policy dora-art28 14 controls · signer @m.ruiz log inclusion entry 1,284,551 · witnessed ×3 VERIFIED chain intact · 0 gaps · offline check in 1.9s
Verification
fully offline
Evidence formats
in-toto · DSSE · SPDX · CycloneDX
Retention
your storage, your keys

The platform

Four guarantees, end to end.

Current DevSecOps practices improve security but stop short of evidence. Each pillar closes one half of that gap.

I

The evidence

Cryptographic verifiability

Tamper-proof evidence collected with trusted hardware and modern cryptography. Every action is signed at the moment it happens, not reconstructed afterwards.

II

The chain

Unbroken provenance

Source, build, dependencies, tests, approvals and deployment link into a single chain. A missing link is as visible as a forged one.

III

The policy

Compliance as code

Encode regulatory controls as machine-checked gates. Releases that fail a control never ship, and the ones that pass carry the proof with them.

IV

The audit

Continuous assurance

Trust is measured continuously instead of once a year. Auditors, insurers and customers query live evidence rather than requesting a point-in-time report.

Hardware anchored

Proof has to start somewhere physical.

A signature is only worth the key behind it. TrustOps binds every attestation to a hardware root of trust — a TPM, a confidential enclave, or a transparency log — so evidence cannot be forged by anyone who merely has write access.

Roots of trust

Pick where the proof comes from. Or let TrustOps decide.

Evidence is only as strong as the hardware that signs it. Pin a root of trust per environment, or let TrustOps select the strongest one available on each runner.

01 Auto

Strongest available root, zero configuration.

02 TPM 2.0

Discrete TPM measured boot on your own runners.

03 Confidential VM

Intel TDX or AMD SEV-SNP with remote attestation.

04 Keyless

Sigstore OIDC identities with transparency-log anchoring.

Root selection live
08:12runner eu-west-1-a capabilities probed
08:12TDX available · selected · fallback TPM 2.0
08:12quote verified against Intel PCS ok
08:13signing key bound to measurement · non-exportable
Awaiting next event

Strong by default.

TrustOps probes each runner, picks the strongest root of trust it can attest to, and records which one it used. Downgrades are logged as policy events — never silently accepted.

Attestation overhead
< 900ms per job
Key custody
TPM · HSM · Vault transit
Deployment
SaaS · VPC · on-premise

Where it lands

Built for the industries that have to show their work.

Finance Healthcare Government

Regulated industries

Automate audit trails for financial, health and public-sector systems. Satisfy DORA, NIS2 and CRA obligations with cryptographic proof instead of documentation about documentation.

CI/CD Supply chain SBOM

DevOps toolchains

Add verifiability to the pipelines you already run. Every build, test and deployment is signed and auditable — so a supply-chain question becomes a query, not an investigation.

Risk Underwriting Assurance

Cyber insurance

Give insurers and auditors a measurable, evidence-backed security posture. Price risk on observed practice rather than a questionnaire filled in once a year.

Pricing

Start free. Scale when the auditors do.

No per-attestation metering. No charge for handing evidence to a third party. Verification is open source and always free.

Starter

Freeforever

For small teams putting their first pipeline under evidence.

Get started
  • Up to 5 team members
  • 1 CI/CD connector
  • Keyless signing (Sigstore)
  • Open-source verifier CLI
  • Community support

Enterprise

Customannual

For organisations with sovereignty and custody requirements.

Book a call
  • Everything in Pro
  • On-premise or VPC deployment
  • HSM key custody
  • SAML SSO + SCIM
  • Custom SLA & dedicated engineer

Get started

Stop promising trust.
Start handing over proof.

Tell us which pipeline hurts most at audit time. We will show you what its evidence chain looks like within a week.