Skip to main content
The evidence your governance requires — signatures, change records, named approvals — arrives per release, instead of being assembled by your team every week.
Rung. The smoke receipt is what that procedure produces, but no audio has reached the pipeline in any delivery run yet, so no receipt on record carries a segment count from a real capture — what’s proven, and where.

Framework mapping

Mapping, not legal advice; your compliance function owns the interpretation.
  • Change management (ISO 27001 A.8.32, SOX ITGC, PCI DSS) — the evidence bundle plus the two approval records, machine-collected per release.
  • Software integrity (NIST SP 800-53 SI-7, SSDF) — digest pinning and signature verification at admission, by your own policy engine.
  • ICT third-party risk (DORA, EBA outsourcing, NIS2) — a contracted provider with incident support, exit clarity, and the telemetry rung your side sets. Everything you run is open source and your evidence verifies offline, so exit leaves you with working software and records.
  • Air-gapped networks — releases, evidence and signatures move as OCI content through your own mirror (what is proven).
Evidence kinds that do not yet exist are declared absent, with reasons, inside each signed entry — today, per-image build attestations. Next: Verify · The station gate · Security model