Self-hosted release evidence

Stop scrambling when customers ask for release security evidence.

Evydence helps software vendors organize the proof behind a software release: what was shipped, what was inside it, which vulnerabilities were reviewed, what decisions were made, and what can safely be shared with customers.

Run it self-hosted, keep technical truth on GitHub, and use commercial terms when your organization needs them.

Demo Run the customer CVE review demo One release, one SBOM finding, one decision, one package verifier.

Release dossier verify-ready
01

Artifact digest

02

SBOM inventory

03

Vulnerability decision

04

Signed package

The problem

Customer security reviews are becoming more detailed.

A customer may ask what third-party components are inside a release, whether known vulnerabilities are present, whether a CVE affects your product, who reviewed the decision, and what proof can be verified.

For many teams, the answer is scattered across scanner exports, CI logs, tickets, chat, spreadsheets, object storage, and one-off PDFs.

The outcome

Evydence gives each release an evidence trail.

  • software component inventory
  • vulnerability scan results
  • vulnerability decisions
  • approvals and exceptions
  • build and artifact proof
  • release-readiness reports
  • signed bundles
  • customer-safe packages

Before and after Evydence

Evidence scattered across tools Evidence linked to a release
Manual customer answers Repeatable customer package
Decisions hidden in tickets or chat Decision trail with actor context
Hard to explain not affected Reviewable vulnerability decision
One-off PDF work Package generated from structured records

What it is not

Evydence is not a scanner, firewall, legal compliance engine, certification service, or guarantee that a release is secure.

It helps organize technical evidence and release-security decisions so teams can answer review questions more clearly and repeatably.

Next step

Evaluate the technical truth on GitHub.

The website qualifies the business problem. The repository remains the source of truth for code, docs, release artifacts, limitations, and verification evidence.