Self-hosted release evidence
Stop scrambling when customers ask for release security evidence.
Evydence helps software vendors organize the proof behind a software release: what was shipped, what was inside it, which vulnerabilities were reviewed, what decisions were made, and what can safely be shared with customers.
Run it self-hosted, keep technical truth on GitHub, and use commercial terms when your organization needs them.
Demo Run the customer CVE review demo One release, one SBOM finding, one decision, one package verifier.
Artifact digest
SBOM inventory
Vulnerability decision
Signed package
The problem
Customer security reviews are becoming more detailed.
A customer may ask what third-party components are inside a release, whether known vulnerabilities are present, whether a CVE affects your product, who reviewed the decision, and what proof can be verified.
For many teams, the answer is scattered across scanner exports, CI logs, tickets, chat, spreadsheets, object storage, and one-off PDFs.
The outcome
Evydence gives each release an evidence trail.
- software component inventory
- vulnerability scan results
- vulnerability decisions
- approvals and exceptions
- build and artifact proof
- release-readiness reports
- signed bundles
- customer-safe packages
Before and after Evydence
What it is not
Evydence is not a scanner, firewall, legal compliance engine, certification service, or guarantee that a release is secure.
It helps organize technical evidence and release-security decisions so teams can answer review questions more clearly and repeatably.
Next step
Evaluate the technical truth on GitHub.
The website qualifies the business problem. The repository remains the source of truth for code, docs, release artifacts, limitations, and verification evidence.