Product overview

A self-hosted evidence system for software releases.

Evydence keeps release evidence connected to the product, version, artifact, vulnerability, decision, approval, and customer package it belongs to.

Release dossier verify-ready
01

Artifact digest

02

SBOM inventory

03

Vulnerability decision

04

Signed package

Capture release evidence

Collect proof material around a release: component inventories, vulnerability scans, build metadata, artifact digests, source records, deployment events, and supporting files.

Record vulnerability decisions

When a known vulnerability appears, record whether it affects the release, why, who reviewed it, and what evidence supports the decision.

Generate customer-safe packages

Create packages that include evidence a customer can review without exposing unnecessary internal detail.

Verify the package

Use manifests, hashes, signatures, and audit-chain records to make the package reviewable instead of just another static document.

Self-hosted by design

Evydence is designed for teams that want to run the evidence system in their own environment, close to release, security, and CI/CD systems.

Different from adjacent tools

Dependency-Track and SBOM inventory Evydence packages release-scoped SBOM, scan, decision, bundle, and verification evidence for review.
GUAC-style supply-chain graph tools Evydence focuses on release manifests, verification receipts, and customer-safe package evidence.
OpenVEX tooling Evydence stores VEX as evidence and links normalized decisions to releases, scans, SBOM context, and packages.
Vanta, Drata, and broad GRC Evydence is self-hosted release evidence infrastructure, not a compliance platform or certification service.
Scanners and internal scripts Evydence records their outputs, preserves hashes, and adds tenant scope, append-only history, and verification commands.

Next step

Evaluate the technical truth on GitHub.

The website qualifies the business problem. The repository remains the source of truth for code, docs, release artifacts, limitations, and verification evidence.