Use case

Customer security reviews should not require a scavenger hunt.

Enterprise customers increasingly ask software vendors to explain what is inside a release, which known vulnerabilities are present, which ones actually affect the product, and what proof supports the answer.

Evydence helps turn that review from a manual scramble into a repeatable release evidence workflow.

Release dossier verify-ready
01

Artifact digest

02

SBOM inventory

03

Vulnerability decision

04

Signed package

The question that triggers the scramble

A customer asks: This CVE appears in your software bill of materials. Are we affected?

Without a system, the answer may require checking the SBOM, vulnerability scanner, CI logs, build artifacts, internal tickets, approvals, release notes, and previous customer responses.

A clearer answer

  • yes, affected and fixed
  • yes, affected and accepted with an exception
  • no, present but not exploitable in this product context
  • unknown, with documented gaps and next steps

Before and after

We think this is not exploitable. Let us check with engineering. For this release, the finding was reviewed, marked not affected, linked to supporting evidence, and included in the customer-safe package.

Next step

Evaluate the technical truth on GitHub.

The website qualifies the business problem. The repository remains the source of truth for code, docs, release artifacts, limitations, and verification evidence.