Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

JUDGE Unified Developer and Governance Experience

JUDGE Unified Developer and Governance Experience

By: TestifySec Latest Version: @testifysec/judge@v1.2.0
Linux/Unix
Linux/Unix

Product Overview

JUDGE enables a unified developer and cybersecurity governance experience to mitigate the risk of software supply chain attacks by integrating zero trust principles of observability and verification into software build pipelines. JUDGE contains a configurable package, including:

  • Build pipeline observer - automate the collection of trusted telemetry across input, environment, action, and output to cryptographically verify supply chain metadata (telemetry) via signing that data with a self-managed key, a key from a Key Management Service (KMS), or an identity

  • Certificate Authority (CA) - enable an identity-based signature by authenticating and generating a short-lived key to create a short-lived certificate (only valid for 10 minutes) that then uses that certificate and key to sign the data, thereby removing the entire burden of key management, key rotation, etc

  • Time Stamping Authority (TSA) - provide cryptographic proof that your data was signed while the certificate was valid and verify provenance without relying on an external service, enabling artifact verification across disconnected (air-gapped) environments

  • GraphQL data store - ability to manage storage, retrieval, and retention of software build pipeline attestations and trusted telemetry via a GraphQL API to facilitate either ad hoc or deploy-time compliance verification from developer commit to production deployment


Trusted telemetry is securely stored and accessible via a GraphQL API for custom integrations. If all policies are verified, one or more evidence-based software supply attestations are generated, encompassing the entire SDLC from developer commit to production deployment. Create software deployment policies, distribute policies, digitally sign policies to avoid tampering, and identify specific responses to disparate types of policy violations when they are detected.

At the core of this are two key open-source components: Witness, a CI/CD pipeline observer that collects trusted telemetry for attestations, and Archivista, a trusted telemetry and attestation storage manager. Originally built and maintained by TestifySec, both open-source tools were donated to the Cloud Native Computing Foundation (CNCF) as subprojects underneath the in-toto project.

Continuous monitoring of software build pipeline trusted telemetry yields a lower residual risk of software supply chain attack by verifying provenance and meets multiple NIST SP 800-53r5 security controls. For custom pricing, EULA, or a private contract, please contact awsmarketplace@testifysec.com, for a private offer.

Version

@testifysec/judge@v1.2.0

Categories

Operating System

Linux

Delivery Methods

  • Container

Pricing Information

Usage Information

Support Information

Customer Reviews