SECURITY

Security.

We build supply-chain security tooling, so we hold this site and our releases to the standard we sell.

Report a vulnerability

Found a security issue in this site, our releases, or our infrastructure? Email security@attestree.com. We aim to acknowledge within two business days and to keep you updated through resolution. We support coordinated disclosure and will not pursue legal action against good-faith research that respects this policy and our users' privacy.

Scope

In scope: attestree.com and its subdomains, the Attestree Community Edition image, and our published open-source components.
Out of scope: third-party services we use (please report those to the vendor), social engineering, and volumetric denial-of-service.

Our posture

The domain enforces SPF, DKIM, and DMARC (p=reject). Changes to this site are made through signed, verified commits; CI actions are pinned by commit SHA with least-privilege tokens; dependencies are lockfile-pinned and audited. The Community Edition image is cosign-signed, and each release carries the image's CycloneDX SBOM. Build provenance for the image and the installer shim is set up in the release pipelines but has not been published yet.

Honest about state

Attestree is pre-GA. The free Community Edition signs its audit chain with a local, file-backed key and exports bundles that verify offline — but that key's custody is not hardware-attested, so it is not built for regulatory submission. The commercial tier keeps the key in a Key Vault in your own Azure subscription; hardware-backed custody is on the roadmap. We say so wherever it matters, in-product included.