Signed evidence, from source to environment.
One self-hosted control plane scans your images, gates each release on policy and reachable risk, deploys what passes, and watches what runs. Every artifact carries proof of what is inside it, what is reachable, and who approved it — verifiable long after the release.
Built for technical teams under audit pressure
Decision
Gate evaluation: reachable risk, not raw counts
Every allow or block traces to its inputs: SBOM, reachability verdicts, VEX status, policy snapshot, approvals. “Why was this blocked” is a lookup, not an investigation.

A check that could not run is reported as NOT EVALUATED and recorded in the verdict. It is never counted as a pass.
Chain of custody
Source → Build → Scan → Verdict → Decision → Deploy → Watch
Every release moves along this seven-stage spine. Each stage carries one of three evidence states. A stage without evidence stays visibly empty — nothing is inferred to fill the gap.

MISSING
No evidence captured for this stage yet. The stage stays a visible gap.
RECORDED
Evidence captured and linked to the release digest, not yet signed.
SIGNED
Evidence sealed with a verifiable signature, made with a key generated inside your own installation — the product ships none. Checked against a trust root you configure, never against a Stella Ops service.
What you get
See the gap, the moment it opens
After deploy, Watch compares the running digest against the approved one — every service, every environment. A mismatch means an unapproved or altered image, flagged with the evidence that shows it.
A release is proven at deploy time. Watch is how that proof stays current afterwards — drift detection is a first-class stage of the custody spine, not an add-on.
See the estate view
Check the proof first: The evidence model, the signing keys and the replay workflow are public. Verify them before you trust anything else on this page.
Customer references are coming soon — results from our internal beta.
Review evidence model Verify signing keys See replay workflow
Prove your next release
Free tier: 3 environments, 999 new-digest scans per rolling 24 h.
Start free and self-hosted. Move to a paid plan when you need more environments or scan volume — every capability is in every tier.
Compliance packs map custody evidence to NIS2, DORA and CRA obligations — evidence-only mode; they do not claim regulatory compliance. A published example capsule can be verified with stock cosign, no Stella Ops install required.
