Gate on what runs. Sign what ships.
One self-hosted control plane scans your images, gates each release on policy and reachable riskVulnerabilities whose code your application actually calls — the ones that can affect you, rather than every CVE present in the image, deploys what passes, and watches what runs.
Built for technical teams under audit pressure
Most of what a scanner flags sits in code your application never runs — Sysdig's 2024 report puts it at ~85% of critical container vulnerabilities. A gate that cannot tell the difference blocks everything, so teams learn to wave it through — and the wave-through is the part nobody can show an auditor.
Stella Ops inverts that: every release gated on real vulnerability risk — with signed evidence.
Decision
Gate evaluation: reachable risk, not raw counts
Every allow or block traces back to the exact inputs behind it — so “why was this blocked?” is a lookup, not an investigation.
Those inputs: SBOM, reachability verdicts, VEX status, policy snapshot, approvals.

A check that could not run is reported as NOT EVALUATED and recorded in the verdict. It is never counted as a pass.
Chain of custody
Source → Build → Scan → Verdict → Decision → Deploy → Watch
Every release moves along this seven-stage spine, and each stage carries one of three evidence states. A stage without evidence stays visibly empty — nothing is inferred to fill the gap. What comes out the other end is an artifact carrying proof of what is inside it, what is reachable, and who approved it — verifiable long after the release.

MISSING
No evidence captured for this stage yet. The stage stays a visible gap.
RECORDED
Evidence captured and linked to the release digest, not yet signed.
SIGNED
Evidence sealed with a verifiable signature, made with a key generated inside your own installation — the product ships none.
What you get
See the gap, the moment it opens
After deploy, Watch compares the running digest against the approved one — every service, every environment. A mismatch means an unapproved or altered image, flagged with the evidence that shows it.
A release is proven at deploy time. Watch is how that proof stays current afterwards — drift detection is a first-class stage of the custody spine, not an add-on.
See the estate view
EstateEverything you run and deploy to: the hosts, VMs and Compose projects across your environments, and the containers running on them. view: every running container whose digest is not an approved one, flagged as drift. Stella Ops console — a sample estate, with drift counts from this development stack observing itself.Check the proof first: The evidence model, the signing keys and the replay workflow are public. Verify them before you trust anything else on this page.
Customer references are coming soon — results from our internal beta.
Review evidence model Verify signing keys See replay workflow
Prove your next release
Free tier: 3 environments, 999 new-digest scans per rolling 24 h.
Start free and self-hosted. Move to a paid plan when you need more environments or scan volume — every capability is in every tier.
Compliance packs map your custody evidence to what NIS2, DORA and CRA ask for — they gather and organise the evidence, they do not certify that you comply.
