Release control for VMs, Docker Compose and plain servers

Gate on what runs. Sign what ships.

One self-hosted control plane scans your images, gates each release on policy and reachable riskVulnerabilities whose code your application actually calls — the ones that can affect you, rather than every CVE present in the image, deploys what passes, and watches what runs.

Built for technical teams under audit pressure

Reachable vulnerabilities | Source to environment | Signed evidence | Compliance packs | Offline-ready
v1.0-RC1 — release candidate. v1.0 is expected on 1 January 2027; pre-orders are open now. Between now and then the work is bug fixing, validating with customers, and further modules. Signed v1.0.0-RC1 images and the install bundle are both public — download and pull anonymously, no account needed.

Most of what a scanner flags sits in code your application never runs — Sysdig's 2024 report puts it at ~85% of critical container vulnerabilities. A gate that cannot tell the difference blocks everything, so teams learn to wave it through — and the wave-through is the part nobody can show an auditor.

Stella Ops inverts that: every release gated on real vulnerability risk — with signed evidence.

Decision

Gate evaluation: reachable risk, not raw counts

Every allow or block traces back to the exact inputs behind it — so “why was this blocked?” is a lookup, not an investigation.

Those inputs: SBOM, reachability verdicts, VEX status, policy snapshot, approvals.

Promotions screen in the Stella Ops console: six lifecycle states from awaiting approval to retired, with per-promotion status and risk signal
Promotions in the Stella Ops console, shown with demo data. Every promotion is in exactly one lifecycle state, and its gate posture travels with it.

A check that could not run is reported as NOT EVALUATED and recorded in the verdict. It is never counted as a pass.

See the gate model

Chain of custody

Source → Build → Scan → Verdict → Decision → Deploy → Watch

Every release moves along this seven-stage spine, and each stage carries one of three evidence states. A stage without evidence stays visibly empty — nothing is inferred to fill the gap. What comes out the other end is an artifact carrying proof of what is inside it, what is reachable, and who approved it — verifiable long after the release.

Chain of Custody screen: seven stages from Source to Watch, each marked Missing, Recorded, or Signed
Absent evidence is shown as Missing, never faked. Stella Ops console, demo data.

MISSING

No evidence captured for this stage yet. The stage stays a visible gap.

RECORDED

Evidence captured and linked to the release digest, not yet signed.

SIGNED

Evidence sealed with a verifiable signature, made with a key generated inside your own installation — the product ships none.

What you get

See the gap, the moment it opens

After deploy, Watch compares the running digest against the approved one — every service, every environment. A mismatch means an unapproved or altered image, flagged with the evidence that shows it.

A release is proven at deploy time. Watch is how that proof stays current afterwards — drift detection is a first-class stage of the custody spine, not an add-on.

See the estate view
Estate screen: a matrix of services against environments, above an open deviations panel summarising running containers whose digest is not an approved one
EstateEverything you run and deploy to: the hosts, VMs and Compose projects across your environments, and the containers running on them. view: every running container whose digest is not an approved one, flagged as drift. Stella Ops console — a sample estate, with drift counts from this development stack observing itself.

Check the proof first: The evidence model, the signing keys and the replay workflow are public. Verify them before you trust anything else on this page.

Customer references are coming soon — results from our internal beta.

Review evidence model Verify signing keys See replay workflow

Prove your next release

Free tier: 3 environments, 999 new-digest scans per rolling 24 h.

Start free and self-hosted. Move to a paid plan when you need more environments or scan volume — every capability is in every tier.

Compliance packs map your custody evidence to what NIS2, DORA and CRA ask for — they gather and organise the evidence, they do not certify that you comply.