StellaOps Attestor

Attestor converts signed DSSE evidence from the Signer into transparency-log proofs and verifiable reports for every downstream surface (Policy Engine, Export Center, CLI, Console, Scheduler). It is the trust backbone that proves SBOM, scan, VEX, and policy artefacts were signed, witnessed, and preserved without tampering.

Notable capabilities & posture

Why it exists

Roles & surfaces

Supported payloads

API surface (WebService)

Minimal-API endpoints (AttestorWebServiceEndpoints.cs, PredicateRegistryEndpoints.cs, WatchlistEndpoints.cs) and MVC controllers (Controllers/). Scope shown is the policy required; verify/read are satisfied by higher scopes (see Security hardening).

Trust & envelope model

Security hardening

UI, CLI, and SDK workflows

Storage, offline & air-gap posture

Observability & performance

Key integrations

Backlog references

Epic alignment

Implementation Status

Delivery Phases:

Acceptance Criteria:

Key Risks & Mitigations: