Evidence

The consolidated evidence and attestation service (ADR-039 D14). One deployable family, two replica roles, one database.

Start here: architecture.md.

RoleImageServes
evidence-webstellaops/evidence-webthe whole /api/evidence/v1 surface, plus the absolute proof/anchor/verify controller routes
evidence-workerstellaops/evidence-workerthe carried background loops; no HTTP surface

Capabilities

CapabilityWhere it lives
DSSE attestation submit, verify and retrievalStellaOps.Attestor.Application, .Verify
Local transparency log, checkpoints and inclusion proofsStellaOps.Attestor.Infrastructure/Rekor/
Proof chains, merkle spines, receipts, content-addressed storeStellaOps.Attestor.ProofChain
Sealed evidence capsules, materials, exports and legal holdsStellaOps.EvidenceLocker*
RFC 3161 existence-time anchoring at sealStellaOps.EvidenceLocker.Infrastructure/Signing/
Predicate schema registry and standard predicatesStellaOps.Attestor.StandardPredicates
Identity watchlistStellaOps.Attestor.Watchlist
Timestamp Assurance (source-only, composed into no host — TA-4)StellaOps.Evidence.TimestampAssurance*

Predecessors

WasNow
attestorretired 2026-09-05. Read ../attestor/README.md.
evidence-locker-web / evidence-locker-workerretired 2026-09-05. Read ../evidence-locker/README.md.
attestor-tileproxyalive and unchanged; an Evidence-family member by ownership.
tsaalive and unchanged; an Evidence-family member by ownership.

signer is not in this family and never joins it: key custody is a separate service with a separate database (ADR-039 D14). Read ../signer/README.md.

Operating