Stella Ops – 2‑Minute Overview

The Problem We Solve

  • Supply-chain attacks exploded 742 % in three years; regulated teams still need to scan hundreds of containers a day while disconnected from the public Internet.
  • Existing scanners trade freedom for SaaS: no offline feeds, hidden quotas, noisy results that lack exploitability context.
  • Audit fatigue is real: Policy decisions are opaque, replaying scans is guesswork, and trust hinges on external transparency logs you do not control.

The Promise

Stella Ops delivers deterministic, sovereign container security that works the same online or fully air-gapped:

  1. Deterministic replay manifests (SRM) prove every scan result, so auditors can rerun evidence and see the exact same outcome.
  2. Lattice policy engine + OpenVEX keeps findings explainable; exploitability, attestation, and waivers merge into one verdict.
  3. Sovereign crypto profiles let you anchor signatures to eIDAS, FIPS, GOST, or SM roots, mirror your feeds, and keep Sigstore-compatible transparency logs offline.

Core Capability Clusters

ClusterWhat you getWhy it matters
SBOM-first scanningDelta-layer SBOM cache, sub‑5 s warm scans, Trivy/CycloneDX/SPDX ingestion + dependency cartographingSpeeds repeat scans 10× and keeps SBOMs the source of truth
Explainable policyOpenVEX + lattice logic, policy engine for custom rule packs, waiver expirationsReduces alert fatigue, supports alert muting beyond VEX, and shows why a finding blocks deploy
Attestation & provenanceDSSE bundles, optional Rekor mirror, DSSE → CLI/UI exportsLets you prove integrity without relying on external services
Offline operationsOffline Update Kit bundles, mirrored feeds, quota tokens verified locallyWorks for sovereign clouds, SCIFs, and heavily regulated sectors
Governance & observabilityStructured audit trails, quota transparency, per-tenant metricsKeeps compliance teams and operators in sync without extra tooling

Who Benefits

PersonaOutcome in week one
Security engineeringDeterministic replay + explain traces
Platform / SREFast scans, local registry, no Internet dependency
Compliance & riskSigned SBOMs, provable quotas, legal/attestation docs

Where to Go Next