Evidence Engine

Know which vulnerabilities actually matter

Generate SBOMs, analyze hybrid reachability, and produce signed evidence for every artifact.

Meaningful reduction in false positives through three-layer analysis

The reachability difference

Traditional scanners tell you a CVECommon Vulnerabilities and Exposures - a unique identifier for a publicly known security vulnerability exists. Stella proves whether your code actually calls the vulnerable function.

Static analysis

Call graph extraction from bytecode and source. Traces execution paths to vulnerable functions.

Manifest analysis

Import statements, dependency trees, package manifests. Identifies which code is actually included.

Runtime traces

Runtime facts you supply, for higher confidence. Proves what code paths are actually executed. RC1 ships the ingest path, not the collector. eBPFExtended Berkeley Packet Filter — a Linux kernel technology that runs sandboxed programs for high-performance observability and runtime analysis without kernel modules

Result: Significantly fewer false positives

Focus on reachable CVEs instead of hundreds of theoretical ones.

The real-world difference

Typical scanner output
Total: 128 vulnerabilities CRITICAL: 23 HIGH: 89 MEDIUM: 12 LOW: 4 "Great. Which ones actually matter?"
Stella Ops with reachability
Total: 128 CVEs detected
Reachable: 12 CVEs CRITICAL: 2 (both in auth path) HIGH: 4 (3 in API handler) MEDIUM: 6 Focus on what matters. Ship with confidence.

Illustrative counts, not a live transcript — the shape is the point: totals by severity versus the reachable subset.

SBOM capabilities

Generate, ingest, and diff SBOMs with full version history and lineage tracking.

Multi-format support

CycloneDXAn open standard format for software bill of materials (SBOM) used across the industry 1.7, SPDXSoftware Package Data Exchange - another open standard format for SBOMs, widely used in open source 3.0, Trivy-JSON with auto-detection.

Delta-SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software caching

Sub-second warm-path scans through intelligent caching.

SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software lineage ledger

Full versioned history with traversal queries.

Layer-aware analysis

Per-layer SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software extraction and base image detection.

Semantic SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software diff

Material change detection between releases.

Bring your own SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software

Ingest external SBOMs and add reachability analysis.

11 language analyzers

.NET/C#
Java
Go
Python
Node.js
Ruby
Bun
Deno
PHP
Rust
Native
+more

Plus OS package analyzers for apk, apt, yum, dnf, rpm, and pacman.

38 advisory sources

Aggregate vulnerability intelligence from global, vendor, and regional sources with automatic sync and conflict detection.

Global databases
  • NVDNational Vulnerability Database - the U.S. government repository of standards-based vulnerability data (NIST), CVECommon Vulnerabilities and Exposures - a unique identifier for a publicly known security vulnerability (MITRE), OSVOpen Source Vulnerabilities - a distributed vulnerability database for open source projects, GHSAGitHub Security Advisories - security vulnerability database for packages on GitHub
  • Alpine, Debian, Ubuntu, RHEL, SUSE
  • CISACybersecurity and Infrastructure Security Agency - U.S. federal agency responsible for cybersecurity guidance and vulnerability catalogs KEVKnown Exploited Vulnerabilities - CISA's catalog of vulnerabilities actively exploited in the wild, EPSSExploit Prediction Scoring System - a probability score (0-100%) predicting how likely a vulnerability is to be exploited in the wild v4
Vendor PSIRTs
  • Microsoft MSRC, Cisco PSIRT, Oracle CPU
  • VMware, Adobe PSIRT, Apple Security
  • Chromium, Kaspersky ICS-CERT
National CERTsComputer Emergency Response Teams - regional cybersecurity organizations that publish vulnerability advisories
  • CERT-FR, CERT-Bund (BSI), CERT-In
  • ACSC, CCCS, KISA, JVNJapan Vulnerability Notes - Japan's vulnerability database managed by JPCERT/CC and IPA
  • FSTEC BDU, NKCKI, Astra Linux
Custom feeds
  • Private advisory connectors
  • Advisory merge engine with conflict resolution
  • Connector health monitoring

All sources deduplicated with signed snapshots for deterministic replay

Built for speed

<1s

Warm-path scans

Delta-SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software caching for repeated digests

70-90%

False positive reduction

Through hybrid reachability analysis

38

Advisory sources

Aggregated with automatic sync

Evidence output

Every scan produces signed, exportable evidence.

SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software snapshot (CycloneDXAn open standard format for software bill of materials (SBOM) used across the industry/SPDXSoftware Package Data Exchange - another open standard format for SBOMs, widely used in open source)
ReachabilityAnalysis that proves whether vulnerable code is actually called by your application — filtering out false positives from scanner noise graph with edge attestations
Advisory state at scan time
Path witness generation for audit
DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures-signed evidence bundles
SARIF export for CI integration

Where it fits

Evidence engine only

Use Stella's scanning and reachability as a standalone evidence producer.

  • Generate SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software + reachability for your CI pipeline
  • Export findings as SARIF, CycloneDXAn open standard format for software bill of materials (SBOM) used across the industry, or Decision Capsules
  • Integrate with your existing CD tool
Full release control

Add orchestration, policy gates, and deployment execution for end-to-end release governance.

  • Scan → Gate → Promote → Deploy → Prove
  • Digest-firstRelease identity based on immutable content hashes (SHA-256 digests) rather than mutable tags — ensuring byte-identical deployments versioning across environments
  • A/B, canary, rollback with evidence preservation

Ready to focus on what matters?

Start scanning with reachability analysis.

Release Orchestration · Security Decisioning · All features