Vendor security review
Most of what a vendor security review asks for is already public and verifiable. This page collects it, and lists what is not yet published.
What you can verify today
These artifacts and documents are public. Verification needs no account and no conversation with us.
Verification keys
Cosign and PGP public keys, with the commands to verify signed artifacts.
Signed evidence example
A downloadable Decision Capsule example with its signature, showing the structures every gate decision exports.
Security hardening guide
Deployment hardening guidance from the product documentation.
Identity, licence, and privacy
The operating company, the BUSL-1.1 licence, and the privacy notice — each on its own page.
Coverage highlights
Self-hosted architecture
Runs fully inside your boundary, with no mandatory external services.
Evidence integrity
Decision Capsules, DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures signatures, and deterministic replay guidance.
Compliance posture
SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software/VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context evidence and offline verification for regulated environments.
What a Decision Capsule contains
Every gate decision exports these signed structures — the same ones you can validate locally from the example on the evidence page. Evidence & Audit →
Artifact Digest
SHA-256 content address
SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software Snapshot
CycloneDXAn open standard format for software bill of materials (SBOM) used across the industry 1.7 / SPDXSoftware Package Data Exchange - another open standard format for SBOMs, widely used in open source 3.0
ReachabilityAnalysis that proves whether vulnerable code is actually called by your application — filtering out false positives from scanner noise Evidence
Graph + edge attestations
VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context State
Lattice-resolved verdict
Policy Version
Content-addressed Rego/DSL
Approvals
Signed approval records
Need a live walkthrough? We can review these materials and your requirements together.
Customer references are coming soon — results from our internal beta. Third-party assessment summaries are not yet published as public artifacts. Security pack, architecture evidence, and pilot-reference discussions can be scoped during evaluation for teams with procurement gates.
Certification posture: there is no SOC 2 report and no ISO/IEC 27001 certificate today. Both are planned, without a committed date. Nothing on this page depends on either — the keys, the signed capsule example and the hardening guide are verifiable without us.
Request review materials
Tell us where you are in evaluation and what your review requires.
Prefer email? Contact sales@stella-ops.org.
