Vendor security review

Most of what a vendor security review asks for is already public and verifiable. This page collects it, and lists what is not yet published.

What you can verify today

These artifacts and documents are public. Verification needs no account and no conversation with us.

Coverage highlights

Self-hosted architecture

Runs fully inside your boundary, with no mandatory external services.

Evidence integrity

Decision Capsules, DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures signatures, and deterministic replay guidance.

Compliance posture

SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software/VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context evidence and offline verification for regulated environments.

What a Decision Capsule contains

Every gate decision exports these signed structures — the same ones you can validate locally from the example on the evidence page. Evidence & Audit →

Artifact Digest

SHA-256 content address

Signed

SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software Snapshot

CycloneDXAn open standard format for software bill of materials (SBOM) used across the industry 1.7 / SPDXSoftware Package Data Exchange - another open standard format for SBOMs, widely used in open source 3.0

Signed

ReachabilityAnalysis that proves whether vulnerable code is actually called by your application — filtering out false positives from scanner noise Evidence

Graph + edge attestations

Signed

VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context State

Lattice-resolved verdict

Signed

Policy Version

Content-addressed Rego/DSL

Signed

Approvals

Signed approval records

Signed

Need a live walkthrough? We can review these materials and your requirements together.

Customer references are coming soon — results from our internal beta. Third-party assessment summaries are not yet published as public artifacts. Security pack, architecture evidence, and pilot-reference discussions can be scoped during evaluation for teams with procurement gates.

Certification posture: there is no SOC 2 report and no ISO/IEC 27001 certificate today. Both are planned, without a committed date. Nothing on this page depends on either — the keys, the signed capsule example and the hardening guide are verifiable without us.

Request review materials

Tell us where you are in evaluation and what your review requires.

Prefer email? Contact sales@stella-ops.org.