FOR SAAS ENGINEERING

Ship at SaaS speed,
with an SBOM at ingest.

You ship daily, and your Windows dev fleet and CI runners install tooling from winget and Chocolatey all day. EU CRA and EO 14028 now expect an SBOM for what you run — without a security team slowing engineering down. With a detonation host attached, Attestree detonates each winget package at ingest, builds its SBOM and records an attestation, so the evidence is a side effect of installing software, not a release-day scramble. Chocolatey is inventoried and managed today; its detonation, and npm and pip provenance, are on the roadmap.

Hosted or self-hosted EU CRA · EO 14028 SBOM at ingest Signed audit export
INGEST · LAST 24H winget
  • ingest winget:[email protected]
    sbom · detonated sig:9c2a…
  • ingest winget:[email protected]
    detonated · clean sig:1f7b…
  • halt winget:Vendor.Tool · signer changed
    held HALT
  • sbom cyclonedx · syft
    recorded sig:a4d0…
  • cve KEV match · 3 endpoints
    flagged sig:77e1…
  • export audit-bundle.tar.zst
    signed sig:0be4…
Hosted instance · CVE index · audit bundle 4,117 verified

On our horizon. Attestree is pre-GA and onboarding design partners. winget ingest — detonation, SBOM and attestation — ships today; the npm and pip ingest an engineering org needs does not yet, so this page describes where we're heading. If that's you, come build it with us .

WHY THIS MATTERS HERE

What engineering-led security teams ask us first.

SBOM by construction

A CycloneDX SBOM and an attestation for each detonated winget package at ingest, not a scanner bolted on before release; exporting the SBOM for an EU CRA file is being built. Chocolatey, npm and pip follow.

Hosted for you, in your own subscription

A dedicated Attestree instance in your own Azure subscription, deployed and upgraded by us — no box for your platform team to operate, and your evidence never leaves your tenancy. Same attestations and evidence as self-hosted, which stays available.

Evidence for SBOM requests

The SBOM supports EO 14028 SBOM requests once its export ships. A per-package signed attestation that one command can verify — in your fleet or your auditor's — is being built.

PRICING

Commercial — request access.

Pre-GA pricing is design-partner friendly. Tell us about your stack — we'll come back within two business days.

Dedicated hosted instance SBOM at ingest Fleet CVE index Signed audit export
ENDPOINTS

We'll only use this to schedule a 30-minute fit-check.

DESIGN-PARTNER QUOTE · TBD

"Design partner pipeline open. Be first to be quoted."

Your name here · Head of Security, SaaS design partner