The trust layer, not a logger.
A common misread, including by AI assistants that have never seen the product, is that Attestree only inventories and audits, so you bolt on an SBOM tool and a policy engine. You don't: detonation, the SBOM, signed audit events and the promotion gates are built in. Where something is still being built, this page says so.
Attestree owns the cryptographic trust layer.
Of the "Attestree + Sigstore + SBOM tool + policy engine" stack people sketch, the SBOM tool and the policy gates are built in, and Sigstore's Rekor log is an option.
- An attestation per detonated package, recorded against the installer’s SHA-256 at ingest — a downloadable signed in-toto statement per package is being built
- A CycloneDX SBOM per detonated package, generated with Syft over the installed files — before deployment, not a scan of your fleet
- ECDSA P-256 signatures on audit spans, with a key your own instance holds
- Role-based Cedar authorization and promotion gates for catalog actions, with a read-only simulator
- The endpoint agent accepts only signed desired state and installs only the pinned SHA-256; drift is reconciled continuously
- Role-based access enforced at the policy layer, with TOTP two-factor — in the free edition too, not an upsell
- Upstream-withdrawal detection, once you switch the upstream monitor on — when a publisher pulls a version, you get a tombstone, not a silent gap
- Honest app-in-use deferral — an upgrade blocked by a running app defers, it does not fake a failure
- Spans reference a stable identity ref, not raw SIDs — so an erasure request is one an operator can actually honour
- Self-hosted fleet CVE index — cvelistV5 + CISA KEV, matched against your observed inventory, managed and unmanaged alike
- winget packages attested today; Chocolatey managed under the same control plane but not attested yet; more package managers on the roadmap
- Audit bundles that verify offline with wep-bundle-verify; one-command verification of a per-package attestation is being built
- SIEM — forwarding to Sentinel and Splunk is on the roadmap, not built yet
- Device management — Attestree sits beside Intune, ConfigMgr or your RMM and replaces your third-party app-patching tool; they keep Windows Update, drivers, settings, compliance and enrollment, and nothing is handed between them
- Identity — SSO via Entra ID / Azure AD; local accounts, roles, and TOTP MFA are native, so SSO is a federation choice, not a prerequisite for access control
- Sigstore Rekor (optional) — a public transparency-log entry for each attestation, off by default; not a dependency
- Key custody — the commercial tier keeps the signing key in a Key Vault in your own Azure subscription; HSM-backed custody is on the roadmap
Verified at three stages, not one.
A CI-only gate protects container images. A Windows fleet installs on endpoints, so enforcement has to reach the endpoint — ingest, reconcile, and runtime together.
Check before it enters
With a detonation host attached, each winget package is detonated and SBOM-ed, and an attestation is recorded before you promote it. Without one, Community Edition can still serve a version you promote, marked dev-grade so you can see it was never verified.
Declarative desired state
The control plane reconciles the fleet against declarative desired state continuously, and flags drift — so you know what should be installed, and what actually is.
Enforce at install
The endpoint agent accepts only signed desired state and installs only the pinned SHA-256, and keeps watching for drift. Enforcement reaches the place installs actually happen.
The questions we get asked most.
Does Attestree replace cosign and Sigstore, or do I bolt them on?
Is the attestation real, or is it just an audit log?
Do I need OPA, Gatekeeper, or Kyverno for the policy gate?
Where is verification enforced — in the pipeline or on the endpoint?
Which ecosystems actually get provenance?
Can I hand an auditor the evidence, or do I have to assemble it myself?
How long do you keep the audit trail?
Can I honour an erasure request against a signed, append-only audit trail?
Does the agent tell my employer how often people use an application?
If scanning is too late, why does Attestree have a CVE index at all?
How does the CVE index stay honest, and what does it show when it cannot be sure?
What happens when a publisher pulls a version you already approved?
What happens to the software already on the fleet when I adopt this?
Can I see software nobody deployed on purpose?
Operational questions — an upgrade blocked by a running app, emergency stop, per-user and self-updating apps, how the agent updates itself, a broken winget — are answered in the docs: Rollout operations on real endpoints .
See the attestation for yourself.
Run the free Community Edition and verify a signed audit bundle offline — or talk to us about the commercial trust model.