TestifySec
Open-source-rooted software supply chain security platform providing cryptographic build attestation, SBOM generation, and CI/CD policy enforcement.
Visit Website ↗ + Add to CompareOverview
TestifySec builds software supply chain security tooling centered on cryptographic build attestation. Its open-source core — Witness (an attestation framework implementing the in-toto specification), Archivista (attestation storage), and the Judge policy engine — captures and signs evidence at each step of a CI/CD pipeline, then lets organizations enforce policy and generate SBOMs (software bills of materials) based on verifiable proof of how software was actually built, rather than a self-reported manifest.
Founded in 2021 and headquartered in Jasper, Alabama, TestifySec was selected by the Department of Homeland Security’s Science and Technology Directorate (S&T) as one of seven startups nationally for its Silicon Valley Innovation Program cohort focused on software supply chain visibility, receiving a $199,990 award to extend its SBOM generation and policy/admission-control capabilities for DevOps pipelines. The company separately won an AFWERX SBIR Phase 1 award from the Department of the Air Force for FLiCK, a forensic license-compliance tool. It raised a $6.4 million seed round led by Mucker Capital, with Dreamit Ventures and a Jefferies family office also participating.
In January 2024, TestifySec donated Witness and Archivista as official subprojects of in-toto, bringing them into the Cloud Native Computing Foundation ecosystem, and the company’s engineers hold maintainer and steering-committee roles across in-toto, TUF, Witness, Archivista, and the newer SBOMit project.
The company’s credibility currently rests heavily on government pilot work and open-source governance standing rather than a large public roster of commercial enterprise customers, which is typical for a young company building infrastructure-layer security tooling around an emerging, federally-driven compliance mandate (SBOMs and build provenance under Executive Order 14028).
Innovation Matrix Assessment
Progressed from stealth to donating Witness and Archivista as CNCF/in-toto subprojects in January 2024 while continuing to win new federal SBIR/SVIP awards, showing an active technical roadmap.
The open-source attestation core (Witness, Archivista, in-toto) is mature and CNCF-governed, but the commercial Judge policy platform is still developing, limiting full platform maturity.
A $6.4M seed round plus selection for both DHS S&T's national SVIP cohort and an AFWERX SBIR Phase 1 award are real independent signals, though modest in scale for the company's stage.
Builds its core technology as open standards (in-toto) rather than a proprietary black box, addressing the federally mandated SBOM/build-provenance requirement (EO 14028) in a way that avoids vendor lock-in.
Independently validated through DHS/CISA's competitive selection process and CNCF's governance acceptance of its open-source tools, but no named commercial enterprise case studies were found; evidence is concentrated in government pilots.
Software supply chain provenance and SBOM enforcement are fast-growing, federally mandated priorities (EO 14028, NIST SSDF), placing this squarely in a high-relevance category for CISOs facing these requirements.
Why CISOs Should Care
Addresses federally mandated SBOM and software supply chain provenance requirements using an open-standards (in-toto) foundation rather than a proprietary black box, reducing vendor lock-in for compliance-driven programs.
What Makes It Different
Built its core attestation technology as open source (in-toto, Witness, Archivista, now CNCF subprojects) rather than a closed commercial product, and was independently selected by DHS S&T/CISA for its national SBOM tooling initiative.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A technically credible, open-source-rooted player in the nascent software supply chain security space with real federal validation, but still an early-stage company whose commercial platform and broad enterprise proof points are less mature than its open-source technical standing suggests.
Editorial Note: Claims vs. Verified Findings
The DHS SBIR/SVIP award amounts and the January 2024 CNCF/in-toto donation are independently documented via government and CNCF sources. The $6.4M seed round and investor list are self-reported by the company in its own funding announcement and not independently audited. No named enterprise commercial customers were found publicly; current evidence is concentrated in government pilots and open-source ecosystem contributions.
Sources
Alternatives to TestifySec
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…