Skip to content

TestifySec

Open-source-rooted software supply chain security platform providing cryptographic build attestation, SBOM generation, and CI/CD policy enforcement.

Visit Website ↗ + Add to Compare
62/100Incremental Innovator

Overview

TestifySec builds software supply chain security tooling centered on cryptographic build attestation. Its open-source core — Witness (an attestation framework implementing the in-toto specification), Archivista (attestation storage), and the Judge policy engine — captures and signs evidence at each step of a CI/CD pipeline, then lets organizations enforce policy and generate SBOMs (software bills of materials) based on verifiable proof of how software was actually built, rather than a self-reported manifest.

Founded in 2021 and headquartered in Jasper, Alabama, TestifySec was selected by the Department of Homeland Security’s Science and Technology Directorate (S&T) as one of seven startups nationally for its Silicon Valley Innovation Program cohort focused on software supply chain visibility, receiving a $199,990 award to extend its SBOM generation and policy/admission-control capabilities for DevOps pipelines. The company separately won an AFWERX SBIR Phase 1 award from the Department of the Air Force for FLiCK, a forensic license-compliance tool. It raised a $6.4 million seed round led by Mucker Capital, with Dreamit Ventures and a Jefferies family office also participating.

In January 2024, TestifySec donated Witness and Archivista as official subprojects of in-toto, bringing them into the Cloud Native Computing Foundation ecosystem, and the company’s engineers hold maintainer and steering-committee roles across in-toto, TUF, Witness, Archivista, and the newer SBOMit project.

The company’s credibility currently rests heavily on government pilot work and open-source governance standing rather than a large public roster of commercial enterprise customers, which is typical for a young company building infrastructure-layer security tooling around an emerging, federally-driven compliance mandate (SBOMs and build provenance under Executive Order 14028).

Innovation Matrix Assessment

Innovation Velocity 7/10

Progressed from stealth to donating Witness and Archivista as CNCF/in-toto subprojects in January 2024 while continuing to win new federal SBIR/SVIP awards, showing an active technical roadmap.

Operational Value 5/10

The open-source attestation core (Witness, Archivista, in-toto) is mature and CNCF-governed, but the commercial Judge policy platform is still developing, limiting full platform maturity.

Market Momentum 6/10

A $6.4M seed round plus selection for both DHS S&T's national SVIP cohort and an AFWERX SBIR Phase 1 award are real independent signals, though modest in scale for the company's stage.

Category Disruption 6/10

Builds its core technology as open standards (in-toto) rather than a proprietary black box, addressing the federally mandated SBOM/build-provenance requirement (EO 14028) in a way that avoids vendor lock-in.

Real-World Efficacy 5/10

Independently validated through DHS/CISA's competitive selection process and CNCF's governance acceptance of its open-source tools, but no named commercial enterprise case studies were found; evidence is concentrated in government pilots.

Enduring Relevance 8/10

Software supply chain provenance and SBOM enforcement are fast-growing, federally mandated priorities (EO 14028, NIST SSDF), placing this squarely in a high-relevance category for CISOs facing these requirements.

Why CISOs Should Care

Addresses federally mandated SBOM and software supply chain provenance requirements using an open-standards (in-toto) foundation rather than a proprietary black box, reducing vendor lock-in for compliance-driven programs.

What Makes It Different

Built its core attestation technology as open source (in-toto, Witness, Archivista, now CNCF subprojects) rather than a closed commercial product, and was independently selected by DHS S&T/CISA for its national SBOM tooling initiative.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

A technically credible, open-source-rooted player in the nascent software supply chain security space with real federal validation, but still an early-stage company whose commercial platform and broad enterprise proof points are less mature than its open-source technical standing suggests.

Editorial Note: Claims vs. Verified Findings

The DHS SBIR/SVIP award amounts and the January 2024 CNCF/in-toto donation are independently documented via government and CNCF sources. The $6.4M seed round and investor list are self-reported by the company in its own funding announcement and not independently audited. No named enterprise commercial customers were found publicly; current evidence is concentrated in government pilots and open-source ecosystem contributions.

Sources