TestifySec
Open-source-rooted software supply chain security platform providing cryptographic build attestation, SBOM generation, and CI/CD policy enforcement.
Visit Website ↗ + Add to CompareOverview
TestifySec builds software supply chain security tooling centered on cryptographic build attestation. Its open-source core — Witness (an attestation framework implementing the in-toto specification), Archivista (attestation storage), and the Judge policy engine — captures and signs evidence at each step of a CI/CD pipeline, then lets organizations enforce policy and generate SBOMs (software bills of materials) based on verifiable proof of how software was actually built, rather than a self-reported manifest.
Founded in 2021 and headquartered in Jasper, Alabama, TestifySec was selected by the Department of Homeland Security’s Science and Technology Directorate (S&T) as one of seven startups nationally for its Silicon Valley Innovation Program cohort focused on software supply chain visibility, receiving a $199,990 award to extend its SBOM generation and policy/admission-control capabilities for DevOps pipelines. The company separately won an AFWERX SBIR Phase 1 award from the Department of the Air Force for FLiCK, a forensic license-compliance tool. It raised a $6.4 million seed round led by Mucker Capital, with Dreamit Ventures and a Jefferies family office also participating.
In January 2024, TestifySec donated Witness and Archivista as official subprojects of in-toto, bringing them into the Cloud Native Computing Foundation ecosystem, and the company’s engineers hold maintainer and steering-committee roles across in-toto, TUF, Witness, Archivista, and the newer SBOMit project.
The company’s credibility currently rests heavily on government pilot work and open-source governance standing rather than a large public roster of commercial enterprise customers, which is typical for a young company building infrastructure-layer security tooling around an emerging, federally-driven compliance mandate (SBOMs and build provenance under Executive Order 14028).
Innovation Matrix Assessment
Progressed from stealth to donating Witness and Archivista as CNCF/in-toto subprojects in January 2024 while continuing to win new federal SBIR/SVIP awards, showing an active technical roadmap.
The open-source attestation core (Witness, Archivista, in-toto) is mature and CNCF-governed, but the commercial Judge policy platform is still developing, limiting full platform maturity.
A $6.4M seed round plus selection for both DHS S&T's national SVIP cohort and an AFWERX SBIR Phase 1 award are real independent signals, though modest in scale for the company's stage.
Builds its core technology as open standards (in-toto) rather than a proprietary black box, addressing the federally mandated SBOM/build-provenance requirement (EO 14028) in a way that avoids vendor lock-in.
Independently validated through DHS/CISA's competitive selection process and CNCF's governance acceptance of its open-source tools, but no named commercial enterprise case studies were found; evidence is concentrated in government pilots.
Software supply chain provenance and SBOM enforcement are fast-growing, federally mandated priorities (EO 14028, NIST SSDF), placing this squarely in a high-relevance category for CISOs facing these requirements.
Why CISOs Should Care
Addresses federally mandated SBOM and software supply chain provenance requirements using an open-standards (in-toto) foundation rather than a proprietary black box, reducing vendor lock-in for compliance-driven programs.
What Makes It Different
Built its core attestation technology as open source (in-toto, Witness, Archivista, now CNCF subprojects) rather than a closed commercial product, and was independently selected by DHS S&T/CISA for its national SBOM tooling initiative.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A technically credible, open-source-rooted player in the nascent software supply chain security space with real federal validation, but still an early-stage company whose commercial platform and broad enterprise proof points are less mature than its open-source technical standing suggests.
Editorial Note: Claims vs. Verified Findings
The DHS SBIR/SVIP award amounts and the January 2024 CNCF/in-toto donation are independently documented via government and CNCF sources. The $6.4M seed round and investor list are self-reported by the company in its own funding announcement and not independently audited. No named enterprise commercial customers were found publicly; current evidence is concentrated in government pilots and open-source ecosystem contributions.
Sources
Alternatives to TestifySec
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…