TestifySec Announces Availability of JUDGE in AWS Marketplace
JUDGE enables a unified developer and cybersecurity governance experience to mitigate the risk of software supply chain attacks by integrating zero trust principles of observability and verification into software build pipelines. In
- Build pipeline observer - automates the collection of trusted telemetry across input, environment, action, and output to cryptographically verify supply chain metadata (telemetry) via signing that data with a self-managed key, a key from a Key Management Service (KMS), or an identity.
- Certificate Authority (CA) - enable an identity-based signature by authenticating and generating a short-lived key to create a short-lived certificate (only valid for 10 minutes) that then uses that certificate and key to sign the data, thereby removing the entire burden of key management, key rotation, etc.
- Time Stamping Authority (TSA) - provide cryptographic proof that your data was signed while the certificate was valid and verify provenance without relying on an external service, enabling artifact verification across disconnected (air-gapped) environments
- GraphQL data store - ability to manage storage, retrieval, and retention of software build pipeline attestations and trusted telemetry via a GraphQL API to facilitate either ad hoc or deploy-time compliance verification from developer commit to production deployment.
Customers will now have access to TestifySec's software supply chain attestation and compliance platform directly in
"Bringing JUDGE to
At the core of this are two key open-source components: Witness, a CI/CD pipeline observer that collects trusted telemetry for attestations, and Archivista, a trusted telemetry and attestation storage manager. Originally built and maintained by TestifySec, both open-source tools were donated to Cloud Native Computing Foundation (CNCF) as subprojects underneath the in-toto project.
"Supply chain attestations are the foundation of effective supply chain security and I believe Witness is the most comprehensive solution for generating build attestations,"
Continuous monitoring of software build pipeline trusted telemetry yields a lower residual risk of software supply chain attack by amplifying the Sec in DevSecOps and meets multiple NIST SP 800-53r5 security controls.
The availability of JUDGE in
To learn more about JUDGE and how it can secure your software supply chain, visit TestifySec's AWS Marketplace Listing or TestifySec's Website.
About TestifySec
TestifySec unifies developers and cybersecurity teams in the fight against software supply chain threats by embedding zero-trust governance principles into build pipelines. With a portfolio of both open-source and commercial products, TestifySec enhances transparency and accountability at each step of software and AI model generation processes, ensuring secure software for all.
Contact Information:
Director of Marketing and Outreach
[email protected]
View original content to download multimedia:https://www.prnewswire.com/news-releases/testifysec-announces-availability-of-judge-in-aws-marketplace-302137773.html
SOURCE TestifySec, Inc.
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Crypto stocks surge as Bitcoin short squeeze hits record $2.7B
- Amylyx prices $500M stock offering at $35.50 per share
- Backblaze prices upsized $175M convertible notes due 2031
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share