Auditor
Auditor certifies and guarantees only this: the listed checks were executed by Auditor on this exact release (hash), under the published criteria (script versions), and the result is signed by Auditor. Everything needed to audit that claim is published. Whether to trust it is up to the reader.
Release hash and, when applicable, the artifact hash. An attestation is valid only for that build; any other build is outside its scope.
Every check is a script in the public catalog, identified by id, version and sha256. What ran is what is published, nothing else.
Each attestation is signed by Auditor with a published Ed25519 key at the recorded time. Anyone can check it without an account.
Automated checks executed in a sandbox with AI assistance; not a human audit and not an accreditation. The result is a verifiable record of what ran and how it ended.
No repository permissions needed. Add one line to your deployment.
| curl -fsSL https://adt.p-sf.com/cli.sh | sh -s -- attest --wait |
The first time, upload the source from the app and audit it in three steps. From then on, the line at the end of your deployment uploads the pre-build source through a signed single-use URL and starts the run. No GitHub App, no read token, no webhook; it never blocks your deploy.