§1

The audit trail your scanners and your compliance vendor both forgot to give you.

Attestable keeps an append-only, cryptographically signed ledger of every vulnerability your team detects and resolves — and turns it into evidence packs your insurer, auditor, or enterprise prospect can independently verify.

§2

The artifact

An excerpt from our own ledger — Displace runs Attestable on Displace. Structure exact; this is what your insurer sees.

Sample vulnerability remediation ledger excerpt
recorded (utc) cve package sev disposition entry hash
2026-06-02T09:14:33Z CVE-2026-21847 jackson-databind critical patched · PR #431 sha256:e3b1…a94c
2026-06-04T16:47:02Z CVE-2026-22910 urllib3 high patched · PR #438 sha256:77d0…3f2e
2026-06-09T11:03:58Z CVE-2026-23155 lodash medium dismissed · dev-only dependency, not shipped sha256:4ba9…c101
2026-06-11T08:22:19Z CVE-2026-23590 openssl high patched · PR #445 sha256:1fc7…88de
2026-06-16T19:55:41Z CVE-2026-24102 next critical patched · PR #452 sha256:b52a…07f3
2026-06-20T13:31:07Z CVE-2026-24688 pg (node-postgres) medium patched · PR #459 sha256:c9e4…512b
2026-06-24T10:08:26Z CVE-2026-25071 golang.org/x/net high patched · PR #463 sha256:08aa…d6e9
2026-06-27T17:40:12Z CVE-2026-25344 pillow medium open · triaged, SLA 30d sha256:f21c…4b70
chain verified · 0 gaps · signed ed25519 · anchored 2026-07-18T22:14:07Z
CVEs surfaced
147
dispositioned in SLA
139
MTTR (high)
6.4 days
open material
1

This is the deliverable. A PDF pack plus a machine-verifiable attestation — verify it yourself with our published key.

§3

The gap

  1. Your scanners find vulnerabilities and your engineers fix them. Neither produces a record anyone else can rely on. Dependabot alerts get closed; PRs get merged; the history is scattered across repos, and none of it is attested by anyone.

  2. Compliance platforms cost $10–20k a year and answer a different question — whether you have controls, not whether you remediated the specific vulnerabilities your tools surfaced this quarter. Their evidence is a screenshot of your settings page.

  3. Then the questionnaire arrives. "Demonstrate your vulnerability management process." GitHub archaeology on a deadline is not evidence. It is a weekend, and it convinces no one.

If you have an insurance renewal or security questionnaire in the next 6 months, you are exactly who this is for.

§4

How the pilot works

  1. 001

    You grant read-only access (a fine-grained PAT) or run our export script — your choice. We never need write access to anything.

  2. 002

    We import 12 months of history — disclosed in the ledger as imported, never disguised as live-recorded — then maintain the chain weekly from that point forward.

  3. 003

    You get a weekly digest of material items: what was detected, what was resolved, what is aging toward an SLA boundary.

  4. 004

    When the questionnaire lands, you request a pack. You get a PDF and a signed attestation JSON, usually within two business days.

What this is not

Attestable is not a scanner, not a compliance platform, and not a certification or audit. It is a signed record of observed remediation activity, produced by a named practitioner who stakes a professional reputation on its accuracy. If your process has gaps, the ledger will show the gaps. That is the point.

§5

Founding terms

onboarding$1,500 one-time — 12-month history import, materiality review, first signed pack within 5 business days
maintenance$499/mo, or $4,000/yr (annual default) — weekly digest, continuous chain + anchoring
founding seats5 — 30% off maintenance for as long as you stay ($349/mo · $2,800/yr)
packson demand, ≤1/mo included
exitcancel anytime — you keep your full ledger and the verification tooling
insuranceCOI on request

§6

Request a founding seat

Five seats. If you hold a live trigger — a renewal date, a questionnaire, a deal in diligence — say so; those go first.

Scanners in use

e.g. insurance renewal, customer security questionnaire, enterprise deal in diligence

§7

Verify

How do I verify a pack?

Every pack ships with an attestation JSON, a PDF, and a ledger excerpt. Fetch verify.sh and our public key from keys.displace.tech and run it — it checks the pin, the hash chain, the ed25519 signature, and the OpenTimestamps anchor, offline:

sh verify.sh attestation.json evidence-pack.pdf attestable-2026-a.pub ledger-excerpt.jsonl

What access do you need?

Read-only. A fine-grained GitHub PAT scoped to security events and pull requests, or the output of our export script if you'd rather not grant a token. We never request write access.

Where does my data live?

Encrypted at rest on infrastructure we control. Never on GitHub, never sold, never used to train anything. Deleted on request, and the deletion is itself a ledger event.

What happens if I cancel?

You keep your full ledger and the verification tooling. Every entry signed while you were a customer stays verifiable forever — the signatures do not expire when the subscription does.

Is this SOC 2?

No. SOC 2 attests that your controls exist; Attestable attests that specific remediation happened, with proof. A pack can serve as supporting evidence for vulnerability-management criteria in an audit, but it is not a certification, and we will not pretend otherwise.