§1
The audit trail your scanners and your compliance vendor both forgot to give you.
Attestable keeps an append-only, cryptographically signed ledger of every vulnerability your team detects and resolves — and turns it into evidence packs your insurer, auditor, or enterprise prospect can independently verify.
§2
The artifact
An excerpt from our own ledger — Displace runs Attestable on Displace. Structure exact; this is what your insurer sees.
| recorded (utc) | cve | package | sev | disposition | entry hash |
|---|---|---|---|---|---|
| 2026-06-02T09:14:33Z | CVE-2026-21847 | jackson-databind | critical | patched · PR #431 | sha256:e3b1…a94c |
| 2026-06-04T16:47:02Z | CVE-2026-22910 | urllib3 | high | patched · PR #438 | sha256:77d0…3f2e |
| 2026-06-09T11:03:58Z | CVE-2026-23155 | lodash | medium | dismissed · dev-only dependency, not shipped | sha256:4ba9…c101 |
| 2026-06-11T08:22:19Z | CVE-2026-23590 | openssl | high | patched · PR #445 | sha256:1fc7…88de |
| 2026-06-16T19:55:41Z | CVE-2026-24102 | next | critical | patched · PR #452 | sha256:b52a…07f3 |
| 2026-06-20T13:31:07Z | CVE-2026-24688 | pg (node-postgres) | medium | patched · PR #459 | sha256:c9e4…512b |
| 2026-06-24T10:08:26Z | CVE-2026-25071 | golang.org/x/net | high | patched · PR #463 | sha256:08aa…d6e9 |
| 2026-06-27T17:40:12Z | CVE-2026-25344 | pillow | medium | open · triaged, SLA 30d | sha256:f21c…4b70 |
| chain verified · 0 gaps · signed ed25519 · anchored 2026-07-18T22:14:07Z | |||||
- CVEs surfaced
- 147
- dispositioned in SLA
- 139
- MTTR (high)
- 6.4 days
- open material
- 1
This is the deliverable. A PDF pack plus a machine-verifiable attestation — verify it yourself with our published key.
§3
The gap
-
Your scanners find vulnerabilities and your engineers fix them. Neither produces a record anyone else can rely on. Dependabot alerts get closed; PRs get merged; the history is scattered across repos, and none of it is attested by anyone.
-
Compliance platforms cost $10–20k a year and answer a different question — whether you have controls, not whether you remediated the specific vulnerabilities your tools surfaced this quarter. Their evidence is a screenshot of your settings page.
-
Then the questionnaire arrives. "Demonstrate your vulnerability management process." GitHub archaeology on a deadline is not evidence. It is a weekend, and it convinces no one.
If you have an insurance renewal or security questionnaire in the next 6 months, you are exactly who this is for.
§4
How the pilot works
-
001
You grant read-only access (a fine-grained PAT) or run our export script — your choice. We never need write access to anything.
-
002
We import 12 months of history — disclosed in the ledger as imported, never disguised as live-recorded — then maintain the chain weekly from that point forward.
-
003
You get a weekly digest of material items: what was detected, what was resolved, what is aging toward an SLA boundary.
-
004
When the questionnaire lands, you request a pack. You get a PDF and a signed attestation JSON, usually within two business days.
What this is not
Attestable is not a scanner, not a compliance platform, and not a certification or audit. It is a signed record of observed remediation activity, produced by a named practitioner who stakes a professional reputation on its accuracy. If your process has gaps, the ledger will show the gaps. That is the point.
§5
Founding terms
| onboarding | $1,500 one-time — 12-month history import, materiality review, first signed pack within 5 business days |
|---|---|
| maintenance | $499/mo, or $4,000/yr (annual default) — weekly digest, continuous chain + anchoring |
| founding seats | 5 — 30% off maintenance for as long as you stay ($349/mo · $2,800/yr) |
| packs | on demand, ≤1/mo included |
| exit | cancel anytime — you keep your full ledger and the verification tooling |
| insurance | COI on request |
§6
Request a founding seat
Five seats. If you hold a live trigger — a renewal date, a questionnaire, a deal in diligence — say so; those go first.
§7
Verify
How do I verify a pack?
Every pack ships with an attestation JSON, a PDF, and a ledger excerpt. Fetch verify.sh and our public key from keys.displace.tech and run it — it checks the pin, the hash chain, the ed25519 signature, and the OpenTimestamps anchor, offline:
sh verify.sh attestation.json evidence-pack.pdf attestable-2026-a.pub ledger-excerpt.jsonl
What access do you need?
Read-only. A fine-grained GitHub PAT scoped to security events and pull requests, or the output of our export script if you'd rather not grant a token. We never request write access.
Where does my data live?
Encrypted at rest on infrastructure we control. Never on GitHub, never sold, never used to train anything. Deleted on request, and the deletion is itself a ledger event.
What happens if I cancel?
You keep your full ledger and the verification tooling. Every entry signed while you were a customer stays verifiable forever — the signatures do not expire when the subscription does.
Is this SOC 2?
No. SOC 2 attests that your controls exist; Attestable attests that specific remediation happened, with proof. A pack can serve as supporting evidence for vulnerability-management criteria in an audit, but it is not a certification, and we will not pretend otherwise.