Attest ingests your repos & CI logs, auto‑fills the CISA Secure‑Software Development Attestation (SSDA) PDF, and signs it—so you breeze through FY 2025 audits.
Start Free WizardOAuth to GitHub / GitLab. No persistent token storage—just scoped, short‑lived access.
We orchestrate Syft, Trivy & Semgrep, then generate SSDF narratives.
Get a signed SSDA PDF + JSON evidence bundle. Attest can even push it to CISA’s RSAA API for you.
$999/mo
Up to 25 devs · 3 apps
$2,499/mo
Up to 100 devs · 10 apps
Custom
Unlimited devs & apps
Yes. We use GitHub/GitLab short‑lived OAuth tokens, read‑only scopes, and never persist your code. Scans run in single‑tenant containers that self‑destruct after processing.
Attest fills the exact PDF form issued by CISA in March 2024 (OMB M‑22‑18) and signs it with your org cert.
Most teams generate a draft in under 10 minutes after install. Final review and signature typically take < 1 hour.