Every governance decision is a signed fact
- Every artifact has cryptographically verifiable in-toto Statements sealed in a Dead Simple Signing Envelope (DSSE).
- No build can falsify its own signed facts because the server generates attestations independently.
- Retain full control over the chain of trust by supplying your own signing keys.
- Answer any compliance question from signed records, not by assembling data across different systems.
