Overview
News
Technologies
Salaries
Products
People
Growth
Offices
Financials

Overview

CI/lock collects trusted telemetry across every checkpoint between commit and production — CI/CD builds, security scans (SAST/DAST/SBOM), runtime + cluster integrity (Falco, Linkerd mTLS, kube-bench), and continuous compliance (CSPM, FIPS, STIG).

News

News cilock.dev 3 months ago
The signed record we didn't have in March CI/lock
Two March attacks had the same shape - CI ran code it shouldn't have, with credentials it shouldn't have had, and nobody could prove what executed. That's the gap CI/lock closes.
Read more
Report
Blog 3 months ago
We took a real project to SLSA Level 3 in 75 minutes. This post is the build log
Most write-ups about supply-chain hardening are composed weeks after the fact, by someone who was not in the terminal when it happened. This one was written in the terminal, while it happened. The screenshots are timestamped from the build. If that sounds
Read more
Report