TestifySec
TestifySec is a cloud-native security and compliance platform that converts CI/CD pipelines into cryptographically signed audit evidence, automatically mapping to NIST 800-53, FedRAMP, SOC 2, ISO 27001, and EU CRA frameworks for technology companies and government contractors.
- Company typePrivate
- Founded2023
- HeadquartersJasper, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What TestifySec does
TestifySec, Inc. is a Delaware-incorporated, Jasper, Alabama-headquartered software company founded in 2021 (with one source referencing 2023) that builds an evidence-driven security and compliance platform. Its core technology observes CI/CD pipelines running on GitHub Actions, GitLab CI, Jenkins, Tekton, and Docker; wraps build, test, and deployment steps with cryptographic attestations signed via Sigstore Fulcio OIDC; and stores those attestations in a graph engine (Archivista) for compliance verification. The platform auto-maps pipeline evidence, IaC, source code, and scanner output to NIST 800-53, FedRAMP (Low/Moderate/High), SOC 2 Type II, ISO 27001, NIST 800-171, and EU CRA controls using a RAG-based AI agent (TestifyGPT), and pushes the resulting evidence into Vanta, Drata, or Secureframe or exports OSCAL bundles for auditors.
The product surface spans the commercial TestifySec Platform with its Customer Cloud authorization-boundary module, an AI Assistant for natural-language auditor queries, and a suite of open source projects — Witness (in-toto attestation runner), Archivista (attestation graph store), cilock (pipeline observer with credential-leak detection and Rego policy enforcement), Rookery (Aflock AI modular attestation core), and cilock-action. The business model is primarily SaaS subscription at $65/user/month with a 14-day free trial, supplemented by a multi-year FedRAMP accessible gap-analysis package (positioned at roughly one-tenth the cost of traditional consulting), annual self-hosted deployments for regulated environments, and channel revenue from MSPs and defense contractors. GTM combines product-led growth (self-serve trial, AWS Marketplace listing, AWS ATO partnership) with enterprise field sales targeting compliance decision-makers at technology companies seeking first certifications, cloud-native firms pursuing federal authorization, government contractors handling CMMC/FedRAMP, and managed service providers delivering multi-tenant compliance-as-a-service.
The company maintains the in-toto project within CNCF after donating Witness and Archivista as official subprojects in January 2024, co-authored NIST SP 800-204D through Director of R&D Frederick Kautz, and was selected by DHS and CISA in 2024 for the Protobom Initiative alongside Lockheed Martin and NYU. It is privately held and venture-backed, having raised $6.4 million in September 2023 from Mucker Capital and Dreamit Ventures; named customer and partner logos include Autodesk, Datadog, Best Buy, Adobe, Farmer's Insurance, Precisely, GitLab, Lockheed Martin, GDIT, Carahsoft, and Sigstore.
TestifySec firmographics
Firmographics- Name
- TestifySec
- Legal name
- TestifySec, Inc.
- Website
- https://testifysec.com
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- TestifySec is a cloud-native security and compliance platform that converts CI/CD pipelines into cryptographically signed audit evidence, automatically mapping to NIST 800-53, FedRAMP, SOC 2, ISO 27001, and EU CRA frameworks for technology companies and government contractors.
- Ownership category
- akta.pro rank
TestifySec industry classification
Industry- Product category
- Compliance Automation / Software Supply Chain Security
- NAICS
- Computer Systems Design and Related Services (5415), Custom Computer Programming Services (541511)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC), Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where TestifySec is headquartered
LocationHeadquarters
- HQ city
- Jasper
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
TestifySec business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription Licensing: SaaS subscription model with per-user pricing at $65/user/month. Includes access to the TestifySec platform, evidence collection, control mapping, and compliance framework coverage. Self-hosted deployment available for regulated environments at higher price points.
- FedRAMP Gap Analysis Package: Entry-level package providing AI-powered gap analysis for FedRAMP authorization, control coverage assessment, and baseline SSP generation. Positioned as accessible alternative to traditional $100K+ consultant engagements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Per seat | Monthly | Standard platform subscription at $65/user/month with access to all core features, evidence collection, and compliance framework mapping. |
| Subscription | Multi-year contract | FedRAMP 'Get Started' accessible package providing gap analysis, control coverage assessment, technical gap identification, and baseline SSP generation. |
| Subscription | Annual | Self-hosted deployment for regulated environments requiring on-premise compliance infrastructure. |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels7 records
TestifySec product offering
Product offeringCore offering
TestifySec sells a SaaS platform that observes CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and security tools (Snyk, Semgrep, Trivy) to produce cryptographically signed attestations from every build, test, and deployment. The platform automatically maps that evidence to compliance controls across NIST 800-53, FedRAMP (Low/Moderate/High), SOC 2, ISO 27001, NIST 800-171, and EU CRA, generates System Security Plans (SSPs) and POA&Ms with AI, and syncs to Vanta/Drata/Secureframe. It is sold as a per-seat subscription ($65/user/month) plus a FedRAMP gap-analysis package, with optional self-hosted deployment for regulated environments.
Product overview
TestifySec is an evidence-driven security and compliance platform that transforms CI/CD pipelines into continuous compliance engines. The core offering is the TestifySec Platform, which integrates with GitHub Actions, GitLab CI, Jenkins, Snyk, Semgrep, and Trivy to capture cryptographically signed attestations from every build, test, and deployment. The platform supports compliance frameworks including NIST 800-53, FedRAMP, SOC 2, ISO 27001, and EU CRA. Customer Cloud provides an authorization boundary for managing multiple repositories under a single SSP. The open source portfolio includes Witness (attestation framework implementing in-toto), Archivista (graph database for attestations), cilock (pipeline observer for supply chain security), and Rookery (modular attestation core). TestifyGPT AI agent generates SSPs from IaC configurations, while the AI Assistant provides natural language access to compliance evidence.
Differentiator
Problem solved
Functional benefit
Brands
- Witness: Open source attestation framework for generating cryptographically signed attestations from CI/CD pipelines, ensuring software supply chain integrity
- Archivista
- Aflock AI
- cilock
- TestifyGPT
Products and services
- TestifySec Platform SaaS platform that observes CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and security tools (Snyk, Semgrep, Trivy) to produce cryptographically signed attestations and automatically map them to NIST 800-53, FedRAMP, SOC 2, ISO 27001, and EU CRA. Targets enterprise security, engineering, and GRC teams.
- Customer Cloud Authorization-boundary module that covers multiple connected repositories (web app, API gateway, identity, billing, data plane) under a single System Security Plan with live attestation feeds and continuous compliance monitoring.
- Witness Open-source attestation framework implementing the in-toto specification; cryptographically signs and verifies evidence from CI/CD pipelines. Used by developers and security teams building supply-chain integrity into build pipelines.
- Archivista Graph-based storage and query engine for in-toto attestations, exposing a GraphQL API for traceability and complex supply-chain provenance queries.
- cilock Open-source pipeline observer that wraps CI/CD steps with cryptographic attestation, detects credential leakage through content scanning and behavioral analysis, and enforces action pinning via Rego policy evaluation.
- cilock-action GitHub Action version of cilock that delivers prevention, content detection, and behavioral detection layers to catch credential leakage and enforce action pinning policies in CI/CD pipelines.
- TestifyGPT AI agent that uses Retrieval-Augmented Generation to map pipeline evidence to NIST 800-53 controls and auto-generate control narratives and POA&M entries from Infrastructure as Code repositories, producing auditor-ready System Security Plans.
- AI Assistant Natural-language AI compliance help feature that answers auditor questions in English, drafts POA&Ms, summarizes changes since the last audit, and provides real-time control coverage analysis directly from the evidence base.
- Rookery Modular attestation core and framework for AI attestations, part of the Aflock AI open-source project built by TestifySec.
- FedRAMP "Get Started" Gap Analysis Package Accessible FedRAMP package providing AI-powered gap analysis, control coverage assessment, technical gap identification, and baseline SSP generation; positioned at roughly one-tenth the cost of traditional consulting engagements and sold on a multi-year contract.
Quantifiable outcome
- Reduces FedRAMP authorization from 18 months to 2 weeks
- +6 more outcomes
Companies that use TestifySec
Customer profileNamed customers10 records
Segments4 records
Ideal customer profiles3 records
TestifySec technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration18 records
AI capability6 records
Feature7 records
TestifySec partnerships and signals
Strategic signalPartnerships
20 partnerships are on record, tiered core, secondary and minor.
- in-toto (CNCF)coreWitness and Archivista donated as subprojects under in-toto, ratified by steering committee and integrated into CNCF ecosystem. TestifySec team maintains in-toto project and drives standards development.
- Amazon Web Services (AWS)coreAWS Marketplace listing for TestifySec procurement. AWS Authority to Operate on AWS Program partner recognized for accelerating customer path to FedRAMP authorization. Native integrations with AWS services including EKS.
- Open Source Security Foundation (OpenSSF)coreActive leadership in OpenSSF Security Toolbelt and participation in working groups for Securing Software Repositories. Contributing to supply chain security standards and best practices.
- Cloud Native Computing Foundation (CNCF)coreHost organization for in-toto project. TestifySec contributes to CNCF ecosystem through specification development and project maintenance.
- SigstorecoreIntegration with Sigstore for keyless signing using Fulcio OIDC identity and Sigstore TSA timestamps. Enables cryptographic proof of artifact integrity without long-lived key management.
- GitHubcoreGitHub Actions integration for CI/CD evidence collection. Attestations generated from GitHub workflow runs with Fulcio OIDC signing tied to GitHub Actions identity.
- GitLabcoreGitLab CI integration for continuous evidence collection and attestation generation from GitLab pipeline runs.
- JenkinssecondaryJenkins CI/CD integration for organizations using Jenkins-based build infrastructure.
- Defense UnicornssecondaryIntegration partner for defense-focused supply chain security solutions.
- DaggersecondaryIntegration for portable CI/CD pipelines using Dagger.
- SnykcoreSecurity scan integration for vulnerability scanning evidence collection and attestation.
- SemgrepcoreSAST (Static Application Security Testing) integration for code scanning evidence collection.
- TrivycoreContainer vulnerability scanning integration for SBOM and CVE evidence collection.
- Lockheed MartincoreCollaboration partner in Protobom initiative for next-generation SBOM format and tooling. Working alongside NYU to create Protobomit tool for enhanced software bill of materials management.
- National Institute of Standards and Technology (NIST)coreTestifySec Director of R&D co-authored NIST SP 800-204D, the federal standard for DevSecOps integration and continuous compliance evidence. Contributed to Software Supply Chain Best Practices paper.
- VantacoreGRC sync integration. TestifySec pushes evidence to Vanta for customers maintaining existing Vanta workflows while gaining cryptographic verification layer.
- DratacoreGRC sync integration for Drata customers wanting to leverage TestifySec's cryptographic evidence while maintaining Drata platform.
- SecureframecoreGRC sync integration enabling Secureframe customers to import TestifySec attestations into their compliance workflows.
- NYU (New York University)minorAcademic collaboration partner in Protobom SBOM initiative alongside Lockheed Martin.
- DHS / CISA SVIPcoreSilicon Valley Innovation Program (SVIP) collaboration for Protobom next-generation SBOM format development. Selected from thousands of applicants for next-generation security tools development.
Scale indicators8 records
Recent moves6 records
Expansion highlights5 records
TestifySec competitors and assessment
Company assessmentDirect peers
- Chainguard: Chainguard secures the software supply chain through hardened base images and provenance tooling. It is a direct competitor to TestifySec's supply-chain attestation and SBOM-centric compliance approach, targeting the same cloud-native and federal buyer.
- Sonatype: Sonatype provides SBOM, component intelligence, and supply-chain security for open-source dependencies. It overlaps with TestifySec's SBOM and provenance capabilities (including Protobom-adjacent tooling) and serves similar regulated enterprises.
- Anchore: Anchore offers SBOM generation, container compliance, and policy-as-code enforcement for software supply chains. It competes with TestifySec in federal, DoD, and FedRAMP-adjacent workflows where attestation and container integrity are required.
- Kusari: Kusari builds supply-chain security and compliance tools including GUAC (Graph for Understanding Artifact Composition), focused on SBOM-centric visibility and policy enforcement—directly comparable to TestifySec's Archivista graph and attestation layer.
Emerging players
- Socket: Socket detects supply-chain attacks and malicious packages in open-source dependencies. It addresses a narrower developer-security use case than TestifySec but converges on supply-chain integrity for cloud-native engineering teams.
- Ox Security: Ox Security provides application security testing with supply-chain and pipeline-integrity modules. Its ASPM platform partially overlaps with TestifySec's attestation and control-mapping capabilities for engineering-led security buyers.
Broad incumbents
- Vanta: Vanta is a leading automated compliance/GRC platform supporting SOC 2, ISO 27001, HIPAA, and FedRAMP. While TestifySec integrates with Vanta via GRC sync, Vanta's breadth and scale make it the dominant incumbent in TestifySec's adjacent category.
- Drata: Drata automates SOC 2, ISO 27001, HIPAA, and other compliance audits with continuous control monitoring. Like Vanta, it is a GRC incumbent and integration partner to TestifySec, but could extend into attestation-native features.
- Secureframe: Secureframe provides compliance automation for SOC 2, ISO 27001, HIPAA, PCI, and FedRAMP readiness. As another GRC sync partner of TestifySec, it competes for the same compliance-driven buyer and could absorb attestation workflows.
- Snyk: Snyk is an established developer-security platform spanning SAST, SCA, container, and IaC scanning. TestifySec integrates Snyk as evidence input, but Snyk's scale and roadmap could encroach on TestifySec's attestation and policy-as-code territory.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
TestifySec social profiles
Digital presenceTestifySec compliance and trust
Trust signalCompliance9 records
TestifySec financial estimates
Financial estimateRevenue estimate
Valuation estimate
TestifySec leadership team
Management profileNumber of profiles
Profiles3 records
TestifySec funding detail
Funding detailFunding overview
Funding rounds1 record
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
TestifySec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about TestifySec
What does TestifySec do?
TestifySec sells a SaaS platform that observes CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and security tools (Snyk, Semgrep, Trivy) to produce cryptographically signed attestations from every build, test, and deployment. The platform automatically maps that evidence to compliance controls across NIST 800-53, FedRAMP (Low/Moderate/High), SOC 2, ISO 27001, NIST 800-171, and EU CRA, generates System Security Plans (SSPs) and POA&Ms with AI, and syncs to Vanta/Drata/Secureframe. It is sold as a per-seat subscription ($65/user/month) plus a FedRAMP gap-analysis package, with optional self-hosted deployment for regulated environments.
Is TestifySec a public or private company?
TestifySec is a private company. It is classified as venture growth investor backed and is currently operating.
When was TestifySec founded?
TestifySec was founded in 2023. It employs 11 to 50 people.
Where is TestifySec based?
TestifySec is headquartered in Jasper, United States, in the North America region.
How does TestifySec make money?
Two revenue lines are on record. Subscription Licensing is the primary driver. The others are fedRAMP Gap Analysis Package.
Who are TestifySec's main competitors?
Direct peers on record are Chainguard, Sonatype, Anchore and Kusari. Emerging players are Socket and Ox Security. Broad incumbents are Vanta, Drata, Secureframe and Snyk.
Does TestifySec have an API?
No public API is recorded for TestifySec.
What industry is TestifySec in?
TestifySec's product category is Compliance Automation / Software Supply Chain Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 5415 and its SIC code is 7372.