SOFTWARE DELIVERY ASSURANCE

Software
Delivery,
Verified.

CDK generates cryptographically verifiable evidence for every software delivery event, enabling organizations to prove how software was built, approved, secured, and deployed.

TRUST GRAPH — LIVE
  • Identity
  • Commit
  • Review
  • Approval
  • Build
  • Artifact
  • Deployment
Verified delivery chain

Software delivery is automated.
Trust is not.

Organizations deploy continuously, but the proof behind those deployments remains fragmented across disconnected systems.

THE GAP

The missing layer in modern software delivery.

01

Manual Evidence

Audit evidence is collected after the fact through screenshots, exports, and spreadsheets.

02

Fragmented Trust

Delivery history is distributed across source control, pipelines, cloud platforms, and security tools.

03

Limited Provenance

Organizations cannot always prove exactly how production software was created.

04

Vendor Dependency

Existing systems rarely provide portable, independently verifiable evidence.

THE SIGNATURE MODEL

The CDK Trust Graph

A cryptographically verifiable record of every event that transforms code into production software. Every relationship carries who, what, when, and how it was verified.

DELIVERY CHAIN
  • Developer
  • Commit
  • Pull Request
  • Approval
  • Policy Decision
  • Build
  • Artifact
  • Attestation
  • Deployment
  • Runtime
Verified delivery chain
EVIDENCE RECORD VERIFIED
event:      "deployment.approved"
actor:      "[email protected]"
artifact:   "release-2026.07"
policy:     "release-policy-v3"
timestamp:  "2026-07-28T09:41:00Z"
signature: "8f92ab…"
status:     VERIFIED
ARCHITECTURE

A trust layer above existing delivery systems.

CDK does not replace your CI/CD platform. It observes delivery events and turns them into portable, verifiable evidence.

GitHub
GitLab
Jenkins
Azure DevOps
CircleCI
CDK CORE
EVIDENCE GRAPH
Security
Compliance
Audit
Customers
HOW IT WORKS

Three steps. Continuous proof.

01 / OBSERVE

Connect existing systems.

Collect delivery events without replacing current workflows or CI/CD tooling.

02 / ATTEST

Create cryptographic proof.

Generate signed evidence for every event using open, portable standards.

03 / ASSURE

Continuously prove trust.

Make delivery integrity visible to engineering, security, and audit — automatically.

OPEN STANDARDS

Built on open foundations.

CDK does not create proprietary evidence. It creates portable trust signals.

Sigstore
Keyless signing
in-toto
Supply chain
SLSA
Build integrity
OIDC
Identity
OPA
Policy as code
OCI
Artifacts
COMPLIANCE

Compliance becomes an output of trusted delivery.

Frameworks consume CDK's evidence — they don't require organizations to assemble it after the fact.

FrameworkApprovalEvidenceTraceabilityPolicyRetention
SOC 2
ISO 27001
PCI DSS
NIST 800-53
FedRAMP
DORA
OPEN SOURCE

Trust infrastructure should be open.

The core of CDK — attestation generation, verification, standards-based evidence — is open source and free to run.

  • CI/CD integrations for GitHub, GitLab, Jenkins, and more
  • Local evidence storage — no vendor lock-in
  • APIs and SDKs for custom workflows
FOR CISOs & CTOs

Enterprise assurance at scale.

Centralized evidence, policy management, and reporting across every team and environment.

Organization Overview
94
Trust Score
18,204
Evidence Records
247 / 260
Policy Coverage
Recent Deployments
production / api-gatewayVerified
staging / billing-serviceVerified
production / auth-servicePending
RESEARCH

Published, not proprietary.

CDK's architecture, trust model, and specifications are public by default.

Specification

Trust Graph Specification

The formal model for representing software delivery evidence as a verifiable graph.

Read spec →
Model

Evidence Model

How delivery events become signed, portable, independently verifiable attestations.

Read spec →
Architecture

Security Architecture

The cryptographic foundations behind CDK's evidence and verification design.

Read spec →
Threat Model

Threat Model

What CDK protects against, and the assumptions its trust model depends on.

Read spec →
RFCs

Request for Comments

Open proposals shaping CDK's public specifications before they're finalized.

View RFCs →

Build software with proof.

CDK gives organizations continuous assurance over every change, every release, and every deployment.