Software
Delivery,
Verified.
CDK generates cryptographically verifiable evidence for every software delivery event, enabling organizations to prove how software was built, approved, secured, and deployed.
- Identity
- Commit
- Review
- Approval
- Build
- Artifact
- Deployment
Software delivery is automated.
Trust is not.
Organizations deploy continuously, but the proof behind those deployments remains fragmented across disconnected systems.
The missing layer in modern software delivery.
Manual Evidence
Audit evidence is collected after the fact through screenshots, exports, and spreadsheets.
Fragmented Trust
Delivery history is distributed across source control, pipelines, cloud platforms, and security tools.
Limited Provenance
Organizations cannot always prove exactly how production software was created.
Vendor Dependency
Existing systems rarely provide portable, independently verifiable evidence.
The CDK Trust Graph
A cryptographically verifiable record of every event that transforms code into production software. Every relationship carries who, what, when, and how it was verified.
- Developer
- Commit
- Pull Request
- Approval
- Policy Decision
- Build
- Artifact
- Attestation
- Deployment
- Runtime
event: "deployment.approved" actor: "[email protected]" artifact: "release-2026.07" policy: "release-policy-v3" timestamp: "2026-07-28T09:41:00Z" signature: "8f92ab…" status: VERIFIED
A trust layer above existing delivery systems.
CDK does not replace your CI/CD platform. It observes delivery events and turns them into portable, verifiable evidence.
Three steps. Continuous proof.
Connect existing systems.
Collect delivery events without replacing current workflows or CI/CD tooling.
Create cryptographic proof.
Generate signed evidence for every event using open, portable standards.
Continuously prove trust.
Make delivery integrity visible to engineering, security, and audit — automatically.
Built on open foundations.
CDK does not create proprietary evidence. It creates portable trust signals.
Compliance becomes an output of trusted delivery.
Frameworks consume CDK's evidence — they don't require organizations to assemble it after the fact.
| Framework | Approval | Evidence | Traceability | Policy | Retention |
|---|---|---|---|---|---|
| SOC 2 | ✓ | ✓ | ✓ | ✓ | ✓ |
| ISO 27001 | ✓ | ✓ | ✓ | ✓ | ✓ |
| PCI DSS | ✓ | ✓ | ✓ | ✓ | ✓ |
| NIST 800-53 | ✓ | ✓ | ✓ | ✓ | ✓ |
| FedRAMP | ✓ | ✓ | ✓ | ✓ | ✓ |
| DORA | ✓ | ✓ | ✓ | ✓ | ✓ |
Trust infrastructure should be open.
The core of CDK — attestation generation, verification, standards-based evidence — is open source and free to run.
- CI/CD integrations for GitHub, GitLab, Jenkins, and more
- Local evidence storage — no vendor lock-in
- APIs and SDKs for custom workflows
Enterprise assurance at scale.
Centralized evidence, policy management, and reporting across every team and environment.
Published, not proprietary.
CDK's architecture, trust model, and specifications are public by default.
Trust Graph Specification
The formal model for representing software delivery evidence as a verifiable graph.
Read spec →Evidence Model
How delivery events become signed, portable, independently verifiable attestations.
Read spec →Security Architecture
The cryptographic foundations behind CDK's evidence and verification design.
Read spec →Threat Model
What CDK protects against, and the assumptions its trust model depends on.
Read spec →Request for Comments
Open proposals shaping CDK's public specifications before they're finalized.
View RFCs →Build software with proof.
CDK gives organizations continuous assurance over every change, every release, and every deployment.