product · security
divinate
collects and preserves technical evidence for security review and compliance.
| evidence | 03-02 | 04-06 | 05-04 | 06-01 |
|---|---|---|---|---|
| branch protection | recorded | recorded | recorded | recorded |
| required checks | recorded | recorded | changed since previous | recorded |
| review policy | recorded | recorded | recorded | changed since previous |
| release sbom | recorded | not available | recorded | recorded |
| azure branch policy | not available | not available | not available | not available |
divinate is in early development. it is open source and runs today, but its sources, outputs, and interfaces are still changing. there is no packaged offering yet.
keep your evidence up to date
security reviews and compliance reports make claims about how a team controls its code and releases. divinate keeps the evidence behind those claims, so a reviewer can point to it later.them, for example:
- whether a default branch requires review and passing checks before changes merge
- which checks a repository runs, and which of them are required
- what a release contains, from its software bill of materialssbom
- what changed between one collection and the next
how it works
a local store with provenance
evidence is collected into a local store. every item records where it came from and when.
retained history
no collection is overwritten, so a review can compare state and keep track of it over time.
gaps, reported as gaps
when evidence is missing or inaccessible, we record that too. even absence is data.
current sources
- github
- checks and, branch protection
- azure devops
- branch policies
- releases
- software bills of materialssboms
outputs
- dossier
- a markdown summary of the current evidence, its coverage, and its gapsevidence, coverage, gaps
- report export
- a report view for inclusion in a wider assessmentfor wider assessments
structurelicensing
- core
- open source, apache-2.0
- packs
- sources are added through external packs, which can carry their own licencesown licences
if you run security reviews or compliance, we’d like to hear what you examine.
contact@cyberwitchery.comnext steps
read the source
documentation covers setup, concepts, and the trust boundaries of the evidence store.
github.com/cyberwitchery/divinatetalk to us about an application
if you run security reviews or compliance and want to know whether divinate fits, we’d like to hear what you examine.
contact@cyberwitchery.com