cyberwitchery lab

product · security

divinate

collects and preserves technical evidence for security review and compliance.

example evidence ledger across four collections
evidence03-0204-0605-0406-01
branch protectionrecordedrecordedrecordedrecorded
required checksrecordedrecordedchanged since previousrecorded
review policyrecordedrecordedrecordedchanged since previous
release sbomrecordednot availablerecordedrecorded
azure branch policynot availablenot availablenot availablenot available
status

divinate is in early development. it is open source and runs today, but its sources, outputs, and interfaces are still changing. there is no packaged offering yet.

keep your evidence up to date

security reviews and compliance reports make claims about how a team controls its code and releases. divinate keeps the evidence behind those claims, so a reviewer can point to it later.them, for example:

  • whether a default branch requires review and passing checks before changes merge
  • which checks a repository runs, and which of them are required
  • what a release contains, from its software bill of materialssbom
  • what changed between one collection and the next

how it works

a local store with provenance

evidence is collected into a local store. every item records where it came from and when.

retained history

no collection is overwritten, so a review can compare state and keep track of it over time.

gaps, reported as gaps

when evidence is missing or inaccessible, we record that too. even absence is data.

current sources

github
checks and, branch protection
azure devops
branch policies
releases
software bills of materialssboms

outputs

dossier
a markdown summary of the current evidence, its coverage, and its gapsevidence, coverage, gaps
report export
a report view for inclusion in a wider assessmentfor wider assessments

structurelicensing

core
open source, apache-2.0
packs
sources are added through external packs, which can carry their own licencesown licences

if you run security reviews or compliance, we’d like to hear what you examine.

contact@cyberwitchery.com

next steps

read the source

documentation covers setup, concepts, and the trust boundaries of the evidence store.

github.com/cyberwitchery/divinate

talk to us about an application

if you run security reviews or compliance and want to know whether divinate fits, we’d like to hear what you examine.

contact@cyberwitchery.com