Skip to content

Explainable AI for software authorization

CYBO Attest documentation

Attest makes the submission, review, and approval process transparent, traceable, and easy for applications navigating the ATO process.

If you are new here, the short version is this. Your pipeline scans every container build. Attest reads those results, works out what is blocking authorization, and shows each person exactly the part that concerns them. Developers see what to fix and how. Reviewers see what needs a decision, with the evidence and a plain language explanation beside it. Security leadership sees who decided what, when, and on what basis. Explainable AI does the explaining; a named person does the deciding.

The developer You build and ship containers. These pages cover connecting a project, reading your worklist, fixing or justifying findings, and getting a build submitted. Start here

The reviewer You make the authorization call. These pages cover the queue, reading a package, deciding each finding, and recording your authorization. Start here

The risk owner You answer for the decisions. These pages cover the posture view, what a decision record contains, and what to hand an auditor. Start here

Where to begin

  1. If you have not used Attest before, read What Attest is and The seven steps first. They take about ten minutes together.
  2. If you are setting it up for a team, go to Connecting your pipeline and then Sign in and roles.
  3. If you are looking something up, the Reference section has the gates, the scanners, every field in cdso_config.yml, and a glossary.

The console is at attest.ulapcybo.app. The capability brief is at ulapcybo.app/brief.html. If you have a question these pages do not answer, write to contact@ulap.co and someone will reply.