Where it sits¶
Most organizations already run some security tooling around their containers. Attest is not a replacement for it. Attest performs the one step none of them perform: the approval, with proof.
| Category | What it gives you | What it leaves you with |
|---|---|---|
| Detection tools | Findings, ranked, in one place | A list, and a person staring at unresolved risk with no way to dispose of it on the record |
| Hardened images | Cleaner ingredients for the parts you buy | Nothing about the parts you build |
| DevOps platforms | The substrate you build on; artifact storage | Raw pipeline output, log files, and markdown |
| CYBO Attest | The approval, with proof | A signed, attributed, evidence anchored authorization |
Already running some of these? Keep them. Fewer findings arrive, your platform stores the artifacts, and Attest performs the approval nobody else does.
Why none of them end in a decision¶
Finding a risk is not disposing of it. The disposition is what an auditor, a regulator, or a customer's security team is actually asking you to produce. A scan report says what was found. An authorization record says what was found, what was fixed, what was accepted, on what basis, and who decided. Only the second one closes the question.
What you have to change to use it¶
Connect your pipeline. Evidence publishes to your own private security repository in immutable, hash verified directories, and the review opens in the GitLab project your team already works in. Self managed or hosted, in your cloud or ours. See Connecting your pipeline.