Skip to content
@TrustSignal-dev

TrustSignal

Evidence integrity infrastructure for compliance workflows. Signed verification receipts for audit-ready provenance.

TrustSignal

Evidence integrity infrastructure for compliance and audit workflows.

TrustSignal issues signed verification receipts so organizations can prove when evidence was created, where it came from, and whether it has changed - without replacing the system that collected it.


What TrustSignal Does

Compliance and audit teams rely on artifacts that pass through multiple systems. Without a durable integrity reference, provenance becomes difficult to validate during later review.

TrustSignal adds an integrity layer at the handoff point:

  • Signed verification receipts - issued at artifact ingestion, binding hash, source, control, and timestamp
  • Verifiable provenance - source metadata travels with the receipt from the start
  • Later integrity checks - compare the current artifact against the original receipt before audit review
  • Tamper detection - mismatch signals surface when a record no longer matches intake state
  • No workflow replacement - fits alongside Vanta, Drata, and existing GRC platforms via a clean API boundary

How It Works

POST /api/attest-evidence

{
  "source": "vanta",
  "artifact_hash": "sha256:93f6f35...",
  "control_id": "CC6.1",
  "timestamp": "2026-03-11T21:00:00Z"
}

-> Returns a signed receipt with verification signal and provenance metadata
-> Store receipt alongside the artifact
-> Verify again later when trust conditions matter

Built For

Use Case How TrustSignal Fits
Compliance evidence pipelines Attests artifacts at ingestion, returns signed receipts
Audit-readiness workflows Provides tamper-evident reference for later review
GRC platform integrations Sits behind Vanta, Drata, or internal collectors
Security and partner review Public API contract, claims boundary, and threat model available

Documentation

Resource Description
Developer Docs Verification lifecycle, API overview, architecture
API Overview Public request and response model
Security Model Claims boundary and public-safe controls
Threat Model Threat assumptions and review posture
Architecture Workflow fit and trust-boundary framing

Claims Boundary

TrustSignal provides signed verification receipts, verification signals, and verifiable provenance metadata.

TrustSignal does not provide legal determinations, compliance certification, fraud adjudication, or replacement for the system of record.


Contact

-> trustsignal.dev · Request a Pilot · info@trustsignal.dev

Pinned Loading

  1. TrustSignal-Verify-Artifact TrustSignal-Verify-Artifact Public

    GitHub Action that verifies build artifacts and issues signed TrustSignal verification receipts.

    JavaScript 2

  2. TrustSignal TrustSignal Public

    Evidence integrity infrastructure for compliance workflows. Signed verification receipts for audit-ready provenance.

    TypeScript 1

  3. TrustSignal-docs TrustSignal-docs Public

    TrustSignal Public Documentation

  4. TrustSignal-App TrustSignal-App Public

    Github app

    TypeScript 1

Repositories

Showing 6 of 6 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…