Attested Builds

Attested builds are a new approach to verifiable software distribution. Source code is compiled inside hardware-isolated environments that produce cryptographic proof linking binaries to their exact inputs.

Try an attested build to see how provenance is generated inside a confidential VM. Submit a GitHub repo URL or upload source code. We currently support Cargo and Nix builds (requires Cargo.lock or flake.lock).

Builds from GitHub repos are uploaded to a public registry of attested builds stored on Docker Hub. Browse attested builds or the Confidential VM disk image that uses Kettle to create attested builds.

Try: