Skip to content
Developer-native compliance evidence

Know what shipped.
Prove what mattered.

Connect your source control to a product-level record of releases, dependencies, findings, and decisions. Keep the evidence behind every version close to the way you build software.

Built around your delivery stackGitLabGitHubCI/CD
Illustrative product preview
Products/Industrial Gateway/Releases

Release 3.8.0

Industrial Gateway · 05 Oct 2026

Snapshot recorded
1,482
SBOM components
2
High findings
6
Resolved since 3.7.0
Evidence trail4 records
✓CycloneDX SBOMCaptured
✓Commit & pipeline #18432Linked
✓Container image digestCaptured
!Vulnerability decisions2 to review

Example data for illustration · Product in development

Connected to
source control
Organized by
product
Preserved by
release
Ready to
explain and export

The missing connection

Security data exists.
The release story doesn't.

Your pipelines, scanners, issue trackers, and repositories each hold a piece of the picture. Reconstructing what was true at release time still takes manual work.

Today's scan cannot answer yesterday's question.

Dependencies, findings, and build systems all change. A historical release needs its own durable record.

01 / Fragmented sources

One product, many systems

Commercial products span repositories, services, images, and documentation.

02 / Missing decisions

A finding is only the start

Teams also need the owner, assessment, action taken, and evidence behind it.

The workflow

Evidence, built into the way you ship.

ReleaseProof is designed to turn the data already in your delivery workflow into a product-level release record.

01

Connect the sources

Bring GitLab or GitHub repositories together under the software product they actually belong to.

Repositories → product
02

Capture the release

Link commits, CI evidence, image digests, SBOMs, and vulnerability findings to a specific version.

Pipeline → evidence snapshot
03

Keep the context

Preserve the historical state and record how findings were assessed, mitigated, or resolved.

Decisions → durable record

Release-level memory

The record stays when the code moves on.

A release is more than a tag. Keep the build provenance, component inventory, known findings, and decisions together, so the answer is still there months later.

Versioned evidence tied to the product
Vulnerability state and decision history
Exportable evidence for review
Example release record

Industrial Gatewayv3.8.0

Recorded
Git commit
9ad31fe
Pipeline
#18432
SBOM
1,482 items
High findings
2 to assess
Dependency change3.7.0 → 3.8.0
−openssl 3.2.1
+openssl 3.2.3
+github.com/foo/bar 1.8.0
Snapshot · SBOM · findings · decision history · provenance

Illustrative data based on the ReleaseProof product concept.

What we're building

A clearer line from build to evidence.

Focused on the engineering evidence that software teams need to find, explain, and retain.

Product mapping

Connect multiple repositories and artifacts to the commercial product they support.

SBOM & dependencies

Retain the component inventory and see what changed between software versions.

Finding decisions

Track assessments, owners, remediation, and the reasoning behind each action.

Evidence packages

Assemble a traceable record for internal reviews and CRA preparation workflows.

Built for the CRA era

Make technical evidence easier to stand behind.

The EU Cyber Resilience Act raises the bar for product security documentation and vulnerability handling. ReleaseProof is being designed to support the evidence collection and operational workflows around those obligations.

The platform supports preparation and traceability; it does not determine legal compliance or replace expert review.

Frequently asked

A few useful distinctions.

Does ReleaseProof replace our scanners?+

No. The platform is designed to collect and connect scanner outputs, source control data, and release metadata, then retain the context and decisions that make them useful later.

Why organize around products instead of repositories?+

A shipped product often includes several repositories, services, images, or firmware components. A product-level view keeps their evidence together for each release.

Does it make a product CRA compliant?+

No tool can make that determination on its own. ReleaseProof is intended to help teams gather, maintain, and explain technical evidence while people remain responsible for assessment and decisions.

Who is it for?+

European software manufacturers and the engineering, product security, and compliance teams supporting their release process—especially those shipping B2B, industrial, embedded, or on-premise software.

ReleaseProof

Every release has a story.
Keep the evidence.

A more reliable way to answer what shipped, what was known, and what your team did about it.

Back to the overview