Skip to content

Structured metadata

Schema-validated submissions in the formats your toolchain already speaks.

Speak the language of your supply chain

Vitrified validates every submission’s metadata against a declared schema and indexes it for query, browsing, and export. Your attestation registry is queryable by the same identifiers your build system, package manager, and downstream consumers already use.

Supported schemas

  • Package URL (purl) — ecosystem-aware package identifiers across npm, PyPI, Maven, Cargo, Go modules, Debian, RPM, OCI, and more.
  • OCI digest — container images and OCI artifacts with full registry/repository/digest identification.
  • Git artifact — commits, trees, blobs, tags with repository context.
  • SLSA provenance — full SLSA v1 predicate, including builder identity, build type, and materials.
  • in-toto attestation — in-toto v1 statement envelope with any predicate type, suitable for downstream cosign verify-attestation.
  • DSSE envelope — opaque DSSE payloads where the customer holds the signing key.
  • Generic — free-form structured metadata for cases that don’t fit a standard schema.

Validation is opt-in to indexing, not gating

Failed metadata validation does not waste your attestation. The hash is still queued and witnessed on schedule; the metadata is flagged as draft for correction. Stamping throughput is decoupled from metadata correctness so you never lose a witness window to a schema error.

Submission-time foot-gun warnings

If your declared file extension or metadata suggests your artifact will likely drift (.pdf, .docx, .heic), Vitrified surfaces a warning explaining the risk and suggesting remediations. The warning never blocks unless the declared type is almost certainly a mistake (.tmp, .swp) — and even then, an explicit override succeeds.

Get Started

Self-serve. Subscription with volume-scaled tiers. See pricing