Evidence Events across the SDLC

Know the story behind every production change.

What changed, who did it, and who approved it? Those facts already live in your issue tracker, git host, CI, and cluster — then they expire, disagree, or cannot be reconstructed. Evitrus captures them as signed Evidence Events, correlates them into a Change, and lets you search it, export it, or evaluate controls against it.

The facts of how you ship are trapped.

Software organizations already produce the story of how work is planned, built, tested, and shipped. It is scattered across Linear, GitHub, CI logs, deploy consoles, and chat. When production breaks, on-call needs that story in minutes. A year later, an auditor still asks what shipped, who approved it, and which controls were in place — and nobody can answer it from one place.

Observe your SDLC — independent of the exact tools that you are using

Evitrus is not your issue tracker, CI, or cluster. We observe how you plan, build, test, and ship as Evidence Events from the tools you already use — whatever those are. Those events join into a Change you can search, export, or evaluate — and, if you opt in, use to stop a non-compliant production rollout.

Three ways to consume a Change

Search. Export. Evaluate.

Search · Changelog

What shipped in this window?

On-call needs a changelog for a service and environment, not a tour of five vendor UIs. One row per Change; deploys — including failed, blocked, and rolled-back — as lines inside it.

Search · Audit log

Prove what happened, to whom, when.

When auditors ask for evidence of what you shipped a year ago, who approved it, and which controls were in place — your answer is one query away, instead of digging through the logs of ten different systems for the next week.

Export · Data Export

Take your events with you. Any time.

Evitrus is not a lock-in tool. If you want to leave, feed a lake, or take your own backups, you can use our data export — in a simple JSONL plus manifest format.

Evaluate · Controls

Pass, fail, or not applicable — live.

Continuously judge controls against the same Change, with the evidence that justifies each verdict. Optionally stop a production rollout on breach.

How it works

One pipeline. Facts in, stories out.

Events are named by lifecycle step, not by vendor. GitHub, Linear, Kubernetes, and ECS are sources. Plan, Build, Test, Deploy, and Operate are steps.

Plan Build Test Deploy Operate
  1. 1

    Exporters observe

    They map a native payload to the Evidence Event envelope and push it to Ingest. They do not produce changelogs, verdicts, or exports. No application code changes.

  2. 2

    Ingest signs. Correlate joins.

    Every accepted event is hashed and cryptographically signed. Facts are immutable — a correction is a new event. Ingested events are then correlated into Changes, outlining the full story of what happened.

  3. 3

    Search, export, or evaluate

    Changelog and Audit log query Changes. Data Export serializes the event log. Controls produce pass / fail / na — and customer-hosted evaluators can deny a ship.

Linear GitHub webhook GitHub Actions Kubernetes ECS (EventBridge) Alert receiver

Live evaluation

See exposure continuously — not once a year.

See which controls are passing as soon as evidence lands — and open the Change that justifies each verdict. In addition to provided compliance packs (e.g. SOC 2) you can build your own custom enforcements — and have the same controls applied.

  • Know your posture while you ship, not only when an auditor asks
  • Show why a control passed or failed, with the backing evidence
  • Start from a pack such as SOC 2, then add the rules that match how you work
  • Evitrus evaluates evidence. You still own the audit report.

Production enforcement

Stop a rollout when a bound control fails.

A GitHub Actions step or Kubernetes admission in your environment asks Evitrus at the deploy boundary — independent from the exporter for that source. Enabling a pack includes the gate unless you switch it off, and you control whether an evaluation failure should stop or allow the rollout.

  • Block production on a failed control, not on a missing integration
  • A blocked deploy is recorded as evidence, so you can see why it stopped
  • A blocked rollout can be force-approved with break-glass mechanisms

Boundaries

What Evitrus is not

  • Not a ticketing, sprint, or change-advisory board Evitrus works with Evidence Events emitted from the tools you already use — it does not replace them.
  • Not a CI/CD runner or a second git host We observe builds and deploys as they happen in your pipeline. We do not run CI or host your repositories.
  • Not a SIEM or log warehouse competing on volume We keep the facts of how you ship — not every log line your systems produce.
  • Not a GRC tool that attests the audit program We evaluate evidence and can gate production. We do not run your audit calendar or sign your SOC 2 report.
  • Not an incident commander, pager, or status page On-call uses Evitrus to see what changed right now. Paging, war rooms, and public status stay in the tools you already have.
  • Not a second source of truth for PRs, tickets, or clusters Linear, GitHub, and Kubernetes remain the systems of record. Evitrus is the trail of what they emitted.

Built for the buyers who scrutinize vendors hardest

Signed facts. Germany-hosted. Your boundary at the edge.

Immutable, signed events

Ingest never acknowledges an event it did not store. Each accepted body is hashed and signed. Search, Export, and Evaluate look at those bytes. Wrong correlation moves an event to another Change — it does not edit the fact.

Hosted in Germany

Evitrus is a SaaS hosted in Germany. Customer-hosted exporters run in your CI and cluster and authenticate with an API key you manage. Webhook sources bind to a workspace secret. Ingest sees events, not your SCM token.

Least privilege, strong tenancy

Exporters read the event surface they need — nothing more, and no write-back into your tools. Every query is tenant-scoped. Roles and permission keys are evaluated server-side.

Closed beta

Request access to the Evitrus closed beta

We're onboarding a small number of design-partner engineering teams. This form does not create an account. Tell us a little about you and we'll be in touch.

By submitting, you agree that we may contact you about the beta. See our privacy policy.

Get started

Open Evitrus and follow a Change