What shipped in this window?
On-call needs a changelog for a service and environment, not a tour of five vendor UIs. One row per Change; deploys — including failed, blocked, and rolled-back — as lines inside it.
Evidence Events across the SDLC
What changed, who did it, and who approved it? Those facts already live in your issue tracker, git host, CI, and cluster — then they expire, disagree, or cannot be reconstructed. Evitrus captures them as signed Evidence Events, correlates them into a Change, and lets you search it, export it, or evaluate controls against it.
Software organizations already produce the story of how work is planned, built, tested, and shipped. It is scattered across Linear, GitHub, CI logs, deploy consoles, and chat. When production breaks, on-call needs that story in minutes. A year later, an auditor still asks what shipped, who approved it, and which controls were in place — and nobody can answer it from one place.
Evitrus is not your issue tracker, CI, or cluster. We observe how you plan, build, test, and ship as Evidence Events from the tools you already use — whatever those are. Those events join into a Change you can search, export, or evaluate — and, if you opt in, use to stop a non-compliant production rollout.
Three ways to consume a Change
On-call needs a changelog for a service and environment, not a tour of five vendor UIs. One row per Change; deploys — including failed, blocked, and rolled-back — as lines inside it.
When auditors ask for evidence of what you shipped a year ago, who approved it, and which controls were in place — your answer is one query away, instead of digging through the logs of ten different systems for the next week.
Evitrus is not a lock-in tool. If you want to leave, feed a lake, or take your own backups, you can use our data export — in a simple JSONL plus manifest format.
Continuously judge controls against the same Change, with the evidence that justifies each verdict. Optionally stop a production rollout on breach.
How it works
Events are named by lifecycle step, not by vendor. GitHub, Linear, Kubernetes, and ECS are sources. Plan, Build, Test, Deploy, and Operate are steps.
They map a native payload to the Evidence Event envelope and push it to Ingest. They do not produce changelogs, verdicts, or exports. No application code changes.
Every accepted event is hashed and cryptographically signed. Facts are immutable — a correction is a new event. Ingested events are then correlated into Changes, outlining the full story of what happened.
Changelog and Audit log query Changes. Data Export serializes the event log. Controls produce pass / fail / na — and customer-hosted evaluators can deny a ship.
Live evaluation
See which controls are passing as soon as evidence lands — and open the Change that justifies each verdict. In addition to provided compliance packs (e.g. SOC 2) you can build your own custom enforcements — and have the same controls applied.
Production enforcement
A GitHub Actions step or Kubernetes admission in your environment asks Evitrus at the deploy boundary — independent from the exporter for that source. Enabling a pack includes the gate unless you switch it off, and you control whether an evaluation failure should stop or allow the rollout.
Boundaries
Built for the buyers who scrutinize vendors hardest
Ingest never acknowledges an event it did not store. Each accepted body is hashed and signed. Search, Export, and Evaluate look at those bytes. Wrong correlation moves an event to another Change — it does not edit the fact.
Evitrus is a SaaS hosted in Germany. Customer-hosted exporters run in your CI and cluster and authenticate with an API key you manage. Webhook sources bind to a workspace secret. Ingest sees events, not your SCM token.
Exporters read the event surface they need — nothing more, and no write-back into your tools. Every query is tenant-scoped. Roles and permission keys are evaluated server-side.
Closed beta
We're onboarding a small number of design-partner engineering teams. This form does not create an account. Tell us a little about you and we'll be in touch.