Evidence types
An SBOM lists components. Provenance describes how an artifact was built from source and materials. An attestation is an authenticated statement about an artifact. A signature binds an identity to bytes or a statement. Verification policy decides which identities, predicates, sources, builders, and results are acceptable.
Artifact binding
Bind every statement to an immutable artifact digest. Record producer identity, predicate type, scope, creation time, materials, and verification result. Promote the same digest across environments instead of rebuilding.
Decision use
Use an SBOM to find affected components, provenance to check build origin, attestations to carry test or review results, signatures to authenticate statements, and policy to allow or deny deployment. Each answers a different question.
Failure and residual risk
An authentic statement can be false or weak. An SBOM can omit runtime or generated components. Provenance can describe a compromised trusted builder. A signature does not prove safety. Policy can trust too many identities.
Pomerium boundary
Pomerium artifacts and guidance can be inputs to an operator's verification. Operators own their artifact source, images, configuration, deployment evidence, verification policy, exceptions, runtime inventory, and rollback.
Evaluation checklist
- Which exact artifact digest does each evidence item describe?
- Which claim does the SBOM, provenance, attestation, or signature make?
- Which producer and predicate does policy trust?
- Can deployment reject missing, stale, mismatched, or revoked evidence?
- Does runtime inventory prove the verified artifact is executing?
