Skip to content
Home

attestd

Provides deterministic security signals for software components: CVE risk classification, supply chain compromise status, and package name integrity (typosquat detection).

www.attestd.ioSecurity MonitoringJul 2026Toronto, CanadaMarshall Digital Solutions Ltd.

Launch screenshots from Product Hunt, Jul 2026

Attestd is a security API that provides deterministic risk signals for software components, addressing the problem of ambiguous vulnerability data that autonomous systems cannot act on. It serves developers, operations, and IT teams in organizations of all sizes, particularly those using CI/CD pipelines, infrastructure automation, and AI agents. The service is delivered as a cloud API with a free tier, offering three independent signals: CVE risk classification, supply chain compromise status, and package name integrity (typosquat detection).

Key features

  • CVE risk classification (critical, high, elevated, low, none)
  • Supply chain compromise status
  • Package name integrity (typosquat detection)
  • Deterministic signals (same version returns same result)
  • Worst-case aggregation for multiple CVE ranges
  • Continuous ingestion from NVD, CISA KEV, vendor advisories
  • Webhooks for supply chain compromise alerts
  • Coverage for 356 infrastructure products
  • Supply chain monitoring for PyPI and npm packages
Social posts
  • No social media activity within the last 30 days
GTM channels
  • Blog
  • Marketplace
  • API
  • Docs
ICP
  • Software developers
  • DevOps sre teams
  • Security teams