












.webp)
.webp)
.webp)
A hash confirms an artifact wasn't altered in transit, but not that it came from a trusted build pipeline. Artifact Signing verifies both the integrity and the origin of every artifact, so only code produced by an approved pipeline can run.
Endor Labs' signing is built on many of the same principles as Sigstore, but keeps everything private to your tenant. There's no public transparency log exposing provenance metadata, and no separate PKI or identity system to deploy and manage.
Container images, application binaries, configuration files including infrastructure as code, media assets — any artifact you're willing to sign and verify.
At launch, your admission controller calls Endor Labs to confirm the artifact is signed by a trusted CA, the signature is valid, the provenance claims hold, and the version hasn't been revoked or blocklisted. Run-time checks can terminate and report unsigned or invalid artifacts.
No. endorctl establishes identity through secretless authentication in your AWS, GCP, or GitHub Actions runners — optionally backed by your SSO — and generates single-use ephemeral certificates. A few lines of pipeline config is all it takes to start.
Signature metadata links each artifact to its package, SBOM, VEX, and source git ref. Code-to-cloud tracing finds where a vulnerable version runs, and cloud-to-code tracing identifies an artifact's owner and build — turning a research task that took hours or days into minutes.