SegAudit
Trust center

Supply chain

Signed images, a software bill of materials for every release, and how to verify them offline.

Every release image is built in CI, scanned, and signed before you download it.

Control Status Detail
Signed images In place Sigstore keyless signing (Cosign) from the CI pipeline; no long-lived signing key to steal
SBOM In place SPDX JSON software bill of materials, generated by Syft, for every image
Vulnerability gate In place Grype scan fails the build on any High or Critical finding
Pinned base image In place Base image pinned by SHA-256 digest
Checksums In place SHA-256 for every download
VEX statements Planned Exploitability notes for CVEs reported in dependencies that do not affect the product

Verify before you import

Check the signature and digest on a connected machine, then carry the verified tarball into the air gap. The verification guide has the exact commands.

Dependencies

Fonts and libraries are bundled into the image. The app makes no runtime requests to package registries or CDNs.

Last updated 2026-10-01.