Attesta
Deterministic compliance and auditable evidence
Deterministic compliance evaluation, signed attestations, and auditable evidence workflows for regulated teams.
Discuss a projectWhat it is
Attesta combines a Rust-based Universal Compliance Engine with an operational console for versioned rulepacks, reproducible evaluations, signed attestations, evidence review, remediation, drift monitoring, and chain of custody.
Attesta is engineered both as a standalone compliance product and as a reusable trust layer for Dorico Dynamics workflows, including selected ledger controls, reporting, and document-integrity paths. It does not govern every InfraNotes transaction.
Capabilities
Evaluation and rulepacks
Deterministic CEL-based evaluation against versioned and signed rulepacks, with evaluation history, details, and execution graphs.
Evidence workflows
Manual evidence submission, collected-evidence and evidence-pack workflows, assertions, native registration, evidence review, remediation, and POA&M.
Attestations and reports
Signed attestations and reports, with chain verification over the evidence path in scope.
Monitoring and drift
Monitoring, drift detection, health, and DORA-oriented incident surfaces.
Tenancy and administration
Tenants, keys, certificates, API keys, usage, plans, and entitlements. Console routes are plan-, role-, and entitlement-aware.
Who it is for
- Compliance and risk officers.
- Security and platform engineers.
- Internal and external audit teams.
- Regulated financial-service and operational teams.
These are supported personas and designed audiences, not evidence of current customers.
Technical proof
- Deterministic CEL evaluation in a Rust engine, with versioned and signed rulepacks.
- CLI, gRPC, and Rust crate interfaces to the same engine.
- PostgreSQL state with S3/MinIO WORM-oriented evidence storage.
- OpenTelemetry instrumentation and webhook delivery.
- React 19 and Vite console using Connect Web, React Flow, and TanStack tooling, with Vitest, Playwright, and accessibility checks in CI.
- Fail-closed evaluation invoked inside the InfraNotes core-ledger journal transaction path.
- Sealing and verification exposed on InfraNotes document-version routes.
Availability and scope
The Attesta console currently carries staging and preproduction GitOps declarations. The compliance engine has a production-target declaration, but the production overlay trails the current repository version. Readiness should be assessed from current gates rather than from the existence of a manifest.
Current limitations
- The platform is not generally available and is not described as production-ready.
- Cloud, identity, Git, Kubernetes, and SFTP connectors are not production-certified. Connector foundations and executable support matrices are incomplete, and the connector administration UI has not been started.
- Automated evidence collection is not implied by the manual and native evidence screens.
- AML foundations, SAR filing, Travel Rule, and regulator submission are not operational.
- Regulatory output packs have not been started.
- Framework coverage is not claimed as fully supported on the basis of rule files alone.
- Historical throughput and latency figures are not current service levels.
- Attesta does not provide guaranteed compliance, legal admissibility, regulator approval, or certification.
- The differentiator is deterministic evaluation, not AI-powered compliance.