Connect the sources
Bring GitLab or GitHub repositories together under the software product they actually belong to.
Connect your source control to a product-level record of releases, dependencies, findings, and decisions. Keep the evidence behind every version close to the way you build software.
Industrial Gateway · 05 Oct 2026
Captured with this release and available as CycloneDX JSON.
Record assessment, owner, remediation state, and supporting evidence for each finding.
Example data for illustration · Product in development
The missing connection
Your pipelines, scanners, issue trackers, and repositories each hold a piece of the picture. Reconstructing what was true at release time still takes manual work.
Dependencies, findings, and build systems all change. A historical release needs its own durable record.
Commercial products span repositories, services, images, and documentation.
Teams also need the owner, assessment, action taken, and evidence behind it.
The workflow
ReleaseProof is designed to turn the data already in your delivery workflow into a product-level release record.
Bring GitLab or GitHub repositories together under the software product they actually belong to.
Link commits, CI evidence, image digests, SBOMs, and vulnerability findings to a specific version.
Preserve the historical state and record how findings were assessed, mitigated, or resolved.
Release-level memory
A release is more than a tag. Keep the build provenance, component inventory, known findings, and decisions together, so the answer is still there months later.
Illustrative data based on the ReleaseProof product concept.
What we're building
Focused on the engineering evidence that software teams need to find, explain, and retain.
Connect multiple repositories and artifacts to the commercial product they support.
Retain the component inventory and see what changed between software versions.
Track assessments, owners, remediation, and the reasoning behind each action.
Assemble a traceable record for internal reviews and CRA preparation workflows.
Built for the CRA era
The EU Cyber Resilience Act raises the bar for product security documentation and vulnerability handling. ReleaseProof is being designed to support the evidence collection and operational workflows around those obligations.
The platform supports preparation and traceability; it does not determine legal compliance or replace expert review.
Frequently asked
No. The platform is designed to collect and connect scanner outputs, source control data, and release metadata, then retain the context and decisions that make them useful later.
A shipped product often includes several repositories, services, images, or firmware components. A product-level view keeps their evidence together for each release.
No tool can make that determination on its own. ReleaseProof is intended to help teams gather, maintain, and explain technical evidence while people remain responsible for assessment and decisions.
European software manufacturers and the engineering, product security, and compliance teams supporting their release process—especially those shipping B2B, industrial, embedded, or on-premise software.
ReleaseProof
A more reliable way to answer what shipped, what was known, and what your team did about it.