Skip to content

Platform

Qualify evidence. Evaluate policy. Preserve the decision basis.

GoSentrix sits between the tools that produce signals and the release decisions that depend on them, and preserves the evidence and reasoning behind every qualified decision.

Verification lifecycle

Signals enter as unverified claims. Each stage below qualifies them further before an explicit decision is preserved.

Signal

Claim

Qualified evidence

Policy evaluation

Decision

Review record

Enforcement

Enforcement is introduced only after a release path has been qualified through an Evidence Readiness Assessment. The entry criteria are measurable and customer-defined.

Qualified paths only

Enforcement is gated on completed Evidence Readiness Assessment and defined entry criteria.

Explicit outcomes

Proceed, Stop, Escalate, or Require authorization. No hidden downgrades.

Escalation by default

Insufficient evidence escalates rather than silently allowing the action.

Decision records

Every consequential decision carries the inputs required to understand and reproduce it later.

FieldWhat it preserves
decision_idIdentifier for the decision record
policy_versionThe policy version active at decision time
evidence_snapshotThe qualified evidence that entered the policy evaluation
freshness_stateWhen each piece of evidence was last observed
outcomeProceed, Stop, Escalate, or Require authorization
downgrade_reasonWhy authority was narrowed if required proof was missing
reasoningThe policy rules and evidence that produced the outcome

Illustrative decision record

Synthetic example
Decision
Escalate
Evidence state
Insufficient proof
Policy version
Release policy v3
Inputs
scanner finding, ticket state, CI result, reviewer note
Basis preserved
Yes

Cryptographic signing and content-addressing are architecture targets, not field-proven claims.

What the platform is made of

Evidence qualification

Takes scanner output, test results, change records, and AI-agent claims as unverified inputs and qualifies them against source, freshness, and corroboration rules.

Policy evaluation

Evaluates qualified evidence against the active policy version for the release path.

Explicit outcomes

Emits Proceed, Stop, Escalate, or Require authorization based on the policy evaluation.

Decision history

Preserves the evidence, policy version, and reasoning behind each consequential decision.

Console

Where security, platform, and engineering leaders review decisions, evidence trails, and history.

Connectors

Pull signals from existing scanners, test systems, CI/CD platforms, and workflow tools.

What GoSentrix does, and what it doesn't.

Inputs GoSentrix qualifies

  • SAST, DAST, SCA, container, and IaC scanner output
  • AI coding and review agent output
  • Test and CI/CD results
  • Ticketing and workflow state

Outputs GoSentrix produces

  • Evidence qualification records
  • Policy evaluation outcomes
  • Decision-history records
  • Escalation and downgrade records

Controlled pilot

Controlled pilot: reducing release review from manual assertion to artifact-backed verification

A controlled pilot with anonymized participants tested whether release-evidence verification could replace manual review assertion with qualified, policy-bound evidence.

Starting condition

Release reviews relied on manual assertion: developers marked tickets closed, reviewers scanned checklists, and approvers relied on verbal assurance. Evidence was scattered across scanners, CI logs, ticketing systems, and chat threads.

What GoSentrix verified

Whether the evidence behind each release decision satisfied the customer’s versioned policy. We qualified scanner output, reviewer attestations, and AI-generated change records; flagged approvals unsupported by evidence; and preserved the reasoning for each verdict.

Artifacts produced

Policy-bound decision records, qualified evidence bundles, and explicit escalation notices for insufficient proof. Each record links the release candidate to the evidence evaluated and the policy version active at the time.

Time saved / manual review reduced

Reviewers spent less time reconstructing what had been checked. Instead of chasing evidence across systems, they reviewed a single, qualified evidence summary and the policy evaluation that followed.

Decision enabled

Proceed, stop, escalate, or require authorization — with a recorded basis. Teams could release with confidence when evidence satisfied policy, and escalate transparently when it did not.

Regulatory / security relevance

The preserved decision record supports audit requests, post-incident review, and regulated-release documentation. It shows what was known, what policy applied, and why the outcome followed.

What we do not claim

  • Guaranteed incident prevention or risk reduction.
  • Field-proven enforcement authority in every customer environment.
  • That artifact-backed verification replaces human judgment.
  • Customer outcomes; the pilot measures whether verification can reduce reliance on manual assertion, not whether it prevents breaches.

Read the full doctrine on what we will and will not claim.

Explore verification.

See how GoSentrix qualifies evidence, evaluates policy, and preserves the basis for your release decisions.