Diagrid
Back to Compliance & Audit
Compliance & Audit

How can an auditor validate the integrity of the Catalyst execution engine itself?

Catalyst's control plane emits signed attestations covering build provenance and runtime integrity, giving auditors a verifiable baseline. This leverages software supply chain provenance data and runtime monitoring to prove the engine has not been tampered with. Mechanism: An in-toto-style chain links build manifests, source code hashes, and deployment measurements. Caveat: The auditor must trust Diagrid's signing key and the cloud provider's hardware attestation; physical tampering is not detectable.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all