witness

Prove what you did before you shipped.

  • Sealed before the dispute, not after
  • Held by someone other than you
  • Verifies without trusting us
  • Your source never leaves home
  • Go only, on purpose
RUNNING

WITNESS

33m27s elapsed 58,911 events

ENV darwin/arm64 · 10 cpus · 5 parallel

PROFILE FINAL · 2x test repeats · 84 packages · 4,941 test functions · 59 fuzz targets

BUDGET pkg cap 2h3m33s · test est 14m22s · fuzz budget 7m18s · bench budget 15m0s

LIVE ACTIVITY

TOOLS

PASSED14/14

passed
100%
TESTS

PASSED65,720/65,720

passed
100%
BENCH

RUNNING89/124

github.com/yourcompany/yourcodebase BenchmarkHost
72%
FUZZ

WAITING0/59

waiting
0%
LEDGER

RUNNING1.5 MiB/10 MiB

file 10 · 4.1 MiB current · 98 MiB total
15%
COMPLETION

WAITING0/9

waiting for run completion
0%

MODEFINAL

TESTS65,720 OK

BENCH89/124

RECORDSEALED

Continuous evidence

of continuous fuzzing

inputs tested

Last sealed
Peachy since
packages
targets

What it tests

Peachfuzz sends millions of malformed, unexpected, and adversarial inputs through the code.

Why it matters

It uncovers crashes and security flaws that ordinary tests can miss before customers encounter them.

Runs continuously. Every figure above comes from tamper evident, replayable run records.

Evidence model

Run locally. Seal it. Let us hold a copy of the proof.

Most teams can show that tests passed. Fewer can show it to a third party years later.

  1. 01

    Run locally

    Tests, benchmarks, profiles, and fuzz runs execute where your code lives. Your source never leaves home.

  2. 02

    Seal with Off Grid

    The run folds into a hash linked ledger, gets a timestamp from an authority that isn't us, and seals. We verify it and keep a copy.

  3. 03

    Recall from the vault

    Years later, an auditor, a buyer, or a court asks. You hand them a record instead of a recollection.

The problem

A green check is a claim. Not a record.

Enterprise security review tends to move past whether the code shipped and onto what ran before it did, and who besides you can vouch for the answer. Four specific problems stand between our tests pass and we can prove it. Witness exists because every team meets all four the first time someone asks.

Witness
01

Records made after the question are worth less

Anyone can produce a document once a dispute starts. Courts, auditors, and buyers discount it, because the one thing it cannot prove is that it existed before the trouble did.

  • When was this created?
  • Who has held it since?
  • Can anyone verify that?
02

Self held evidence proves almost nothing

CI retention is usually well run and usually accurate. What it cannot do is separate the record from the party who controls it, which is the same reason financial statements go to an outside firm.

  • Who besides you holds a copy?
  • Could an admin rewrite it?
  • Why should a stranger believe it?
03

Reconstructing the past is the expensive part

Audit prep and legal discovery turn into engineers rebuilding last year from CI scrollback, tickets, and screenshots. Companies spend millions producing records for a single case. Most of that is the price of not having kept them.

  • What ran a year ago?
  • Under which flags and budgets?
  • Where is the output today?
04

A green checkmark carries no detail

CI proves a job exited zero. It does not say which tools ran, at which versions, under which flags, or what was preserved. A second question about tool versions, flags, or retained output has to be answered from somewhere other than the badge.

  • Which gates actually ran?
  • What failed on the way?
  • What evidence survived?
Teams say
  • CI passed.
  • We have tests.
  • The ticket is closed.
Enterprise asks
  • Which tools ran?
  • Under which flags and budgets?
  • What failed, passed, and survived?
  • Who holds the proof?

Enterprise stakes

Contracts are won on evidence, not adjectives.

Enterprise customers buy trust, and trust gets reviewed. Every framework pushes the same question back onto engineering: prove the standards operated before the code shipped.

One run becomes a sealed evidence bundle.

  • human .md reports
  • machine .json reports
  • ledger + sidecars
  • profiles + fuzz evidence
  • timestamp receipts
  • Off Grid retained copy
  1. 01

    The buyer asks for proof

    Security review becomes evidence review: what ran, what failed, and what record existed before anyone asked.

  2. 02

    Witness captures the plan

    Profile, budgets, tools, versions, flags, and why each default exists. The recipe is part of the record.

  3. 03

    Witness preserves the work

    Tests, benchmarks, profiles, and fuzz output are retained with the result rather than discarded at the end of the job.

  4. 04

    Witness seals the record

    Hash linked events, manifests, attestation, timestamp receipts. Verifiable later, by anyone.

  5. 05

    People and machines both get proof

    Markdown for people. JSON for machines. Same facts.

  6. 06

    Off Grid holds the copy

    Your source and secrets stay home. We keep only the sealed result your agreement allows: the copy that still verifies when someone argues.

Honest scope

Witness proves what ran, what was preserved, and what still verifies. It does not certify your company, audit your controls, or promise perfect software. Nothing honest ever does.

Compliance map

Certifications rest on evidence someone else can check.

The certification itself is the smaller cost. The larger one is the evidence: sample requests with short deadlines, engineers pulled off the roadmap to hunt through CI logs, tickets, dashboards, and spreadsheets for runs that happened months ago, and screenshots assembled to stand in for records nobody kept. Then a customer questionnaire asks for the same material in a different format, and a surveillance audit asks again next year. Witness produces the evidence package while the work happens, so the answer already exists when the request arrives.

  • Sampled, not reconstructed
  • Records on demand
  • Sealed before the question
  • Answers the same afternoon
  • No audit week scramble

Five rooms, one question: prove it. Each of them needs an artifact rather than an assurance.

  1. 01 The request arrives

    A buyer, auditor, or assessor asks for SOC 2, ISO, FedRAMP, CMMC, or HIPAA evidence, with a deadline attached. Without a record, this is the point where engineering stops shipping and starts searching.

  2. 02 Local execution

    Engineers run tests, race, shuffle, count, benchmarks, profiles, fuzz, and respected Go security tools where the source already lives.

  3. 03 Sealed evidence

    Witness turns the run into human reports, machine JSON, ledgers, sidecars, hashes, artifacts, timestamps, failures, and profile proof.

  4. 04 3rd party recall

    Off Grid holds a sealed copy outside your systems, so the buyer verifies the record themselves instead of trusting the company that produced it.

  5. 05 Renewal evidence

    The next review asks again. Witness makes the certification record a repeatable operating habit instead of a once-a-year document hunt.

  • Enterprise buyers Security review before signing. Answer in an afternoon instead of a quarter.
  • Auditors Sampling your SOC 2 or ISO period. They sample a sealed record. No audit week scramble.
  • Insurers Pricing your cyber policy, or reviewing a claim. Diligence you can produce, not just assert.
  • Regulators After an incident, asking what you did beforehand. Produce records on demand instead of reconstructing them.
  • Your own counsel Discovery, once someone alleges negligence. A record sealed before the dispute, not after.

SOC 2 Type II

What it is
B2B SaaS and service companies use SOC 2 to prove controls operated over time. Enterprise buyers often treat it as table stakes before signing upmarket contracts.
How Witness helps
Your observation window documents itself. Every release seals its own record as it happens, so when the period closes the evidence is already there instead of being reconstructed from CI logs the week the auditor arrives.
Auditors get
Auditors get period evidence for change management, monitoring, testing, incident follow-up, and release discipline without rebuilding the story from screenshots.
Third party
Off Grid holds the sealed run copy, so the evidence an auditor checks does not depend on your CI vendor, your screenshots, or your internal storage.

ISO/IEC 27001

What it is
ISO/IEC 27001 is a security management baseline for international and enterprise sales. Certification runs on a three-year cycle with surveillance audits in between.
How Witness helps
Surveillance audits stop being a scramble. Each year of evidence is already sealed and portable, so you demonstrate that the process held steady across releases rather than rebuilding the story every cycle.
Auditors get
Auditors can inspect whether the testing process happened as designed and whether evidence remained stable across releases and surveillance periods.
Third party
Off Grid gives the certification body a 3rd party held verification path for ledgers, reports, hashes, attestations, and timestamp receipts.

FedRAMP

What it is
FedRAMP is the authorization path for cloud services selling to US federal agencies. The work is long, expensive, and evidence-heavy.
How Witness helps
Continuous monitoring becomes a by-product of shipping. Each release seals its own proof, so the evidence refresh your authorization depends on stops being a separate project with its own budget.
Auditors get
Assessors get continuous-monitoring evidence that is repeatable and verifiable instead of a one-time binder assembled after the fact.
Third party
Off Grid can keep an independent result copy for later recall, procurement review, incident response, or authorization evidence refresh.

CMMC

What it is
CMMC applies to defense contractors and subcontractors handling federal contract information or controlled unclassified information.
How Witness helps
System integrity evidence is bound to the exact code state, so an assessor can sample any release you shipped and the record still verifies years later at recertification.
Auditors get
Assessors can see that required technical gates operated and that evidence still verifies when sampled during assessment or recertification.
Third party
Off Grid gives assessors a retained 3rd party proof path that the system-integrity evidence existed and still verifies.

HIPAA

What it is
HIPAA applies to healthcare providers, plans, clearinghouses, and business associates that touch protected health information.
How Witness helps
You can prove periodic technical evaluation actually happened, and prove it without exposing anything sensitive, because the record covers the run and never touches protected health information.
Auditors get
Reviewers can ask what was evaluated, when it ran, what failed, what passed, and whether the record could have been altered later.
Third party
Off Grid holds the sealed record so a reviewer can verify it later, and the copy we hold contains no source code, no test code, no PHI, and no private customer data.

SSDF and federal attestation

What it is
Federal software producers are being asked to attest to secure development practices. A signature without technical evidence is weak.
How Witness helps
Your attestation stops resting on a signature alone. The person who signs it has technical evidence behind every claim, and a federal reviewer can check what ran instead of taking the signature on trust.
Auditors get
Reviewers get machine-readable JSON and human-readable reports that explain what was run and why the result can be checked later.
Third party
Off Grid holds the sealed copy so a federal reviewer can verify it independently, without us ever collecting source, tests, secrets, or customer data.

Cost ranges are market planning estimates, not quotes. Your scope, headcount, and assessor set the real number. Witness does not certify you; it automates and strengthens the technical evidence underneath certification so engineering is not forced to become the document-gathering department.

Who it is for

For whoever asks the awkward question after the meeting.

The buyer, the auditor, the insurer, the counsel, the incident reviewer. Witness exists for the person who says: show me.

One run leaves evidence you can hand over.

Success or failure, every run becomes a human report, machine JSON, a hash linked ledger, a timestamp receipt, and preserved proof.

Checks clean
14/14
Tests passed
65,720
Benchmarks passed
124
Fuzz passes
59
Ledger events
66,336
Sidecars verified
763/763

Security reviewers

Inspect the run itself, tools, versions, flags, and preserved output, instead of a summary of it.

Audit and compliance owners

Point SOC 2, ISO, CMMC, FedRAMP, or procurement evidence at a sealed record with hashes and timestamps.

Incident and legal teams

Failure evidence, repro commands, retained output, and an independent chain to argue from later.

Engineering leaders

See whether the quality recipe actually operated: race, shuffle, repeats, fuzzing, benchmarks, profiles, budgets.

The workflow

Seal every release. Recall it years later.

Your code runs on your machine. Witness writes the record. We keep the copy. The day it matters, nobody has to take your word for anything.

witness lifecycle

Command tape
  1. witness quiz
  2. witness test ./...
  3. witness midterm ./...
  4. witness final ./...
  5. witness mcat ./...
  6. witness verify witness_testimony/<run-id>_final/

Observed in /Users/d/code/fun

quiz / test / midterm

quiz / test / midterm

result: fail (auto_fail). Ledger, failures JSON, and human review are sealed.

final

final

66,336 ledger events. Tests, fuzz, profiles, manifests, anchors, and TSA receipt retained.

verify

verify

Chain, fold replay, completeness, and terminal event all verify.

  • Every profile writes a run folder under witness_testimony, profile named in the suffix.
  • Failed runs seal too: ledger, machine failures, and human review, instead of vanishing into CI scrollback.
  • Final runs retain tests, fuzz output, benchmarks, profiles, anchors, manifests, and timestamp receipts.
  • Verification replays the facts: chain, fold, completeness, sealed terminal event.

Generated files

artifacts/final_certificate.md

Human certificate

Reviewer-readable verdict: outcome, grade, policy, tool table, hashes, and verify status.

artifacts/final_certificate.json

Machine certificate

Typed form of the same verdict for automation, audit import, and later comparison.

artifacts/machine_attestation.json

Run attestation

The metrics bundle: checks, tests, benchmarks, fuzz passes, ledger events, and sidecar status.

artifacts/anchors/*.jsonl

Anchor ledger

Timestamp-ready records that bind retained files, hashes, and proof material to the run.

artifacts/retained_facts/*.jsonl

Retained facts

Sharded pass records and run facts that can be inspected without replaying CI memory.

checks/, benchmarks/, fuzz/

Raw tool output

Captured stdout, stderr, profiles, corpora, and crashers for the work the tool actually performed.

SHA256SUMS + index

Manifest

Digest map for the bundle, so missing or modified evidence is visible during verification.

timestamp.tsr + tsa.*

Timestamp receipt

Off Grid calls the TSA, records the time, and returns the receipt that proves when the bundle existed.

What it does

Your quality work, finally visible.

The tests, analysers, and benchmarks your team already runs are not visible to anyone outside the build. Witness runs Go's own machinery plus the analyzers serious teams respect, and records everything worth arguing about: tool, version, flags, diagnostics, outputs, and why each default exists.

Tool inputs

  • go test
  • race
  • shuffle
  • fuzz
  • benchmarks
  • profiles
  • govulncheck
  • staticcheck
  • nilaway
  • gosec
  • errcheck
  • deadcode
  • gocyclo
  • goconst
  • fieldalignment
Witnesstyped ledger

facts / hashes / replay

Sealed outputs

  • hash linked ledger
  • machine JSON
  • human report
  • SHA256 manifests
  • RFC 3161 timestamp
  • Off Grid retained proof

Tool dossier

What the run actually used.

Catalogued from the Witness check registry: defaults, streams, issue signals, and why each tool belongs in the evidence bundle.
  • native engine

    go test

    Compiles the target closure, runs the tests, and records JSON output, stdout, stderr, timings, and the repro command.

  • runtime discipline

    race + shuffle

    Race exposes data hazards. Shuffle exposes order dependence. The exact flags and seeds are sealed, so a reviewer can rerun the same claim.

  • performance evidence

    benchmarks + profiles

    Benchmarks run as evidence phases. CPU, memory, block, and mutex profiles are retained where the profile asks for them.

  • input pressure

    fuzz

    Fuzz targets run under profile budgets. Corpora, crashers, failing inputs, and repro commands are retained, not summarized away.

  • structured analyzer

    staticcheck

    JSON output, so rule IDs, severities, and locations stay machine-readable in the sealed bundle.

  • reachable vulns

    govulncheck

    Symbol-level scanning against the Go vulnerability database. OSV records and call-stack evidence are preserved.

  • nil-flow analysis

    nilaway

    Uber's nilaway as a real finding source: analyzer diagnostics are issues; package-load failures are tool errors, honestly classified.

  • security scanner

    gosec

    JSON findings with rule ID, CWE, severity, confidence, and location. Defaults skip fixture, vendor, generated, and test-only noise.

  • error discipline

    errcheck

    Finds unchecked errors in authored source, ignoring generated and vendored code by default.

  • reachability

    deadcode

    The Go tools deadcode pass, including test executables, so test-only call paths count.

  • complexity budget

    gocyclo

    Flags authored code over cyclomatic 10, skipping vendor, fixtures, tests, and generated files.

  • literal drift

    goconst

    Catches repeated production literals. Diagnostics define truth, not exit codes.

  • layout evidence

    fieldalignment

    The Go fieldalignment analyzer with tests included, so layout waste has nowhere to hide.

Works hand in glove with Go

It runs go test, then turns checks, benchmarks, profiles, and fuzz targets into one repeatable evidence habit.

Records typed facts

Every fact lands in a hash linked ledger: sequenced, validated, canonical.

Binds evidence to the revision

The record carries the Git commit and artifact hashes. The proof matches the exact code, not roughly the right week.

Folds facts into a verdict

Grades are computed from ledger facts, and the computation is replayable.

Publishes sealed bundles

One run, one bundle: ledger, manifests, attestation, receipts, reports, sidecars.

Ships as signed platform bundles

Official builds ship a tool bundle per platform for Linux amd64 and arm64, macOS arm64, and Windows amd64, each with SHA256 sums and a signed attestation.

Built reproducibly

Pinned versions, trimpath, VCS provenance, and CGO disabled, so the same source produces the same binary hash across rebuilds.

Creates 3rd party proof

Off Grid retains the sealed copy: independent proof the record existed and verified.

Evidence doctrine

One command. One policy. On the record.

Pick the profile that matches the moment. It carries the tools, flags, budgets, and retention rules. The recipe becomes a matter of record, not memory.

Evidence doctrine

Designed for scrutiny, down to the flags and versions.

Every setting exists because the artifact has to hold up in front of an engineer, a compliance owner, and counsel. Those three read the same artifact for different reasons, so it has to answer all three without a translation layer.

  • Ledger is source of truth

    The append-only ledger owns the truth. Reports and certificates are projections of the ledger, and verification fails if a projection no longer matches it.

  • Typed evidence or it does not count

    Facts are structs, closed enums, and validated schemas. The verifier refuses through 274 typed error identities, each naming the specific check that failed.

  • Verify by replay

    Verification replays the facts and rejects broken chains, drift, and mismatched sidecars. It runs offline against the bundle contents, so no party to the dispute has to be trusted.

  • Success and failure are symmetric

    A failed run publishes evidence too: repro commands, preserved output, explicit disclosure.

  • 3rd party proof matters

    An independent copy can be checked by a party who was not involved in producing it.

  • Nothing fails on judgement

    The verifier, the timestamp, the ledger, and the manifest each fail on mismatch rather than on judgement.

  • Evidence must survive

    Crashes, disk pressure, and seal failures do not erase evidence. A reserved ledger region guarantees the terminal record lands.

Settings table

Witness profile settings
ProfileWhen to use itTiming policyWhy it differs
witness quizFast affected feedback while an engineer or agent is still working.Race-scaled package timeout floor 20 minutes; aggregate safety floor 40 minutes; no benchmark or fuzz surface.Race and shuffle are on, affected targeting is on, and the loop is short enough to run before a change grows stale.
witness test ./...Normal development confidence across the requested target set.Race-scaled package timeout floor 25 minutes; aggregate safety floor 60 minutes; short benchmark and fuzz budgets.Two test repeats, race, shuffle, benchmarks, and fuzzing expose flaky tests, order dependence, data races, and input-sensitive failures before they become customer problems.
witness midterm ./...Broader pre-merge confidence when the change deserves more than the daily loop.Race-scaled aggregate safety floor 90 minutes; test budget floor 50 minutes; benchmark and fuzz budgets deepen from test.Keeps the same evidence surfaces as test, then gives them more room to expose flaky, slow, or input-sensitive failures.
witness final ./...Release-grade forensic evidence before production, customer delivery, or audit review.Race-scaled package timeout floor 40 minutes; aggregate safety floor 150 minutes; test budget floor 60 minutes.Verbose evidence, two repeats, race, shuffle, CPU profiles, memory profiles, and sealed artifacts create the record you expect to defend later. If one repeat fails, the failure is recorded.
witness soak ./...Long endurance pressure for code paths where flakes, heat, time, or resource behaviour matter.Package timeout floor 30 minutes; aggregate safety floor 24 hours; minimum duration 1 hour; max parallelism capped at 4.Benchmarks and fuzzing stay on for sustained pressure while race and shuffle are off to keep endurance runs stable.
witness mcat ./...Maximum confidence endurance run when the review bar is highest.Inherits soak intent with race and shuffle on; aggregate safety floor 24 hours; minimum duration floor 1 hour.Combines endurance pressure with race and shuffle so the record shows more than a quick green pass.
witness debug ./...Verbose local diagnosis when the operator needs to understand a run, not create a customer-facing release record.Race-scaled package timeout floor 25 minutes; aggregate safety floor 50 minutes; no benchmark or fuzz surface.Keeps race and shuffle on, turns verbose output on, and avoids heavier evidence surfaces.
witness verify <run-dir>Replay a sealed bundle from the run directory, ledger directory, or ledger file.Runs when evidence is challenged, handed to a reviewer, or recalled from storage.The ledger is canonical. Verification rejects broken chains, drifted manifests, mismatched sidecars, and report projections that no longer match the facts.

Profile times are authored policy floors and safety bounds. Witness derives the concrete run from the selected profile, discovered workload, target set, machine characteristics, and effective parallelism, then records the actual timings in the sealed bundle.

Proof record

Open the proof. See the whole run.

Witness keeps the tool flags, trust posture, retained copy, weak alternatives, and rollout path in one reviewable record.

Record details

sealed copy

Why trust Off Grid Software

You do not have to trust us for the evidence to hold.

Witness exists because we needed proof that BLINK was actually great, not merely green in a terminal. We built it for ourselves first, and the BLINK release record below is the one bundle we can show end to end.

  • Built for BLINK first

    It began as our own release standard. The current release seals its own evidence: 65,720 test passes, 59 fuzz targets, a 66,336 event ledger, verified at grade 100.

  • Makes existing discipline inspectable

    The tests, analysis, security checks, and benchmarks your team already runs stop being invisible. They become work a reviewer can examine instead of work you have to describe.

  • Independent retained copy

    A sealed copy lives outside your CI, your laptop, and your artifact store. Independent, when it counts.

  • Verification does not depend on us

    The bundle verifies offline. If an artifact changes, verification fails. We could vanish tomorrow and your proof would not.

  • The signing key is yours

    No shared key hides in the binary. Setup mints a fresh one on your machine, so the trust root is yours from the first run. We keep a copy of the proof, never the key that made it.

  • Timestamped before the argument

    RFC 3161 receipts, multiple authorities raced, trust roots embedded. The record is sealed before the argument starts.

  • Honest legal scope

    Witness records execution evidence, nothing more. Governing law, liability cap, and reliance limit travel inline with every sealed index.

  • Failure records count too

    We do not only stamp green runs. Failure records verify with the same discipline.

  • Custodian, not auditor

    An audit firm sells judgment. A custodian sells custody. We never grade your engineering. We hold the sealed record, prove it never changed, and let verification speak. The narrower promise is the one that survives cross examination.

Where it fits

The receipt nobody can rewrite unnoticed.

Keep everything you have. Witness does not certify companies or replace auditors. It gives everyone in the room something better to point at: a chain of custody for what ran, what was found, and what was sealed.

  • Keep CI for execution.
  • Keep Vanta, Drata, Secureframe, or other GRC tools for control management.
  • Keep scanners and analyzers for findings.
  • Keep auditors for certification.
  • Use Witness to prove what your gates actually did.
  • Use the retained copy for diligence, audits, and disputes.

Alternatives

What teams hand over today, and where it stops short.

Compare Witness against weak evidence, not against the tools that already run your jobs. The jobs are fine. The proof is the problem.

  • CI logs alone

    They show what the provider says happened. Hard to preserve, hard to verify, weak under challenge.

  • Screenshots and PDF exports

    A screenshot carries no hash, no chain, and no independently issued date, so it establishes content but not time or custody.

  • GRC platforms alone

    Vanta, Drata, and Secureframe organize controls well. They organize what you tell them. Witness gives them evidence that holds up when someone checks.

  • Scanners alone

    Scanners find issues. Witness proves the scan actually ran.

  • Artifact attestations alone

    Build provenance says where the artifact came from. Witness says what the tests did, including the failures.

  • Internal-only records

    Internal records are usually accurate and usually sufficient. The gap opens only when the other side asks who besides you can show the record existed before the dispute.

Enterprise rollout

Adopt beside the systems your team already trusts.

Start where the review pressure is real. Prove value on one narrow path. Widen when it earns it.

  • Founder-led evidence pilot

    One Go service, one workflow, one audit requirement. Your first sealed bundles.

  • CI and local developer workflow

    Drop the binary into CI. Run quiz while developing, final on release, with the Git commit bound into the result.

  • 3rd party record retention

    Choose which sealed copies Off Grid retains. An independent trail for when the stakes are high.

  • GRC and portal exports

    Feed the sealed artifacts to Vanta, Drata, auditors, customers, and trust portals.

  • Policy expansion

    Widen from one workflow to release gates, waivers, exceptions, and retention rules.

  • Self-hosted trust, your keys

    Own the signing authority, not just the data. Start with the key setup generates on your machine, move up to your own operator key, then a KMS or HSM where the private key never leaves your walls. Witness never holds it.

Buyer checklist

Questions worth asking any evidence tool.

Ask them of Witness too. Every answer below is checkable against a bundle you can run yourself.

  • Can a 3rd party verify the run without logging into your CI vendor?
  • Can an independent provider retain a sealed copy?
  • Does verification replay the facts and fail on drift?
  • Are failures, skips, and waivers explicit instead of hidden?
  • Are profiles, benchmarks, and retained binaries preserved as evidence?
  • When a run fails, do you get repro commands and preserved output?
  • Does it complement CI, scanners, and auditors instead of pretending to replace them?

When it matters

You do not need Witness when things go well.

You need it on the day someone asks what you did before you shipped. That day is usually scheduled by someone else.

  • SOC 2 readiness, ISO 27001, FedRAMP, or CMMC planning.
  • Enterprise security review asking for proof of testing.
  • Incident review where failed runs matter as much as green badges.
  • Government, defense, healthcare, or fintech procurement.
  • AI written code you cannot fully vouch for.
  • Anyone asking whether the evidence was changed after the fact.

Retention and custody

Custody is what makes a record checkable by someone else.

Companies do not audit their own books. The statements go to an outside firm because a record held only by the party being reviewed carries less weight, however accurate it is. Software evidence has the same problem, and custody is the fix: Witness seals the record on your machine, and Off Grid holds your locked copy as an independent custodian. Think escrow agent, notary, chain of custody. We do not own it, edit it, or grade it. We hold it, so you can produce proof when your customer, auditor, buyer, regulator, or court asks what happened.

Independent custody

Rolling 1 year on Bronze, 3 on Silver

For teams whose customer, buyer, auditor, or security reviewer needs to check the record without relying on the systems of the company being reviewed.

Witness runs on your machine and seals what happened there. Off Grid keeps your locked copy ready for download when proof is requested.

Retained
The sealed evidence bundle: reports, manifests, ledgers, hashes, timestamps, and verification metadata. Never source code. Never secrets.
Reason
A record held only inside your own systems carries less weight with a reviewer. The retained copy sits outside your CI trail and still belongs to you.
Guardrail
Once the retention window starts, the sealed copy is locked custody. It is not a file someone can quietly replace after the question arrives.

Customer proof

Rolling 10 years on Gold

For certification, recertification, procurement, and dispute work where the question is not what you claim, but what you can produce.

You can log in and retrieve the sealed Witness record from Off Grid when your customer, auditor, regulator, or court asks what happened.

Retained
A custody trail of what arrived, when it arrived, what account owns it, which Witness release produced it, which hashes identify it, and which locked copy backs it.
Reason
Proof has to survive the moment and the tool version. A 2026 bundle is interpreted with the 2026 Witness instrument that produced it, not reimagined by a future release.
Guardrail
You retrieve the record; Off Grid does not rewrite the story. Custody proves the receipt, not a fresh memory of the run.

Locked retention

Set by your plan and contract

For teams that need proof long after the build, review, incident, deal, certification, or lawsuit has moved on.

Bronze keeps the first audit year. Silver keeps the certification cycle. Gold keeps the long record for serious procurement, regulation, and legal exposure.

Retained
Each tier holds the window published on its plan card, and ten years on Gold is the ceiling we publish.
Reason
The value is not storage. The value is an independent copy nobody can quietly change, produced by Witness and held for the day someone asks.
Guardrail
Off Grid is the custodian, not the owner. The record belongs to you, and custody exists so you can produce it.

The vault, in plain terms

Witness creates the sealed record on your machine. Off Grid holds your locked copy so you can produce independent proof when a customer, auditor, buyer, regulator, or court asks.

  • Witness seals evidence on your machine.
  • Off Grid holds your locked copy.
  • Released Witness instruments are retained with their verifier material.
  • A bundle produced by Witness X is verified with Witness X.
  • Retention stops quiet deletion during the custody window.
  • You retrieve your own evidence after login.

The going rate

What proof already costs.

A price only means something next to the alternative. These are the figures companies already pay to be believed. Read them as invoices, then add the cost that never appears on one: the engineering weeks spent assembling the evidence behind each of them.

  • Weeks of it

    Senior engineering time, every cycle

    Evidence hunts, sample responses, and security questionnaires, taken off the roadmap and handed to someone who did not sign up for it. It never appears on the audit invoice and it is usually the largest line. Price it against your own salary bands.

    Your payroll, not a survey
  • Twice over

    Paid once to consultants, once to your own team

    Readiness consultants tell you which evidence to produce. Your engineers still have to go and produce it. The fee below buys the checklist, not the work.

    The line item nobody budgets
  • $60K to $100K

    SOC 2 Type II, year one

    Readiness, consultants, and the audit itself. Then $15K to $40K every year to keep the letter current.

    Linford & Company, SOC auditors
  • $900K

    FedRAMP authorization, on average

    That is the GAO's number, not ours. Staying authorized runs another $200K to $500K a year.

    U.S. GAO, report GAO-24-106591
  • $1.8M

    Discovery, in one lawsuit

    The median a major company spends producing records for a single case. Most of it is lawyers reading.

    RAND Corporation
  • $2.2B

    Recordkeeping fines since 2021

    Charged to over 100 firms by US regulators for one failure: records they could not produce.

    SEC & CFTC enforcement
  • $10.2M

    The average US data breach

    Investigation, notification, litigation, and a year of explaining yourself.

    IBM Cost of a Data Breach 2025
  • 1 in 3

    Vendors lose deals this way

    A missing certification stalls the contract, and the buyer rarely tells you that is why it went quiet.

    A-LIGN Compliance Benchmark

Hold those numbers. A full year of Witness on Bronze costs less than the annual upkeep on the SOC 2 letter alone, and a year at any tier costs less than one lawsuit's discovery. What you are buying is not compute. It is an independent copy of the proof, held somewhere you cannot quietly revise it, which is the part that stops being independent the moment you hold it yourself.

Pricing

Priced against the failure, not the test runner.

Every plan is billed monthly and buys the custody described above, for a different length of time. Three things carry across all three. Custody is rolling rather than prepaid, so the window holds while the subscription holds and cancelling in month three buys three months plus the export window rather than the full tier term. Your rate is locked from your start date for the whole of that window. And all sales are final: there are no refunds, credits, or prorated cancellations, so cancelling stops the next charge rather than returning the current one.

Honest. Up front. Predictable.

What each tier is for
Tier and windowWho needs itWhy it is worth it
Bronze, 1 yearFunded teams heading into a first SOC 2 or ISO 27001 cycle.Covers the whole observation period, so the auditor samples a sealed record instead of a reconstruction.
Silver, 3 yearsCompliance-sensitive teams that live in the standards year round.Spans a full ISO certification cycle, including the surveillance audits in between.
Gold, 10 yearsFinance, healthcare, government, and defense programs.Holds the long record for procurement and regulators, with an expert who can take the stand.

Published list prices, the same for a funded startup as for the Fortune 100. No negotiated rate, no Contact Sales button.

Your rate is locked from your start date for the whole of your tier's window. A later list price rise applies to new subscriptions, not to yours.

Bronze

$750 per month

Works on Go only

Funded teams, up to 10 developers or 5 repos, heading into their first SOC 2 or ISO 27001 cycle.

  • A per-repo signing key from witness setup, so every run self-seals with no key management
  • Sealed receipt bundles, hosted and retained by Off Grid for 1 year while paid and in good standing
  • Public verification page
  • Email support
Most teams

Silver

$3,000 per month

Works on Go only

Compliance-sensitive teams up to 50 developers who live in the standards.

  • Everything in Bronze
  • Rolling custody up to 3 years, held for as long as the subscription runs, not prepaid
  • Audit-ready reports and compliance mappings
  • Priority support

Gold

$10,000 per month

Works on Go only

Finance, healthcare, government, and defense programs.

  • Everything in Silver
  • Rolling custody up to 10 years, held for as long as the subscription runs, not prepaid
  • Custody where your program requires: our vault, your cloud, or your premises
  • Founder-level expert testimony at the published hourly rate, to explain the evidence to your auditors, regulators, or a court
  • SLA, SSO, procurement and legal review support
  • Optional customer-controlled signing keys, for teams that must root trust in their own KMS, HSM, or approval authority

FAQ

Hard questions. Direct answers.

Does Witness support every language and build system?

No. Today the commercial promise is intentionally narrow: Go. Witness is built around Go tests, benchmarks, profiles, fuzzing, and the surrounding release evidence. If you do not ship Go, it is not for you yet. There is no non Go path today, and no announced date for one.

Does Witness get us SOC 2, ISO 27001, FedRAMP, HIPAA, or CMMC?

No. Certifications come from a control environment, management discipline, and the relevant auditor, assessor, or certification body. Witness does something narrower and more valuable than a badge claim: it creates and retains sealed technical evidence showing what ran, what passed, what failed, what artifacts existed, which hashes identify them, and when the record was sealed. That evidence can support certification, recertification, procurement, incident review, and litigation, but it is not itself a certification.

Is Witness replacing CI, Vanta, Drata, Secureframe, auditors, or counsel?

No. CI still executes work. GRC platforms still manage controls, owners, tickets, policies, and audit workflows. Auditors still decide audit procedure. Counsel still decides legal posture. Witness creates the sealed technical record those people can rely on: machine-readable results, human-readable reports, ledgers, manifests, timestamps, and retained proof. It complements those systems by giving them evidence with custody instead of screenshots and after-the-fact summaries.

How does Witness fit into CI?

CI still owns execution. Witness wraps the relevant release, test, benchmark, profile, and fuzz work so the result becomes a sealed record tied to the code state and policy profile. The operational goal is simple: engineers keep their workflow, but the organization gets a record that survives procurement, audit, and dispute review.

Does Witness slow our build down?

Not the loop your engineers live in. The quiz and test profiles are the developer path and add sealing overhead measured in seconds on top of the test time you already pay. The heavy profiles are release grade and meant to be scheduled rather than sitting in front of a merge: final for a release candidate, soak and mcat for endurance work you run out of band. One clarification worth making, because the numbers invite it: the timing floors published in the profile guide are safety ceilings that stop a runaway run, not expected durations. A 24 hour aggregate floor describes the outer bound before a run is abandoned, not how long a run takes. Witness runs go test as the engine, so the underlying test time is whatever it already is; what Witness adds is the recording, and the recording is cheap.

What is inside a passing Witness record?

A passing record is not just a green badge. It includes a human-readable report, machine-readable certificate, hash-linked ledger, manifests, timestamp receipt, run attestation, profile and policy facts, checksums, and verifier material. The purpose is reviewability: humans can understand the run, machines can compare the run, and verifiers can check whether the record still matches itself.

What does the ledger actually do?

The ledger is the ordered source of truth for the run. Events are sequenced, hash-linked, and replayed during verification. Reports and certificates are projections from that record. That matters because a polished PDF is easy to produce after the fact; a consistent ledger, manifest, timestamp, and verifier path is much harder to fake without leaving a mismatch.

Why preserve failed runs?

Because failures are often the most important evidence. A failure can show the gate operated, the defect was caught, repro material existed, and the release did not pretend everything was fine. Witness treats failures as first-class records: reason codes, machine failure JSON, human review material, repro commands, retained output, crashers where relevant, and the same sealing discipline as a passing run.

What is the difference between a certificate and a guarantee?

A certificate states what ran, what verified, and what evidence was preserved. A guarantee promises an outcome. Witness does the first, not the second. The distinction matters in review because a certificate can be checked against the bundle, and a guarantee cannot.

What can Off Grid prove, and what can it not prove?

We can help prove that a sealed Witness record existed, belonged to your account, matched its hashes and manifests, and verified according to the verifier material in the bundle. We cannot prove your tests were complete, your controls were perfectly designed, your software had no defects, or your company was legally non-negligent. Witness proves the record. It does not turn engineering judgment, audit judgment, or legal judgment into a magic certificate.

Is Off Grid an audit firm for software?

No, and the distinction matters. An audit firm examines your work and issues an opinion. Off Grid holds evidence and never grades it. The closer comparisons are an escrow agent, a notary, or chain of custody in forensics: we can attest what arrived, when it arrived, and that it has not changed since, while offering no view on whether your engineering was good. That is a narrower promise than certification, and it is the one we can keep under cross examination. Custody solves the same structural problem an outside audit firm solves, without pretending to be an opinion.

What exactly is Off Grid holding, and can you access it?

A customer-owned copy of the sealed Witness evidence bundle. Witness creates the record on your machine. Off Grid holds the locked copy as custodian so you can retrieve it later. We do not own the evidence, edit it, train on it, sell it, or treat it as our operational data. The point is independent custody: when your customer asks for proof, the answer is not limited to your own CI records or your memory of the run. On access: the evidence is yours, we do not own it, edit it, sell it, mine it, or use it to train systems, and the contract says so. There are three circumstances in which anyone here would open your bundle: you ask us to during a support request, a court orders it, or the law compels it. Where we are permitted to tell you, we will. The commercial promise is custody, not inspection.

Does Off Grid hold a key that could forge or rewrite our evidence?

No. The trust model is built around custody, not editorial control. Witness produces the sealed record where your work runs. Verification depends on the bundle, hashes, manifests, timestamps, and the authority model you configure. Off Grid keeps the locked copy for you; we do not need a signing key that lets us invent a better history. If the retained record is changed, verification fails.

Can Off Grid read our source code, secrets, or customer data?

No. Witness runs where your code lives. We do not want your source code, secrets, customer databases, or production data, and the custody product is not designed around receiving them. The retained evidence is about the run and its proof material: reports, ledgers, manifests, hashes, timestamps, and verification facts.

Does verification require trusting Off Grid's website?

No. The retained copy is useful because it is independently held, but the evidence model cannot depend on our website being available or trustworthy. A sealed bundle is meant to verify from its own contents: ledger, manifests, hashes, timestamps, and verifier material. The website helps you find and retrieve what we hold for you; it is not the source of truth.

Why should our customer trust Off Grid as the 3rd party?

They should not have to trust our marketing. The bundle is designed to verify: hash-linked ledger events, manifests, timestamps, reports, machine attestations, sidecars, and replay material. Off Grid adds independent custody. Your customer can ask whether the record existed before the dispute, whether it verifies, and whether the copy was held somewhere you could not quietly rewrite. The claim your customer checks is the bundle, not our role in holding it.

Why does 3rd party retention matter if we already keep CI logs?

Because CI logs are still your records, inside your systems, subject to your retention, access, rebuilds, migrations, and admin privileges. That is the same structural problem financial reporting solved by requiring an outside firm, and it is why a reviewer can discount an internal record without disputing its accuracy. A retained third party copy changes the posture: the proof exists outside the system being reviewed, held by someone who does not benefit from the answer, and it verifies on its own contents rather than on anyone's word.

Will a bundle we sealed in 2026 still verify in 2036?

No, and we do not market that promise. Witness releases are immutable instruments. A result produced by Witness 2026 is a statement under the Witness 2026 rules, tools, threat model, evidence format, verifier, and consulted data. Each released Witness instrument is retained with its binaries, evidence format specification, verifier, data snapshots, checksums, commit identity, build metadata, tool metadata, release notes, assumptions, and limits. It is independently timestamped, so a historic result stays verifiable under the exact rules, tools, and threat data that produced it. The clean promise is not 'latest Witness reinterprets everything forever.' The clean promise is: a bundle produced by Witness X is verified with Witness X. Use the Witness instrument that produced the bundle unless a later release explicitly says it supports that older format. Do not use Witness 2036 to reinterpret a 2026 result by accident, because the 2026 result is a statement under the 2026 instrument. That is easier to explain in court or an audit than a claim that a current release reinterprets every past format: the old release is preserved as an artifact with its assumptions and verifier, while current Witness stays free to represent today's rules, tools, and threat model.

What happens when a newer Witness finds issues an older Witness did not?

That is responsible change, not a contradiction. Your 2026 bundle proves what Witness observed in 2026. New Witness may observe new issues on the same code because the tool, rules, threat model, or threat data improved. The threat landscape evolves daily, and no tool can predict future flaws, future exploit paths, or future reviewer expectations, including this one. When you remediate and seal a new passing result, the delta is itself evidence of responsible change: historical state, new detection, remediation, renewed attestation.

Does Witness prove we were not negligent?

No. Negligence is a legal conclusion. Witness helps establish contemporaneous technical facts: what ran, what failed, what passed, what was preserved, what policy was in force, and when the record sealed. Counsel can use those facts. An auditor can sample those facts. A buyer can review those facts. Witness does not replace the judgment of any of them.

How does this help if we get sued?

Negligence turns on standard of care, and standard of care is argued from contemporaneous records. One common line of attack is not that the tests were weak but that the evidence was assembled after the complaint landed. A hash linked ledger, a timestamp from an authority that is not us, and a copy held by an independent custodian answer that attack directly: the record existed in this exact form before the dispute, and it still verifies. Sealing every release also makes these ordinary course records rather than litigation artifacts. Witness cannot win a lawsuit or make negligence go away, and no evidence system can. It can spare your counsel the alternative, which is engineers rebuilding last year from CI logs, Slack threads, and memory while the meter runs.

Does sealed evidence ever work against us?

Yes, and we would rather say so here than have you discover it later. Failed runs seal with the same discipline as passing ones, so a record showing a gate failed before a release is discoverable too. We consider that a feature. A record that only ever contains passing runs is easier to challenge, because the absence of failures is itself a question. The teams this serves are the teams that act on failures: for them the full record shows a gate caught a defect and the process worked, which is a far stronger story than a year of unbroken green nobody can verify.

Can someone subpoena Off Grid directly for our evidence?

They can try, and you should assume that anyone determined enough will. Here is what we commit to when it happens. We notify you before producing anything, unless a court order legally forbids us from telling you. You get a reasonable window to move to quash before we respond. Where a protective order is available, we will seek one. We are the custodian of your record, not a party with an interest in disclosing it, and we will not treat a request as routine simply because complying is easier than resisting. Two things are worth being clear about. We cannot promise to defeat valid legal process, because no custodian can, and a commitment to fight every request regardless of merit would be a promise we could not keep. And what we hold is the sealed evidence bundle, which contains reports, ledgers, manifests, hashes, timestamps, and verification material. It contains no source code, no secrets, and no customer data, so the material reachable through us is narrower than what sits in your own systems.

Does having a custodian create a discovery target we did not have before?

It creates a second holder of a record you already had, which is a fair thing to weigh, so here is the honest arithmetic. The evidence itself was always discoverable from you, because it describes your own release process and lives in your own systems first. Custody does not create new discoverable content; it creates another place the same content exists, held by someone with no stake in the outcome. In practice that usually helps rather than hurts, because the version we hold is the one nobody can be accused of having curated, and its existence before the dispute is exactly the fact that is hardest to establish after one starts. The tradeoff worth naming plainly: once you routinely seal evidence, allowing custody to lapse during a live dispute is itself an act a court can look at. That is an argument for keeping custody current when it matters, and it is a reason to think about this before you are in a dispute rather than during one. If your counsel wants to review the custody terms before you subscribe, we would rather they did.

Where is our evidence stored, and under whose law?

Off Grid Software operates from Ontario, Canada, and Ontario law governs the customer agreement. Retained evidence is currently stored in Google Cloud's northamerica-northeast1 region, which is Montreal, Quebec. Treat that as the position today rather than a guarantee. We will add regions for redundancy and resilience as the service grows, and you should assume the storage footprint can change without us asking first. If a specific residency is a hard requirement for your program rather than a preference, do not rely on our default: Gold includes custody in your own cloud or on your own premises, which puts the location under your control and your audit scope instead of ours. Two further implications worth stating rather than leaving you to work out. For European and United Kingdom customers, this is a transfer to Canada, and Canada holds a European Commission adequacy decision covering commercial organizations, which is a matter of public record you can verify independently rather than take from us. For customers who care about the CLOUD Act, the honest position is that the data sits in Canada under Canadian law while the storage provider is a United States headquartered company, and that distinction matters to some legal teams and not others. We would rather you weigh it now than discover it during a review. If your program requires evidence to sit somewhere specific, Gold includes custody in your own cloud or on your own premises.

Why are timestamps and retention windows part of the product instead of an implementation detail?

Timing is often the whole dispute. A record that appears after the customer asks, after the auditor samples, or after the lawsuit starts is a weaker record. Witness is designed to show the evidence existed when the work happened, then Off Grid custody keeps extending the locked-copy expiry for as long as the account is paid and in good standing. Read the retention windows on the plan cards as rolling, not prepaid. Your tier sets how far back custody reaches at any moment, and it holds while the subscription runs. Buying Gold and cancelling in month three does not buy ten years of storage; it buys custody for those three months plus the wind-down window to export what we hold.

Why is pricing tied to retention instead of test volume?

Because the expensive part is not running a test binary. The expensive part is credible proof when a buyer, auditor, regulator, or court asks for it. Bronze protects the first audit year. Silver protects the certification cycle. Gold protects the long record. We price against the cost of not having independent evidence, not against CPU minutes.

Storage is cheap. Why not hold our evidence for X years, and why does a lapsed payment end custody at all?

It is a reasonable question, and you are right that the storage itself is inexpensive. The cost sits somewhere else. What custody buys is our commitment to stand behind a record: to hold it under a locked retention window, to keep it in a state where it verifies, to account for how it was stored if a court asks, and on Gold to explain it under questioning. Each of those is an obligation rather than a file, and obligations accrue for as long as we hold the record. A custodian holding evidence indefinitely for accounts that have lapsed takes on commitments it has no way to honour properly, and we would rather offer a window we can genuinely stand behind than a longer one we cannot. That is also why the tiers are priced the way they are. Gold costs more than Bronze because ten years of responsibility is a larger commitment than one year, not because ten years of disk costs more. And it is why a lapsed account gets a wind-down period rather than immediate deletion: the record belongs to you, so the right thing is to give you time to take it with you.

Can the price go up on us?

Not during your guaranteed term. The rate you start at is locked from your start date for the full length of your tier's window: one year on Bronze, three years on Silver, ten years on Gold. A company starting Gold today holds that monthly figure until the same date in 2036. If we raise list prices next year, the new figure applies to new subscriptions and to anyone returning after a lapse, never to a term already running. The reasoning is straightforward. Custody is only useful if you can rely on it for the whole window, and a vendor able to reprice a dependency at will has not offered custody so much as storage with leverage attached. Two boundaries worth stating plainly. The guarantee follows continuous payment, so an account that lapses and later resubscribes starts again at the list price current at that time. And the guarantee covers your term rather than forever: when a ten year Gold term ends, renewal is priced at whatever is current then, with the same guarantee running from that date.

What happens to older evidence if we downgrade a tier?

Your window shrinks to the new tier's, and anything outside it leaves custody. Moving from Gold to Silver takes your reach from ten years to three, so bundles older than three years fall out of the retained set. We do not delete them the moment the change takes effect; you get an export window to retrieve anything the new tier no longer covers, the same courtesy an account closure gets. Two things follow from that. Downgrading is not a way to shed cost while keeping the long tail, and if the old records are the ones that matter for a specific audit or dispute, export them before you change tiers rather than after. The bundles you export keep verifying offline regardless, because verification never depended on us holding them.

What happens if we stop paying?

Custody is a paid service, not a free warehouse after the lease ends. If payment fails, you get thirty days to cure the account. If it is still unpaid after that, we move the account into a thirty-day export-only wind-down period so you can download technically available retained evidence. After that, unpaid, cancelled, lapsed, or abandoned evidence may be treated as expired operational material and deleted or allowed to expire, unless a paid-up archive, legal hold, court order, law, technical retention lock, or signed order says otherwise. The practical rule is simple: keep paying and we keep extending eligible custody dates; stop paying and we give you a fair runway to recover or export before the record is assumed abandoned.

Do you offer refunds, credits, or a trial?

All sales are final. There are no refunds, credits, or prorated cancellations, and we would rather state that plainly here than have you discover it after a charge. Cancelling stops the next month rather than returning the current one, and the custody window you have already paid for is honoured in full, including the export period. The reason we can be this firm is that we try to leave nothing for you to find out later: the tiers, the retention windows, the rate lock, the wind-down process, the jurisdiction, and what happens to your evidence if you stop paying are all written on this page before you spend anything. If a term here does not work for your organisation, the right time to tell us is before the first invoice rather than after.

How does this help sales and procurement?

Security questionnaires increasingly ask for artifacts rather than attestations. Witness gives you a concrete answer: here is the sealed record, here is the retained third-party copy, here are the hashes and timestamps, here is what passed and failed, and here is the verification path. That shortens the distance between 'send us proof' and 'here is the proof.'

Who else is using this? Can we talk to a reference?

Not yet, and we are not going to dress that up. Witness has been used on real Go codebases outside our own, but the custody service is new and we are not currently holding retained evidence for any customer. There are no reference calls to arrange and no logos to show you. Saying otherwise would be the exact behaviour this page argues against, since a page insisting that self attestation is weak has no business offering nothing but self attestation. What we can offer instead is the thing a reference call is a proxy for. Every claim on this page is checkable without talking to anyone: run Witness against your own repository, seal a bundle, verify it offline, and try to alter it and watch verification fail. Our own BLINK release record is the one bundle we can show end to end, and we know it is our own homework. If being an early custody customer is not a risk your organisation takes, that is a reasonable position, and the honest advice is to wait until we can point you at someone other than ourselves.

Off Grid looks small. Why is that safe?

It is a fair question and the honest answer is that Off Grid is deliberately small, which is exactly why the trust model does not rest on our size. Most vendors ask you to trust their headcount, their certifications, and their balance sheet. We ask you to trust a hash chain, a third party timestamp, and offline verification, none of which improve if we hire fifty people. The signing key is yours, the evidence verifies without us, and the bundle is exportable at any time. The one thing our size genuinely affects is service: support is direct rather than tiered, and the founder is the person who shows up for an expert testimony engagement. Judge that as you would any specialist firm. What our size cannot affect is whether your proof survives, and that is the part the architecture settles.

What happens to our evidence if Off Grid shuts down?

Your bundles keep verifying, and that is not a reassurance, it is the architecture. A sealed bundle verifies from its own contents: ledger, manifests, hashes, timestamp receipts, and verifier material. The timestamp comes from an authority that is not us. The signing key was minted on your machine and we never held it. Nothing in the verification path calls an Off Grid server, so a bundle you hold verifies on a laptop with no network in a world where this company no longer exists. What you would lose is the independently held copy and the retrieval service, which is why the wind-down commitment matters: if we cease operating, the same export window applies as for any account closure, and you should keep your own copy of every bundle regardless. We designed the product so that depending on us is optional, and we would encourage you to put the same question to any custody vendor you evaluate.

What is Off Grid's own security posture?

The most useful answer is what the vault does not contain. We never receive source code, secrets, credentials, customer databases, production data, or PHI, because Witness runs where your code lives and seals only the evidence: reports, ledgers, manifests, hashes, timestamps, and verification material. That narrows the blast radius of any incident on our side to material that is, by design, meant to be handed to auditors and adversaries anyway. Retained copies are encrypted at rest, custody is locked for the retention window so stored bundles are not casually replaceable, and any tampering with a retained copy causes verification to fail rather than passing silently. Off Grid does not hold SOC 2 or ISO 27001 certification today, and we would rather state that plainly than let it come up later in your vendor review. Those certifications are meaningful, and we understand the teams buying this product often hold them. What we offer alongside that gap is a custody model you can verify directly rather than take on trust. If your vendor review requires a certified subprocessor, please raise it early and we will tell you honestly whether we can meet the requirement.

Why do purchases go through Stripe?

Because payment collection is not the place to improvise. Checkout, cards, receipts, tax handling, and payment security belong on Stripe's platform. Our server still owns product identity, plan rules, and prices, so the browser cannot invent a cheaper plan. Stripe collects payment; Off Grid grants the entitlement that matches the server-side product.

witness

The record has to exist before anyone asks.

That is the one thing no vendor can backfill for you. One service, one workflow, your first sealed bundles, and a walkthrough scoped for your security, compliance, and legal reviewers in one session.

Book your evidence pilot (opens in new tab)