FAQ
Hard questions. Direct answers.
Does Witness support every language and build system?
No. Today the commercial promise is intentionally narrow: Go. Witness is built around Go tests, benchmarks, profiles, fuzzing, and the surrounding release evidence. If you do not ship Go, it is not for you yet. There is no non Go path today, and no announced date for one.
Does Witness get us SOC 2, ISO 27001, FedRAMP, HIPAA, or CMMC?
No. Certifications come from a control environment, management discipline, and the relevant auditor, assessor, or certification body. Witness does something narrower and more valuable than a badge claim: it creates and retains sealed technical evidence showing what ran, what passed, what failed, what artifacts existed, which hashes identify them, and when the record was sealed. That evidence can support certification, recertification, procurement, incident review, and litigation, but it is not itself a certification.
Is Witness replacing CI, Vanta, Drata, Secureframe, auditors, or counsel?
No. CI still executes work. GRC platforms still manage controls, owners, tickets, policies, and audit workflows. Auditors still decide audit procedure. Counsel still decides legal posture. Witness creates the sealed technical record those people can rely on: machine-readable results, human-readable reports, ledgers, manifests, timestamps, and retained proof. It complements those systems by giving them evidence with custody instead of screenshots and after-the-fact summaries.
How does Witness fit into CI?
CI still owns execution. Witness wraps the relevant release, test, benchmark, profile, and fuzz work so the result becomes a sealed record tied to the code state and policy profile. The operational goal is simple: engineers keep their workflow, but the organization gets a record that survives procurement, audit, and dispute review.
Does Witness slow our build down?
Not the loop your engineers live in. The quiz and test profiles are the developer path and add sealing overhead measured in seconds on top of the test time you already pay. The heavy profiles are release grade and meant to be scheduled rather than sitting in front of a merge: final for a release candidate, soak and mcat for endurance work you run out of band. One clarification worth making, because the numbers invite it: the timing floors published in the profile guide are safety ceilings that stop a runaway run, not expected durations. A 24 hour aggregate floor describes the outer bound before a run is abandoned, not how long a run takes. Witness runs go test as the engine, so the underlying test time is whatever it already is; what Witness adds is the recording, and the recording is cheap.
What is inside a passing Witness record?
A passing record is not just a green badge. It includes a human-readable report, machine-readable certificate, hash-linked ledger, manifests, timestamp receipt, run attestation, profile and policy facts, checksums, and verifier material. The purpose is reviewability: humans can understand the run, machines can compare the run, and verifiers can check whether the record still matches itself.
What does the ledger actually do?
The ledger is the ordered source of truth for the run. Events are sequenced, hash-linked, and replayed during verification. Reports and certificates are projections from that record. That matters because a polished PDF is easy to produce after the fact; a consistent ledger, manifest, timestamp, and verifier path is much harder to fake without leaving a mismatch.
Why preserve failed runs?
Because failures are often the most important evidence. A failure can show the gate operated, the defect was caught, repro material existed, and the release did not pretend everything was fine. Witness treats failures as first-class records: reason codes, machine failure JSON, human review material, repro commands, retained output, crashers where relevant, and the same sealing discipline as a passing run.
What is the difference between a certificate and a guarantee?
A certificate states what ran, what verified, and what evidence was preserved. A guarantee promises an outcome. Witness does the first, not the second. The distinction matters in review because a certificate can be checked against the bundle, and a guarantee cannot.
What can Off Grid prove, and what can it not prove?
We can help prove that a sealed Witness record existed, belonged to your account, matched its hashes and manifests, and verified according to the verifier material in the bundle. We cannot prove your tests were complete, your controls were perfectly designed, your software had no defects, or your company was legally non-negligent. Witness proves the record. It does not turn engineering judgment, audit judgment, or legal judgment into a magic certificate.
Is Off Grid an audit firm for software?
No, and the distinction matters. An audit firm examines your work and issues an opinion. Off Grid holds evidence and never grades it. The closer comparisons are an escrow agent, a notary, or chain of custody in forensics: we can attest what arrived, when it arrived, and that it has not changed since, while offering no view on whether your engineering was good. That is a narrower promise than certification, and it is the one we can keep under cross examination. Custody solves the same structural problem an outside audit firm solves, without pretending to be an opinion.
What exactly is Off Grid holding, and can you access it?
A customer-owned copy of the sealed Witness evidence bundle. Witness creates the record on your machine. Off Grid holds the locked copy as custodian so you can retrieve it later. We do not own the evidence, edit it, train on it, sell it, or treat it as our operational data. The point is independent custody: when your customer asks for proof, the answer is not limited to your own CI records or your memory of the run. On access: the evidence is yours, we do not own it, edit it, sell it, mine it, or use it to train systems, and the contract says so. There are three circumstances in which anyone here would open your bundle: you ask us to during a support request, a court orders it, or the law compels it. Where we are permitted to tell you, we will. The commercial promise is custody, not inspection.
Does Off Grid hold a key that could forge or rewrite our evidence?
No. The trust model is built around custody, not editorial control. Witness produces the sealed record where your work runs. Verification depends on the bundle, hashes, manifests, timestamps, and the authority model you configure. Off Grid keeps the locked copy for you; we do not need a signing key that lets us invent a better history. If the retained record is changed, verification fails.
Can Off Grid read our source code, secrets, or customer data?
No. Witness runs where your code lives. We do not want your source code, secrets, customer databases, or production data, and the custody product is not designed around receiving them. The retained evidence is about the run and its proof material: reports, ledgers, manifests, hashes, timestamps, and verification facts.
Does verification require trusting Off Grid's website?
No. The retained copy is useful because it is independently held, but the evidence model cannot depend on our website being available or trustworthy. A sealed bundle is meant to verify from its own contents: ledger, manifests, hashes, timestamps, and verifier material. The website helps you find and retrieve what we hold for you; it is not the source of truth.
Why should our customer trust Off Grid as the 3rd party?
They should not have to trust our marketing. The bundle is designed to verify: hash-linked ledger events, manifests, timestamps, reports, machine attestations, sidecars, and replay material. Off Grid adds independent custody. Your customer can ask whether the record existed before the dispute, whether it verifies, and whether the copy was held somewhere you could not quietly rewrite. The claim your customer checks is the bundle, not our role in holding it.
Why does 3rd party retention matter if we already keep CI logs?
Because CI logs are still your records, inside your systems, subject to your retention, access, rebuilds, migrations, and admin privileges. That is the same structural problem financial reporting solved by requiring an outside firm, and it is why a reviewer can discount an internal record without disputing its accuracy. A retained third party copy changes the posture: the proof exists outside the system being reviewed, held by someone who does not benefit from the answer, and it verifies on its own contents rather than on anyone's word.
Will a bundle we sealed in 2026 still verify in 2036?
No, and we do not market that promise. Witness releases are immutable instruments. A result produced by Witness 2026 is a statement under the Witness 2026 rules, tools, threat model, evidence format, verifier, and consulted data. Each released Witness instrument is retained with its binaries, evidence format specification, verifier, data snapshots, checksums, commit identity, build metadata, tool metadata, release notes, assumptions, and limits. It is independently timestamped, so a historic result stays verifiable under the exact rules, tools, and threat data that produced it. The clean promise is not 'latest Witness reinterprets everything forever.' The clean promise is: a bundle produced by Witness X is verified with Witness X. Use the Witness instrument that produced the bundle unless a later release explicitly says it supports that older format. Do not use Witness 2036 to reinterpret a 2026 result by accident, because the 2026 result is a statement under the 2026 instrument. That is easier to explain in court or an audit than a claim that a current release reinterprets every past format: the old release is preserved as an artifact with its assumptions and verifier, while current Witness stays free to represent today's rules, tools, and threat model.
What happens when a newer Witness finds issues an older Witness did not?
That is responsible change, not a contradiction. Your 2026 bundle proves what Witness observed in 2026. New Witness may observe new issues on the same code because the tool, rules, threat model, or threat data improved. The threat landscape evolves daily, and no tool can predict future flaws, future exploit paths, or future reviewer expectations, including this one. When you remediate and seal a new passing result, the delta is itself evidence of responsible change: historical state, new detection, remediation, renewed attestation.
Does Witness prove we were not negligent?
No. Negligence is a legal conclusion. Witness helps establish contemporaneous technical facts: what ran, what failed, what passed, what was preserved, what policy was in force, and when the record sealed. Counsel can use those facts. An auditor can sample those facts. A buyer can review those facts. Witness does not replace the judgment of any of them.
How does this help if we get sued?
Negligence turns on standard of care, and standard of care is argued from contemporaneous records. One common line of attack is not that the tests were weak but that the evidence was assembled after the complaint landed. A hash linked ledger, a timestamp from an authority that is not us, and a copy held by an independent custodian answer that attack directly: the record existed in this exact form before the dispute, and it still verifies. Sealing every release also makes these ordinary course records rather than litigation artifacts. Witness cannot win a lawsuit or make negligence go away, and no evidence system can. It can spare your counsel the alternative, which is engineers rebuilding last year from CI logs, Slack threads, and memory while the meter runs.
Does sealed evidence ever work against us?
Yes, and we would rather say so here than have you discover it later. Failed runs seal with the same discipline as passing ones, so a record showing a gate failed before a release is discoverable too. We consider that a feature. A record that only ever contains passing runs is easier to challenge, because the absence of failures is itself a question. The teams this serves are the teams that act on failures: for them the full record shows a gate caught a defect and the process worked, which is a far stronger story than a year of unbroken green nobody can verify.
Can someone subpoena Off Grid directly for our evidence?
They can try, and you should assume that anyone determined enough will. Here is what we commit to when it happens. We notify you before producing anything, unless a court order legally forbids us from telling you. You get a reasonable window to move to quash before we respond. Where a protective order is available, we will seek one. We are the custodian of your record, not a party with an interest in disclosing it, and we will not treat a request as routine simply because complying is easier than resisting. Two things are worth being clear about. We cannot promise to defeat valid legal process, because no custodian can, and a commitment to fight every request regardless of merit would be a promise we could not keep. And what we hold is the sealed evidence bundle, which contains reports, ledgers, manifests, hashes, timestamps, and verification material. It contains no source code, no secrets, and no customer data, so the material reachable through us is narrower than what sits in your own systems.
Does having a custodian create a discovery target we did not have before?
It creates a second holder of a record you already had, which is a fair thing to weigh, so here is the honest arithmetic. The evidence itself was always discoverable from you, because it describes your own release process and lives in your own systems first. Custody does not create new discoverable content; it creates another place the same content exists, held by someone with no stake in the outcome. In practice that usually helps rather than hurts, because the version we hold is the one nobody can be accused of having curated, and its existence before the dispute is exactly the fact that is hardest to establish after one starts. The tradeoff worth naming plainly: once you routinely seal evidence, allowing custody to lapse during a live dispute is itself an act a court can look at. That is an argument for keeping custody current when it matters, and it is a reason to think about this before you are in a dispute rather than during one. If your counsel wants to review the custody terms before you subscribe, we would rather they did.
Where is our evidence stored, and under whose law?
Off Grid Software operates from Ontario, Canada, and Ontario law governs the customer agreement. Retained evidence is currently stored in Google Cloud's northamerica-northeast1 region, which is Montreal, Quebec. Treat that as the position today rather than a guarantee. We will add regions for redundancy and resilience as the service grows, and you should assume the storage footprint can change without us asking first. If a specific residency is a hard requirement for your program rather than a preference, do not rely on our default: Gold includes custody in your own cloud or on your own premises, which puts the location under your control and your audit scope instead of ours. Two further implications worth stating rather than leaving you to work out. For European and United Kingdom customers, this is a transfer to Canada, and Canada holds a European Commission adequacy decision covering commercial organizations, which is a matter of public record you can verify independently rather than take from us. For customers who care about the CLOUD Act, the honest position is that the data sits in Canada under Canadian law while the storage provider is a United States headquartered company, and that distinction matters to some legal teams and not others. We would rather you weigh it now than discover it during a review. If your program requires evidence to sit somewhere specific, Gold includes custody in your own cloud or on your own premises.
Why are timestamps and retention windows part of the product instead of an implementation detail?
Timing is often the whole dispute. A record that appears after the customer asks, after the auditor samples, or after the lawsuit starts is a weaker record. Witness is designed to show the evidence existed when the work happened, then Off Grid custody keeps extending the locked-copy expiry for as long as the account is paid and in good standing. Read the retention windows on the plan cards as rolling, not prepaid. Your tier sets how far back custody reaches at any moment, and it holds while the subscription runs. Buying Gold and cancelling in month three does not buy ten years of storage; it buys custody for those three months plus the wind-down window to export what we hold.
Why is pricing tied to retention instead of test volume?
Because the expensive part is not running a test binary. The expensive part is credible proof when a buyer, auditor, regulator, or court asks for it. Bronze protects the first audit year. Silver protects the certification cycle. Gold protects the long record. We price against the cost of not having independent evidence, not against CPU minutes.
Storage is cheap. Why not hold our evidence for X years, and why does a lapsed payment end custody at all?
It is a reasonable question, and you are right that the storage itself is inexpensive. The cost sits somewhere else. What custody buys is our commitment to stand behind a record: to hold it under a locked retention window, to keep it in a state where it verifies, to account for how it was stored if a court asks, and on Gold to explain it under questioning. Each of those is an obligation rather than a file, and obligations accrue for as long as we hold the record. A custodian holding evidence indefinitely for accounts that have lapsed takes on commitments it has no way to honour properly, and we would rather offer a window we can genuinely stand behind than a longer one we cannot. That is also why the tiers are priced the way they are. Gold costs more than Bronze because ten years of responsibility is a larger commitment than one year, not because ten years of disk costs more. And it is why a lapsed account gets a wind-down period rather than immediate deletion: the record belongs to you, so the right thing is to give you time to take it with you.
Can the price go up on us?
Not during your guaranteed term. The rate you start at is locked from your start date for the full length of your tier's window: one year on Bronze, three years on Silver, ten years on Gold. A company starting Gold today holds that monthly figure until the same date in 2036. If we raise list prices next year, the new figure applies to new subscriptions and to anyone returning after a lapse, never to a term already running. The reasoning is straightforward. Custody is only useful if you can rely on it for the whole window, and a vendor able to reprice a dependency at will has not offered custody so much as storage with leverage attached. Two boundaries worth stating plainly. The guarantee follows continuous payment, so an account that lapses and later resubscribes starts again at the list price current at that time. And the guarantee covers your term rather than forever: when a ten year Gold term ends, renewal is priced at whatever is current then, with the same guarantee running from that date.
What happens to older evidence if we downgrade a tier?
Your window shrinks to the new tier's, and anything outside it leaves custody. Moving from Gold to Silver takes your reach from ten years to three, so bundles older than three years fall out of the retained set. We do not delete them the moment the change takes effect; you get an export window to retrieve anything the new tier no longer covers, the same courtesy an account closure gets. Two things follow from that. Downgrading is not a way to shed cost while keeping the long tail, and if the old records are the ones that matter for a specific audit or dispute, export them before you change tiers rather than after. The bundles you export keep verifying offline regardless, because verification never depended on us holding them.
What happens if we stop paying?
Custody is a paid service, not a free warehouse after the lease ends. If payment fails, you get thirty days to cure the account. If it is still unpaid after that, we move the account into a thirty-day export-only wind-down period so you can download technically available retained evidence. After that, unpaid, cancelled, lapsed, or abandoned evidence may be treated as expired operational material and deleted or allowed to expire, unless a paid-up archive, legal hold, court order, law, technical retention lock, or signed order says otherwise. The practical rule is simple: keep paying and we keep extending eligible custody dates; stop paying and we give you a fair runway to recover or export before the record is assumed abandoned.
Do you offer refunds, credits, or a trial?
All sales are final. There are no refunds, credits, or prorated cancellations, and we would rather state that plainly here than have you discover it after a charge. Cancelling stops the next month rather than returning the current one, and the custody window you have already paid for is honoured in full, including the export period. The reason we can be this firm is that we try to leave nothing for you to find out later: the tiers, the retention windows, the rate lock, the wind-down process, the jurisdiction, and what happens to your evidence if you stop paying are all written on this page before you spend anything. If a term here does not work for your organisation, the right time to tell us is before the first invoice rather than after.
How does this help sales and procurement?
Security questionnaires increasingly ask for artifacts rather than attestations. Witness gives you a concrete answer: here is the sealed record, here is the retained third-party copy, here are the hashes and timestamps, here is what passed and failed, and here is the verification path. That shortens the distance between 'send us proof' and 'here is the proof.'
Who else is using this? Can we talk to a reference?
Not yet, and we are not going to dress that up. Witness has been used on real Go codebases outside our own, but the custody service is new and we are not currently holding retained evidence for any customer. There are no reference calls to arrange and no logos to show you. Saying otherwise would be the exact behaviour this page argues against, since a page insisting that self attestation is weak has no business offering nothing but self attestation. What we can offer instead is the thing a reference call is a proxy for. Every claim on this page is checkable without talking to anyone: run Witness against your own repository, seal a bundle, verify it offline, and try to alter it and watch verification fail. Our own BLINK release record is the one bundle we can show end to end, and we know it is our own homework. If being an early custody customer is not a risk your organisation takes, that is a reasonable position, and the honest advice is to wait until we can point you at someone other than ourselves.
Off Grid looks small. Why is that safe?
It is a fair question and the honest answer is that Off Grid is deliberately small, which is exactly why the trust model does not rest on our size. Most vendors ask you to trust their headcount, their certifications, and their balance sheet. We ask you to trust a hash chain, a third party timestamp, and offline verification, none of which improve if we hire fifty people. The signing key is yours, the evidence verifies without us, and the bundle is exportable at any time. The one thing our size genuinely affects is service: support is direct rather than tiered, and the founder is the person who shows up for an expert testimony engagement. Judge that as you would any specialist firm. What our size cannot affect is whether your proof survives, and that is the part the architecture settles.
What happens to our evidence if Off Grid shuts down?
Your bundles keep verifying, and that is not a reassurance, it is the architecture. A sealed bundle verifies from its own contents: ledger, manifests, hashes, timestamp receipts, and verifier material. The timestamp comes from an authority that is not us. The signing key was minted on your machine and we never held it. Nothing in the verification path calls an Off Grid server, so a bundle you hold verifies on a laptop with no network in a world where this company no longer exists. What you would lose is the independently held copy and the retrieval service, which is why the wind-down commitment matters: if we cease operating, the same export window applies as for any account closure, and you should keep your own copy of every bundle regardless. We designed the product so that depending on us is optional, and we would encourage you to put the same question to any custody vendor you evaluate.
What is Off Grid's own security posture?
The most useful answer is what the vault does not contain. We never receive source code, secrets, credentials, customer databases, production data, or PHI, because Witness runs where your code lives and seals only the evidence: reports, ledgers, manifests, hashes, timestamps, and verification material. That narrows the blast radius of any incident on our side to material that is, by design, meant to be handed to auditors and adversaries anyway. Retained copies are encrypted at rest, custody is locked for the retention window so stored bundles are not casually replaceable, and any tampering with a retained copy causes verification to fail rather than passing silently. Off Grid does not hold SOC 2 or ISO 27001 certification today, and we would rather state that plainly than let it come up later in your vendor review. Those certifications are meaningful, and we understand the teams buying this product often hold them. What we offer alongside that gap is a custody model you can verify directly rather than take on trust. If your vendor review requires a certified subprocessor, please raise it early and we will tell you honestly whether we can meet the requirement.
Why do purchases go through Stripe?
Because payment collection is not the place to improvise. Checkout, cards, receipts, tax handling, and payment security belong on Stripe's platform. Our server still owns product identity, plan rules, and prices, so the browser cannot invent a cheaper plan. Stripe collects payment; Off Grid grants the entitlement that matches the server-side product.