Notary Project
Open SourceAbout Notary Project
The Notary Project provides a set of open-source specifications and tools designed to secure software supply chains by enabling cryptographic signing and verification of software artifacts. It supports signing arbitrary blobs, container images, and other software components, ensuring their integrity and authenticity throughout the development and deployment lifecycle. The project is built on standard Public Key Infrastructure (PKI) and supports both online and air-gapped signing scenarios, making it suitable for diverse enterprise environments.
Targeted at DevOps engineers, security operators, and developers, the Notary Project offers fine-grained security policies to enforce trusted identities and registries, enhancing system integrity. Its pluggable architecture and SDK facilitate integration and customization, while multi-registry support ensures portability and immutability of signed artifacts. Adopted by leading organizations such as AWS and Microsoft, the project is community-driven and governed openly under the Cloud Native Computing Foundation (CNCF) incubating status, providing enterprises with a reliable and extensible solution for securing their software delivery pipelines.
How to evaluate Cloud Security & CSPM
This is how the CIOPages Research Team evaluates this category. It is not an assessment of Notary Project. It comes from our Cloud Security Posture Management (CSPM) buyer guide.
Other Directory Vendors
CIOPages put this listing together from public sources. Itβs information, not an endorsement. How we build listings. Work here? Claim this listing or .
Quick Facts
notaryproject.devWe publish a detail only when we can point at the page it came from. Claim this listing to fill in the rest.