Evidence Pack
Self-serve compliance deliverables: NDJSON activity logs, bundled artifacts, and signed evidence you can hand auditors.
Start with the packaged bundle, run it on any repo, and export the artifacts + receipts that auditors expect.
What you get
Everything ships with the pack so your team can reproduce, verify, and export audit-ready proof on demand.
- NDJSON activity log with gate, actor, timestamp, and signed hashes for every run.
- Evidence bundle (SPEC.md, VERIFY_REPORT.md, SHA256SUMS.txt) plus docs and retention notes.
- Signed artifacts featuring portable run scripts, bundles, and checksum manifests.
Gate-by-gate events with actor, timestamp, status, and hashes so you can prove every change.
- Smoke · lint · typecheck · unit · build · bundle gates
- Outcome + warnings + durations
- Signed gate hashes
SPEC.md, VERIFY_REPORT.md, SHA256SUMS.txt, and curated docs land in one sealed artifact.
- Gate definitions + verification outcomes
- Artifact ledger + hash manifest
- Docs: quickstart, troubleshooting, retention notes
Portable bundle (run.ps1 / run.sh / run.cmd) plus signatures and certs prove delivery integrity.
- Automated bundle -> artifact SCC pipe
- Signed manifests and checksum checks
- Activation scripts + status endpoints
Sample format — NDJSON Activity Log
This is a faithful excerpt of the activity log the pack exports every run.
Filterable, exportable, NDJSON lines keep the entire verification history traceable.
Sample format — Bundle Structure
- Audit-ready exports + specs
- Signed artifacts + checksums
- Docs + troubleshooting notes
How to use
Install the pack, run your gates, and export the bundle on your own timeline — no calls needed.
Grab the portable bundle, install the binaries, and point to your repo.
Run Shipyard to trigger smoke, lint, typecheck, unit, build, and artifact gates locally.
Export the NDJSON log + artifact bundle, then share the signed archive with your compliance team.
Who it's for
Shipyard Evidence Pack supports teams that need determinism, audit trails, and reproducible artifacts.
Clear proof for clients with reproducible gate logs and invoices.
Evidence export plus retention keeps SOC 2, ISO 27001, HIPAA reviewers satisfied.
Portable bundles + scripts ensure you can re-run, verify, and prove what shipped.
Shipyard generates audit-ready evidence for these frameworks. Not a certification.
- Run the pack locally; there are no extra services or onboarding.
- Support happens via GitHub Issues & Discussions; no SLA.
- Need deeper integration? We can share automation hooks when you join the waitlist.