Built for compliance and security
Record environment changes
Automatically run a regular job to query each environment, recording real-time data on how they change.
Your environment data is stored in a secure append-only database using a unique content based ID for each running artifact (eg. docker image digest).
Record pipeline events
Report every CI pipeline event of interest (builds, security scans, test results, approvals, deployments, etc.) to record real-time data on what happens to your software.
Your pipeline data is stored in a secure append-only database using the git commit or artifact SHA as the unique ID for each event.
Query anything!
Kosli can tell you whatâs running in any environment now, in the past, and how it has changed
Kosli can tell you the complete history of builds, tests, approvals, and deployments across all your pipelines
All this data is avalible in your browser and from your command line.
Kosli concepts - Recording your SDLC for audit, compliance and security
Attestation: a record of a fact you care about
- This build in CI pipeline | in Kosli
- This test execution in CI pipeline | in Kosli
- This security scan in CI pipeline | in Kosli
- This deployment approved in CI pipeline
- This pull request in CI pipeline | in Kosli
Trail: a chain of related attestations
- This CI run example
- This journey to production
- This terraform workflow example
- This server access
- This cron job in CI pipeline | in Kosli
- This employee’s offboarding
Flow: a collection of trails for a given process
- CI/CD runs for Payments api service
- Terraform workflows for production account example
- JIRA ticket development work
- Feature flag changes
Snapshot: a record of the artifacts in a runtime system at a point in time
- The running artifacts in a AWS ECS namespace example
- The running pods in a k8s cluster
- The terraform state files in an S3 bucket
- The functions in AWS Lambda
- The files in a directory
Environment: a history of snapshots for a runtime system over time
- How this k8s cluster changes example
- How this S3 bucket changes
- How this directory changes
- How this lambda changes
Action: trigger external systems based on changes
- Send a slack message when a deployment is detected
- Start a CI process when an environment changes
- Open an incident ticket when an unexpected change occurs
Get continuous compliance with DevOps Change Management
Artifact Provenance
Kosli uses cryptographic fingerprinting to record a tamper-proof identity for every artifact in your controlled build process
View Binary Provenance docs >Risk Controls as Code
Kosli logs the evidence from each step in your software development life cycle, building an audit trail of risk controls for each artifact
Release Approvals
With Kosli you can generate release approvals via version control, CI, or even Slack events. Compliant deploys without the ceremony
View Release Approvals docs >Deployment Controls
Automatically ensure only compliant software is deployed by verifying binary provenance, risk controls, and approvals as part of your deployment process
Deployment Logs
Record every change to every environment in a fully auditable environment log
View Deployment Logs docs >Environment Reports
Real-time reporting from operations provides full observability over whatâs really running in production. A complete history of change thatâs instantly available
Bringing Dev and Ops closer together
DevOps Freedom
Kosli frees regulated teams to deliver at the speed of DevOps, with any tools, in any industry, for any standard.
Compliance and Speed
Kosli maintains Continuous Compliance at high rates of change by automating change management in your DevOps.
4D Observability
Kosli can tell you whatâs in production, how it got there, and if itâs compliant â for any point in time.
Fed up with paperwork and meetings? Press the easy button for Audit and Compliance
Do more with kosli
Audit Trails
Automatically provide the proof that a critical business process actually took place.
Continuous Monitoring
Identify threats, trace changes. and secure your production environments.
Slack Notifications
Stay on top of environment changes and compliance events in real time.
Related resources
Kosliâs free asset helps define your SSLDC, providing a defined, repeatable way of working that manages IT risks
Fork the repoDownload Kosliâs Free white paper: Supply Chain Levels for Software Artifacts (SLSA)
View white paperSee how Kosli enabled Staccâs journey to ISO compliance at NDC Conference and that turbo eureka moment!
Watch the videoHow to prove your SDLC is being followed for compliance with medical standards like IEC 62304
Read the blogWhat does it mean to deliver software with Continuous Compliance?
Read the blogMeet the companies that made friends with change with Kosli and ship with confidence and speed
View customer stories