Product Overview -- Early AdopterEarly AccessDenseDefense | DDVault + DDWitness
DDVault + DDWitness
The evidence enclave. DDVault is the custody layer beneath the DenseDefense suite's signed evidence -- every artifact traceable to origin and provably untouched -- and DDWitness is designed to attest that evidence is unaltered without ever holding the evidence itself. In active development -- this is an overview of what the pair is for, not an API reference.
Early Adopter -- in active developmentChain of custody -- origin and integrityDDWitness attests without holding the evidenceAPI reference published at general availability
What this document is
StatusDDVault and DDWitness are an Early-Adopter capability, in active development. They ship today as evidence-custody integrations beneath the suite rather than as a standalone public REST API, so an API reference would be premature. This page is a product overview: what the pair is for and where it fits.
Scope of claimsThis overview describes purpose and intent. It does not assert current capability -- nothing here should be read as a claim about what the pair does to your evidence today.
What comes nextFull API documentation will be published at general availability. Until then, contact us for early access to help shape the custody layer before it ships.
1 | What DDVault and DDWitness are
DDVault and DDWitness are the DenseDefense suite's evidence enclave -- the
custody layer that sits beneath the signed evidence the rest of the suite produces. A
compliance package is only as trustworthy as the story of where each artifact came from and whether
it has been touched since. DDVault and DDWitness exist to carry that story: origin, and integrity.
DDVault is the vault for the evidence; DDWitness is the independent attestation that the evidence
is unaltered -- and it is designed to do that without ever holding the evidence itself,
so the thing that vouches for integrity is separate from the thing that stores the data.
This is an overview of a capability in active development. It describes what the
pair is for. It is not an API reference, and nothing here is a claim that these functions
run against your evidence today.
2 | What it is for
Across the DenseDefense suite, the trust in a result rests on chain of custody: every
artifact traceable to its origin and provably untouched. DDVault and DDWitness are being
built to be exactly that layer -- the place that holds the suite's evidence and the
independent voice that says it has not changed.
Component
Its purpose
DDVault
The evidence enclave. Its purpose is to seal the
suite's compliance evidence with a chain of custody -- each artifact tied to where it came
from and held so that any change would be evident.
DDWitness
The attestation. Its purpose is to attest that the sealed
evidence is unaltered -- and to do so without ever holding the evidence itself, keeping the
witness independent of the vault.
Positioning only. Each row above states an intended role for a capability
in active development, not a shipped feature list. Names and behavior may change before general
availability.
3 | Why custody is a separate layer
Evidence handed to a third-party assessor lives or dies on two questions: where did this come
from? and has anything changed since? The suite already signs its evidence; DDVault and
DDWitness are being built to carry the answer to those two questions as a first-class layer of their
own, so custody is not an afterthought bolted onto a report but a property the evidence carries with
it.
Separating the witness from the vault is the point. A component that both stores evidence and
vouches for it is its own single point of trust. By design, DDWitness is meant to attest to integrity
without holding the evidence, so the attestation does not depend on trusting the same place that keeps
the data.
Chain of custody is the trust vein of the whole suite: an artifact is only as good as
its traceability to origin and the proof it was not touched. DDVault and DDWitness are meant to make
that vein explicit and durable.
4 | Where it fits in the suite
DDVault and DDWitness sit beneath the rest of the DenseDefense suite. The
compliance engine scans and remediates your fleet and produces signed evidence; the offensive console
proves exposures and produces its own signed package. DDVault and DDWitness are being built as the
custody layer those signed artifacts rest on -- the enclave meant to hold them and the witness
meant to attest they are unchanged.
The intent is that a shop can hand an assessor not just evidence, but evidence whose origin and
integrity are independently accounted for -- the same honest, provable posture the suite holds
everywhere else, extended to the custody of the evidence itself.
DDWitness is designed to attest without holding the evidence: the vault keeps the
data, the witness vouches for it, and the two stay separate on purpose.
Licensing model: under the DenseDefense licensing scheme,
DDWitness is free for the life of your license -- the witness comes with any paid,
licensed edition at no separate charge and is not a separately purchasable add-on. It does require a license:
it is not part of the free scanner tier. DDVault -- the SaaS evidence vault that actually holds
the signed evidence -- is the optional, paid half: you add it when you want the suite to store
your evidence, not only witness it. If you cancel, DDVault keeps your evidence for 30 days so you can
still retrieve it before it is removed.
5 | Status & what comes next
DDVault and DDWitness are an Early-Adopter capability, in active development. They
ship today as evidence-custody integrations beneath the suite rather than as a standalone public REST
API, which is why this is an overview and not an API reference -- publishing an interface
reference for a surface still being shaped would be a promise the capability is not yet ready to
keep.
Available now: the early-access program. Contact us for
early access to see the custody layer take shape and to help steer it.
At general availability:full API documentation will be published
-- every route, its inputs, and its outputs -- in the same detailed reference form as the
rest of the suite's products.
Everything in this overview describes purpose and direction for a capability in
active development. Treat any behavior named here as not available today for planning
purposes, and confirm current status against the build you are offered.