Nucleus Systems Code Trust Assurance Framework
Trust, proven acrossidentityintegritysecure developmentthe supply chainruntime behaviourgovernance
A continuous, cryptographically verifiable, and measurable standard for software code trust — spanning identity, integrity, secure development, supply chain, runtime assurance, and governance.
Security tools find issues. This framework proves trust.
Organisations scan code. They still can’t prove software trust.
SolarWinds, Log4Shell, and XZ Utils showed that perimeter-only security fails when the threat originates in trusted software. Every dependency, pipeline, and AI-generated commit is a trust decision — and most organisations cannot demonstrate, continuously and with evidence, that those decisions are controlled.
Nucleus Systems Code Trust Assurance Framework treats every stage of software production and distribution as an independently assessable trust boundary — producing a single, quantified Trust Score.
Find issues in code you already have.
Proves the whole system can be trusted.
Is a point-in-time snapshot.
Is a continuous, evidence-backed measure.
Five questions most organisations cannot answer
Not with policy. With evidence a third party could verify independently. The framework exists because these answers have to be provable, not asserted.
- 01
Can you cryptographically prove that the developer who committed code to your production branch is who they claim to be?
- 02
Can you demonstrate that your build pipeline was not modified between the last security audit and today's release?
- 03
Do you have independently verifiable build provenance attestations a downstream consumer could verify without trusting your assertions?
- 04
Is every dependency in your production software pinned to a cryptographically verified version?
- 05
When a runtime anomaly occurs in production, can you trace it to a specific code change, in a specific commit, by a specific verified contributor?
Answer them for your own organisation
0 of 5 answeredCan you cryptographically prove that the developer who committed code to your production branch is who they claim to be?
Can you demonstrate that your build pipeline was not modified between the last security audit and today's release?
Do you have independently verifiable build provenance attestations a downstream consumer could verify without trusting your assertions?
Is every dependency in your production software pinned to a cryptographically verified version?
When a runtime anomaly occurs in production, can you trace it to a specific code change, in a specific commit, by a specific verified contributor?
You cannot currently evidence code trust. Start with identity and build provenance.
Indicative only. A formal assessment scores 86 controls across six domains and five axes.
Every one of these maps to a scored control, an evidence requirement, and a maturity level — so the answer becomes a number you can put in front of a board or a customer.
Read the full rationaleSix domains. Eighty-six controls.
The Nucleus Systems Code Trust Assurance Framework measures trust across the full software lifecycle — each domain weighted by its impact on overall software trust posture.
Identity & Provenance
Who wrote the code, and where it came from.
Integrity & Immutability
Whether builds and artifacts are tamper-proof.
Secure Development Practices
Whether secure engineering stops vulnerabilities at the source.
Dependency & Supply Chain
Whether third-party components are governed and controlled.
Runtime Behavior Assurance
Whether deployed software keeps behaving as expected.
Governance & Accountability
Whether ownership and policy sustain trust over time.
Identity & Provenance
Who wrote the code, and where it came from.
Developer and build identity cryptography, SBOM generation, contributor trust weighting, AI-generated code attribution, and cross-organisation identity federation.
Every software artifact inherits trust from its creators and origins. Without cryptographically verified developer identity, commit authorship cannot be attributed and dependency origins cannot be traced.
How the domains are weighted
Weights reflect each domain’s impact on overall software trust posture.
From evidence to a public trust signal
Assessment combines evidence, maturity scoring, automated tooling, and independent assessor validation.
Evidence
SBOMs, signing, scans, attestations, runtime and governance data collected and registered.
Assessment
86 controls scored across 5 axes, hard gates applied, evidence independently validated.
Output
Trust Score, domain scores, board report, and a prioritised 12-month roadmap.
Certification
A CTA-1 to CTA-4 certificate and a public Trust Registry listing.
Not all evidence carries the same weight. A control scores higher when its evidence is machine-verifiable and independently reproducible rather than asserted.
The strongest, machine-verifiable proof.
Automated output from tooling and pipelines.
Maintained records and process artefacts.
The weakest tier — assertions only.
Four levels of Code Trust Assurance
Based on the Trust Score and minimum domain thresholds — with seven hard gates that must pass regardless of overall score.
Transparent
45+ controls
The software supply chain is visible. SBOMs, basic scanning, dependency inventory, and ownership are in place.
Verified
63+ controls
Trust is backed by cryptographic evidence — artifact signing, build provenance, and automated security controls.
Assured
78+ controls
Trust is continuously measured across development, supply chain, runtime, and governance.
Adaptive Trust
86 / 86 controls
Trust is automated, continuously computed, self-healing, and independently verified.
Verify certified companies
A public directory where the market can verify certified companies by continent, country, sector, year, and certification level.
Verdex Technologies
Verdex Cloud Platform
Ironpath Software
Ironpath Delivery Suite
Solaris Build Systems
Solaris CI Cloud
Paxley Software
Paxley Core
Check a certificate right here
Enter a certificate ID — or try one of the specimens — to see exactly what a customer doing due diligence on you would see.
Basic certificate verification is public. Certificate downloads, bulk checks, API verification, and full reports are available through Report Access bundles.
Verify a CertificateOne number the board understands
The 0–100 Trust Score summarises true code-trust posture across all six domains — mapped directly to certification readiness.
Aligned with the standards that matter
Nucleus Systems Code Trust Assurance Framework maps to major software-security frameworks and regulations — so a single assessment addresses multiple compliance obligations.
Before you trust a vendor’s software, verify its code trust posture.
Fixed fee $15,000 USD · ~20 business days · Final report, CTA certificate, and 12-month roadmap.
