Evidence-first assessment
Every conclusion is grounded in an observed manifest, repository file, provider response, or explicit omission state.
Lockverity
Local-first software assurance
Lockverity inspects public GitHub repositories and source archives without executing analyzed code. It preserves provenance, keeps missing evidence visible, and gives you a persistent local workspace for software supply-chain review.
At-a-glance evidence of repositories, scans, findings, and provider availability.
Lockverity focuses on what was observed, what supported a finding, and whether provider evidence was complete when the result was produced.
Every conclusion is grounded in an observed manifest, repository file, provider response, or explicit omission state.
Keep repositories, scans, findings, diagnostics, and evidence history in one desktop application.
Uploaded archives are treated as untrusted input. Lockverity does not execute analyzed code or repository scripts.
Unavailable, partial, degraded, and not-applicable states are kept distinct rather than flattened into a false clean result.
Revisit results instead of losing context in one-off terminal output. Useful for developers, consultants, and smaller security teams.
A simple local workflow for checking public repositories or source archives without adopting a full enterprise AppSec platform.
Point Lockverity at a public GitHub repository or upload a source ZIP.
Lockverity identifies manifests, dependencies, provider observations, and relevant supply-chain signals.
See what was found, what evidence supported it, and where evidence was incomplete.
Return later to repositories, scans, findings, and diagnostics in the same local workspace.
The Windows build is currently unsigned, so Windows may show an Unknown Publisher or SmartScreen warning. Lockverity publishes SHA-256 checksums so you can verify the installer before running it.
831264757dccde2c8feef0422390d9812f053fcad811455bde868756c7757bfdNo admin required
Per-user Windows installation.
No analyzed code execution
No npm install, pip install, Makefile, or repository shell execution.
Open source
Inspect the source and star the project on GitHub.
Windows 10/11 x64. The recommended installer is per-user and requires no administrator privileges.