Skip to content
Phylax
Get started

Introduction

Start verifying the AI software supply chain with Phylax.

What Phylax is

Phylax is the verification layer for the AI software supply chain. We provide independent attestations that prove the integrity, provenance, and policy compliance of the tools, models, and code your AI systems depend on.

Packages Verify AI and ML packages from registries and repositories.
MCP Servers Attest to Model Context Protocol servers and their capabilities.
Repositories Verify source code repositories and their provenance.
Policies Evaluate compliance with your organization’s policies and rules.

What Phylax verifies

Phylax verifies artifacts and components across the AI software supply chain, including:

  • Integrity. Artifacts haven’t been tampered with.
  • Provenance. Built from trusted sources and processes.
  • Security. Free from known vulnerabilities and risky dependencies.
  • Policy. Compliant with your organization’s rules and standards.

Why attestations matter

In AI systems, trust doesn’t stop at the model. It extends to every component in the supply chain, and Phylax attestations give you cryptographic proof you can rely on.

Phylax provides independent verification using the Secure Software Supply Chain Attestations (SSSA) standard, so you can trust what you build and ship.

Where to go next

Follow the suggested path to get started quickly, or dive deeper into core concepts and reference materials.

Did this page help you?