Commercial packages
Mixes first. SKUs by group.
Start with Templates — buy-once Next.js starters — or browse Trust & Attestation SKUs. Choose All to scan every SKU.
SKU group
Open package →Trust & Attestation
Public verifier, Proof posture, and Built-with badges — integrity outputs for procurement.
Flomisma Verify
Self-hosted attestation — one-time purchase
Self-hosted hash-chain attestation toolkit: HMAC signing and verification with your own key, plus an optional RFC 3161 third-party timestamp anchor. No hosted service, no recurring billing.
- →@flomisma/verify-standalone npm + CLI
- →Optional RFC 3161 timestamp anchor
- →One-time purchase — buy once, own the code
Proof — Infra Posture Scanning
DNS, SSL, and header scoring with Merkle attestation
Continuous infrastructure posture monitoring for DNS configuration, SSL certificate health, and HTTP security headers. Free tier for one-off scans. Paid tiers unlock real-time monitoring, multi-domain coverage, and attestation-grade Merkle-rooted posture records.
- →DNS posture — SPF, DKIM, DMARC, DNSSEC scored and attested
- →SSL / TLS cert validity, HSTS, TLS version check
- →HTTP security headers — CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy
- →Merkle-rooted posture snapshots (Growth and above)
- →ARPU expansion through tier upgrades — not reseller margin
Built with Flomisma
Verifiable badge for template and licensee buyers
HMAC-signed SVG badge linked to your template license. Counterparties verify deployment without exposing internal evidence.
- →SVG badge + verify endpoint
- →Included with template license delivery email
- →Links to public pipeline verifier