Three steps: generate the document, publish it at the HTTPS address you selected, and advertise that address with one CVD-Policy field in your security.txt. The generator, validator and explainer all run in the browser.
Its own repository, its own domain, its own look. No field exists in the format because a service needed one. Aeskal consumes the specification like anyone else.