Diwo Provenance vs Sema. What’s the actual difference?
Scanners tell you your code has bugs. AI-BOMs tell you what AI you ship. Provenance tells the board which of your code was written by AI, whether it’s governed, and shows the regulator the evidence. Sema and Provenance both detect AI authorship; only one turns that signal into a board-grade decision record.
Provenance is the governance layer for AI in the enterprise across two surfaces — the code AI writes at build time, and how AI agents behave at runtime. It sits above the scanners you already run (GitHub Advanced Security today) and above your runtime monitors (Datadog and event monitoring), correlates them against business criticality and scope decisions, and produces board-grade briefings mapped to the EU AI Act and NIST AI RMF. Its core signal is AI-authorship detection from git/PR metadata across the whole estate.
Sema is the closest single product to Provenance on the detection axis. Its AI Code Monitor uses ML-based content scanning to classify code as “pure GenAI”, “blended” or “human” at function, repository and developer levels, and produces a GBOM (Generative AI Bill of Materials) framed as evidence for legal and regulatory risk. Roots in M&A tech due diligence. Pre-order pricing has been public.
Where the products meet — and where they don’t.
Sema and Provenance both detect AI-authored code — the top row is the only place a Provenance-vs-vendor table has a “yes” on the other side. They diverge from the second row down. Sema stops at the GBOM as its deliverable; Provenance treats the AI signal as an input to a broader risk record that spans scanners, runtime and framework-mapped board briefings.
Categorization based on Provenance’s product capabilities (August 2026) and Sema’s publicly documented AI Code Monitor and GBOM materials. Sema is not a Diwo affiliate; comparisons reflect our reading of the public record and are refreshed before external use.
You need a GBOM report and detection is the whole job.
If your deliverable is a Generative AI Bill of Materials — a defensible content-scanning report on how much of a codebase is AI-authored, at function and repo granularity — Sema is a strong single-purpose choice, particularly for M&A tech due diligence, code-hygiene reviews and legal discovery contexts where its GBOM is the artifact the buyer wants. Its content-based classification catches cases where metadata is silent (squashed AI rewrites landing under a human identity with no bot trailer), and per-developer breakdowns are useful in workforce and productivity contexts. If your brief is “produce a GBOM” and nothing else, Sema is the fit.
Public pre-order pricing: $33/dev/mo annual, $82.50/dev/mo monthly.
Detection is only step one. The board needs a decision record.
If your audit committee is the audience — and the question isn’t just “how much code is AI-authored?” but “is any of it governed, and can we show that to the regulator?” — Provenance is the shape. Same detection as an input; then scanner coverage as first-class evidence, runtime agent-behaviour attribution back to the code that caused it, EU AI Act and NIST AI RMF article-level obligation mapping, and recorded human scope classifications with signatures. The output is an immutable board briefing with verdicts, not a content report. When the Big-4 sponsor of a governance program asks for a single system of record, that’s what Provenance is.
Provenance vs Sema — the questions buyers ask.
Is Diwo Provenance a replacement for Sema?
Not quite. Sema and Provenance both detect AI-authored code, and if that single question is the entire brief, Sema is a legitimate specialist choice — its GBOM is a strong deliverable for M&A tech due diligence and code-hygiene reviews. Provenance is a broader governance layer: same AI-authorship signal, plus scanner coverage (consumes GitHub Advanced Security), runtime agent-behaviour governance, EU AI Act and NIST AI RMF article-level mapping, scope classifications as recorded human decisions, and board-grade frozen briefings. If your audit committee is asking the question, Provenance is the shape; if your due-diligence team is the audience, Sema fits.
Can I use Provenance and Sema together?
Yes. The signals are compatible — Sema's content-scanning classification (pure GenAI / blended / human at the function level) can complement Provenance's metadata-based per-commit signal. Content-based and metadata-based detection cover different failure modes: content misses squashed rewrites of AI code (there's no trailer left), metadata misses AI code committed under a human's identity with no bot signature. Running both narrows both sides of that gap.
Does Sema do AI-authorship detection?
Yes — and this is why Sema is Provenance's closest single competitor on the detection axis. Sema's AI Code Monitor uses ML-based content scanning to classify code as pure GenAI, blended or human, at function, repo and developer levels, and produces a GBOM (Generative AI Bill of Materials). The methods differ: Sema is content-based; Provenance is multi-signal git/PR-metadata-based (bot authors, assistant commit signatures, review metadata). They are complementary approaches to the same question.
What does Provenance do that a GBOM doesn't?
Three things. First, framework-mapped evidence: the same estate graded against EU AI Act and NIST AI RMF article-level obligations, with a one-click framework switch. Second, the loop between build and runtime: when an AI agent misbehaves in production, Provenance attributes the behaviour back to the deployment, PR and author. Third, board-grade shape: recorded human scope classifications with signatures, immutable frozen briefings, and a print-to-PDF committee document. A GBOM is a machine-generated content report; Provenance is a decision record.
How does pricing compare?
Sema's public pre-order pricing was $33 per developer per month on annual, $82.50 per developer per month on monthly. Provenance is quoted as an enterprise governance platform (per-org fee with per-estate scaling); it's a different unit than Sema's per-developer AI Code Monitor unit. For enterprises that want both attribution and governance, running the two together is a reasonable topology — the budget lines are separate.
The decision layer above your scanners.
Provenance connects to your GitHub org and Azure DevOps in minutes. No code changes, no instrumentation. First AI-Code Risk Briefing in a day.
