Diwo
Compare · Provenance vs Sema

Diwo Provenance vs Sema. What’s the actual difference?

Scanners tell you your code has bugs. AI-BOMs tell you what AI you ship. Provenance tells the board which of your code was written by AI, whether it’s governed, and shows the regulator the evidence. Sema and Provenance both detect AI authorship; only one turns that signal into a board-grade decision record.

What Diwo Provenance is

Provenance is the governance layer for AI in the enterprise across two surfaces — the code AI writes at build time, and how AI agents behave at runtime. It sits above the scanners you already run (GitHub Advanced Security today) and above your runtime monitors (Datadog and event monitoring), correlates them against business criticality and scope decisions, and produces board-grade briefings mapped to the EU AI Act and NIST AI RMF. Its core signal is AI-authorship detection from git/PR metadata across the whole estate.

diwo.ai/provenance

What Sema is

Sema is the closest single product to Provenance on the detection axis. Its AI Code Monitor uses ML-based content scanning to classify code as “pure GenAI”, “blended” or “human” at function, repository and developer levels, and produces a GBOM (Generative AI Bill of Materials) framed as evidence for legal and regulatory risk. Roots in M&A tech due diligence. Pre-order pricing has been public.

semasoftware.com/ai-code-monitor

12 capabilities, side by side

Where the products meet — and where they don’t.

Sema and Provenance both detect AI-authored code — the top row is the only place a Provenance-vs-vendor table has a “yes” on the other side. They diverge from the second row down. Sema stops at the GBOM as its deliverable; Provenance treats the AI signal as an input to a broader risk record that spans scanners, runtime and framework-mapped board briefings.

Capability
Diwo Provenance
Sema
AI-authorship detection (which code was written by AI)
Multi-signal detection from git/PR metadata — bot authors, Copilot/Claude/Devin signatures, review metadata — across the whole estate, retroactive on history.
Sema's AI Code Monitor uses ML-based content scanning to classify code as "pure GenAI", "blended" or "human" at function, repo and developer levels.
Tool-agnostic, no instrumentation, works retroactively
GitHub App + Azure DevOps connector against the estate you already have. Works on history from day one.
Content-based classification runs on the codebase as-is. No IDE agent required; retroactive on history.
Multi-SCM estate coverage (GitHub + ADO)
GitHub App (org-wide) plus an ADO connector; 52-repo live estate today.
GitHub-centric per the AI Code Monitor materials; wider SCM coverage rooted in Sema's M&A due-diligence heritage.
Sits above scanners (consumes GHAS, doesn't replace it)
Consumes GitHub Advanced Security (code scanning, secret scanning, Dependabot); correlates rather than re-scans; blind spots are first-class findings.
Sema is a content-scanning and attribution product. It doesn't consume a scanner's output or track scan-coverage gaps.
Runtime governance (agent behaviour in production)
Consumes Datadog and event-monitor metadata (alert name, tags, priority, transition — never traces or prompt payloads) and governs AI agent behaviour at runtime.
Sema is a build-time and code-content product. No runtime agent-behaviour governance surface.
Closes the build↔runtime loop (behaviour → PR/author)
When a production agent misbehaves, Provenance attributes the behaviour back to the exact deployment, PR and author — including whether the code was AI-authored.
No runtime signal in the product, so no loop to close.
Board-grade artifacts (frozen briefings, audit-committee output)
First-person AI-Code Risk Briefing with verdicts, an immutable frozen report library, and print-to-PDF board documents.
GBOM report is a compliance-flavoured artifact and a strong M&A due-diligence deliverable. Not the same shape as a board-committee memo with verdicts.
EU AI Act mapping from code evidence (article-level)
EU AI Act obligations graded against real code signals from the estate; framework switch is one click.
"Legal and regulatory risk" framing around GBOM; generic compliance mapping rather than article-level obligation grading.
NIST AI RMF mapping (same estate, same evidence)
Same evidence evaluator, one-click switch from EU AI Act to NIST AI RMF over the same estate.
Not part of the shipped product surface.
Risk classification as recorded human decisions
CISO scope classifications are append-only, with rationale and signature. Coach, not oracle.
GBOM is a machine-generated report; no scope-decision registry with signatures.
Conversational risk office (NL over tenant data)
Ask Provenance answers plain-English questions over tenant-isolated views and drives the dashboard.
No conversational-analyst surface documented over GBOM data.
White-label for services partners
Brand config (logo, colour, name) built for the Big-4 services channel.
Sema sells to services firms; no published customer-facing brand-config surface for partner white-label.

Categorization based on Provenance’s product capabilities (August 2026) and Sema’s publicly documented AI Code Monitor and GBOM materials. Sema is not a Diwo affiliate; comparisons reflect our reading of the public record and are refreshed before external use.

When to pick Sema

You need a GBOM report and detection is the whole job.

If your deliverable is a Generative AI Bill of Materials — a defensible content-scanning report on how much of a codebase is AI-authored, at function and repo granularity — Sema is a strong single-purpose choice, particularly for M&A tech due diligence, code-hygiene reviews and legal discovery contexts where its GBOM is the artifact the buyer wants. Its content-based classification catches cases where metadata is silent (squashed AI rewrites landing under a human identity with no bot trailer), and per-developer breakdowns are useful in workforce and productivity contexts. If your brief is “produce a GBOM” and nothing else, Sema is the fit.

Public pre-order pricing: $33/dev/mo annual, $82.50/dev/mo monthly.

When to pick Provenance

Detection is only step one. The board needs a decision record.

If your audit committee is the audience — and the question isn’t just “how much code is AI-authored?” but “is any of it governed, and can we show that to the regulator?” — Provenance is the shape. Same detection as an input; then scanner coverage as first-class evidence, runtime agent-behaviour attribution back to the code that caused it, EU AI Act and NIST AI RMF article-level obligation mapping, and recorded human scope classifications with signatures. The output is an immutable board briefing with verdicts, not a content report. When the Big-4 sponsor of a governance program asks for a single system of record, that’s what Provenance is.

Frequently asked

Provenance vs Sema — the questions buyers ask.

Is Diwo Provenance a replacement for Sema?

Not quite. Sema and Provenance both detect AI-authored code, and if that single question is the entire brief, Sema is a legitimate specialist choice — its GBOM is a strong deliverable for M&A tech due diligence and code-hygiene reviews. Provenance is a broader governance layer: same AI-authorship signal, plus scanner coverage (consumes GitHub Advanced Security), runtime agent-behaviour governance, EU AI Act and NIST AI RMF article-level mapping, scope classifications as recorded human decisions, and board-grade frozen briefings. If your audit committee is asking the question, Provenance is the shape; if your due-diligence team is the audience, Sema fits.

Can I use Provenance and Sema together?

Yes. The signals are compatible — Sema's content-scanning classification (pure GenAI / blended / human at the function level) can complement Provenance's metadata-based per-commit signal. Content-based and metadata-based detection cover different failure modes: content misses squashed rewrites of AI code (there's no trailer left), metadata misses AI code committed under a human's identity with no bot signature. Running both narrows both sides of that gap.

Does Sema do AI-authorship detection?

Yes — and this is why Sema is Provenance's closest single competitor on the detection axis. Sema's AI Code Monitor uses ML-based content scanning to classify code as pure GenAI, blended or human, at function, repo and developer levels, and produces a GBOM (Generative AI Bill of Materials). The methods differ: Sema is content-based; Provenance is multi-signal git/PR-metadata-based (bot authors, assistant commit signatures, review metadata). They are complementary approaches to the same question.

What does Provenance do that a GBOM doesn't?

Three things. First, framework-mapped evidence: the same estate graded against EU AI Act and NIST AI RMF article-level obligations, with a one-click framework switch. Second, the loop between build and runtime: when an AI agent misbehaves in production, Provenance attributes the behaviour back to the deployment, PR and author. Third, board-grade shape: recorded human scope classifications with signatures, immutable frozen briefings, and a print-to-PDF committee document. A GBOM is a machine-generated content report; Provenance is a decision record.

How does pricing compare?

Sema's public pre-order pricing was $33 per developer per month on annual, $82.50 per developer per month on monthly. Provenance is quoted as an enterprise governance platform (per-org fee with per-estate scaling); it's a different unit than Sema's per-developer AI Code Monitor unit. For enterprises that want both attribution and governance, running the two together is a reasonable topology — the budget lines are separate.

See it on your estate

The decision layer above your scanners.

Provenance connects to your GitHub org and Azure DevOps in minutes. No code changes, no instrumentation. First AI-Code Risk Briefing in a day.