Diwo
Compare · Provenance vs ZeroPath

Diwo Provenance vs ZeroPath. What’s the actual difference?

Scanners tell you your code has bugs. AI-BOMs tell you what AI you ship. Provenance tells the board which of your code was written by AI, whether it’s governed, and shows the regulator the evidence.

What Diwo Provenance is

Provenance is the governance layer for AI in the enterprise across two surfaces — the code AI writes at build time, and how AI agents behave at runtime. It sits above the scanners you already run (GitHub Advanced Security today) and above your runtime monitors (Datadog and event monitoring), correlates them against business criticality and scope decisions, and produces board-grade briefings mapped to the EU AI Act and NIST AI RMF. Its core signal is AI-authorship detection from git/PR metadata across the whole estate.

diwo.ai/provenance

What ZeroPath is

ZeroPath is an AI-native AppSec platform positioned as “One Scanner. All of AppSec.” — SAST, SCA, secrets, IaC, DAST and autofix in one product, designed to replace the traditional scanner stack. Its AIBOM feature ships a CycloneDX ML-BOM per repository that catalogs the AI components a codebase contains (models, agent frameworks, LLM SDKs, MCP servers), framed for EU AI Act transparency and inventory duties. YC S24; RSAC 2026 Innovation Sandbox Top-10 finalist.

zeropath.com/products/aibom · /pricing · /faq

12 capabilities, side by side

Where the products meet — and where they don’t.

ZeroPath and Provenance are architecturally opposite postures. ZeroPath replaces scanners; Provenance consumes them. ZeroPath’s AI-BOM inventories AI components in a repo; Provenance’s core signal is which code was written by AI across the whole estate. If you already run ZeroPath, adding Provenance is additive, not competitive.

Capability
Diwo Provenance
ZeroPath
AI-authorship detection (which code was written by AI)
Multi-signal detection from git/PR metadata — bot authors, Copilot/Claude/Devin signatures, review metadata — across the whole estate, retroactive on history, no IDE plugin required.
ZeroPath's AI-BOM catalogs AI components a codebase ships (models, agent frameworks, LLM SDKs, MCP servers). Nowhere in the product does it detect AI-authored code.
Tool-agnostic, no instrumentation, works retroactively
GitHub App + Azure DevOps connector against the estate you already have. Works on repo history from day one.
Runs as a scanner on repos it has access to. No dependency on IDE agents, but it produces new scan output rather than reading what's already there.
Multi-SCM estate coverage (GitHub + Azure DevOps)
GitHub App (org-wide) plus an ADO connector; 52-repo live estate today.
GitHub, GitLab, Azure DevOps and Bitbucket integrations documented on their product pages.
Sits above scanners (consumes GHAS, doesn't replace it)
Consumes GitHub Advanced Security (code scanning, secret scanning, Dependabot); correlates rather than re-scans; unscanned repos are first-class findings.
ZeroPath positions as "One Scanner. All of AppSec." — SAST, SCA, secrets, IaC, DAST and autofix designed to replace the scanner stack. Their FAQ confirms they ingest nothing external.
Runtime governance (agent behaviour in production)
Consumes Datadog and event-monitor metadata (alert name, tags, priority, transition — never traces or prompt payloads) and governs AI agent behaviour at runtime.
ZeroPath is a build-time AppSec product. No runtime agent-behaviour governance surface.
Closes the build↔runtime loop (behaviour → PR/author)
When a production agent misbehaves, Provenance attributes the behaviour back to the exact deployment, PR and author — including whether the code was AI-authored.
No runtime signal in the product, so no loop to close.
Board-grade artifacts (frozen briefings, audit-committee output)
First-person AI-Code Risk Briefing with verdicts, an immutable frozen report library, and print-to-PDF board documents.
GRC-style AI-BOM exports (CycloneDX ML-BOM) and dashboards. Component inventory, not a board memo with verdicts.
EU AI Act mapping from code evidence
EU AI Act obligations graded against real code signals from the estate — coverage, unreviewed AI merges, signed scope decisions. Framework switch is one click.
Positions the AI-BOM as evidence for EU AI Act transparency/inventory obligations. No risk-tier classification, no article-level obligation grading.
NIST AI RMF mapping (same estate, same evidence)
Same evidence evaluator, one-click switch from EU AI Act to NIST AI RMF over the same estate.
Not part of the published AI-BOM product surface.
Risk classification as recorded human decisions
CISO scope classifications are append-only, with rationale and signature. Coach, not oracle.
No scope-decision registry.
Conversational risk office (NL over tenant data)
Ask Provenance answers plain-English questions over tenant-isolated views and drives the dashboard.
No conversational-analyst surface documented.
White-label for services partners
Brand config (logo, colour, name) for the Big-4 channel play.
MSP white-label mentioned in their programme materials — direct channel overlap.

Categorization based on Provenance’s product capabilities (August 2026) and ZeroPath’s publicly documented AIBOM, scanner and FAQ pages. ZeroPath is not a Diwo affiliate; comparisons reflect our reading of the public record and are refreshed before external use.

When to pick ZeroPath

You want to consolidate the scanner stack.

If your AppSec problem is that SAST, SCA, secrets, IaC and DAST are four different tools with four different consoles and four different licence lines, ZeroPath’s consolidation pitch is real. Their AIBOM is a legitimate way to answer the EU AI Act inventory duty for what AI components a codebase ships, and their autofix and BYO-LLM options are strong for teams that want to stay entirely inside one AppSec platform. If you also need a CycloneDX ML-BOM per repository as a compliance artifact, ZeroPath ships that today. That is a different job than governing AI-authored code across the estate.

Public pricing: from $1,000/mo + $60/dev (active devs, unlimited repos and scans). Enterprise custom.

When to pick Provenance

You have to answer the board’s AI question.

If the question in the room is “how much of our code is being written by AI, is any of it governed, and can you show that to a regulator or the audit committee?” — that’s the Provenance job. You keep the scanners you already have (GHAS today, ZeroPath tomorrow if you want it), Provenance sits above them, blind spots become first-class findings rather than silence, and every board briefing is mapped to EU AI Act and NIST AI RMF obligations from real code evidence — not a questionnaire. When a production agent misbehaves, Provenance attributes the behaviour back to the deployment, PR and author, and records whether the code was AI-authored.

Frequently asked

Provenance vs ZeroPath — the questions buyers ask.

Is Diwo Provenance a replacement for ZeroPath?

No. ZeroPath is a scanner platform — it replaces your GHAS / Snyk / Semgrep stack and produces its own SAST, SCA, secrets, IaC and DAST findings. Provenance is a governance layer that sits above scanners and consumes their output. If you want to consolidate scanner spend, ZeroPath is the category. If you want a board- and regulator-facing view of AI in your code — including which code was AI-authored and whether it was governed — Provenance is a different layer and doesn't compete with the detection engines beneath it.

Can I run Provenance and ZeroPath together?

Architecturally yes, and it's the cleanest topology if you already run ZeroPath: ZeroPath detects vulnerabilities and inventories AI components per repo; Provenance sits above and correlates AI-authorship signals, scanner coverage, runtime agent behaviour and scope classifications into a single board-grade risk view. Today Provenance's shipped scanner integration is GitHub Advanced Security — a ZeroPath-as-source integration is a natural extension when a customer runs both.

Does ZeroPath do AI-authorship detection?

No. ZeroPath's AI-BOM is a CycloneDX ML-BOM per repository — it catalogs the AI components a codebase ships (models, agent frameworks, LLM SDKs, MCP servers). It answers "what AI is in your software." Nowhere in the product does it detect which code was written by AI. Their "Secure AI-Generated Code" page is a scanner pitch ("your devs use AI, so scan better"), not an attribution feature. Provenance's core signal — bot authors, assistant commit signatures, PR review metadata across the whole estate — is a different problem, solved with different inputs.

Isn't an AI-BOM enough for the EU AI Act?

An AI-BOM covers the transparency/inventory duties around AI components you ship. It doesn't cover the downstream documentation obligations the Commission's GPAI guidance describes — which model was used, what governed generation, what human review occurred, what modifications were made. Provenance derives that evidence from the estate itself: scan coverage, unreviewed AI merges, signed scope decisions, framework-mapped verdicts. Two different questions; Provenance answers the second one.

How do the products differ on channel?

ZeroPath offers MSP white-label. Provenance ships brand config (logo, colour, name) built for the Big-4 services channel — the PwC play in particular. If you're a services partner reselling an AI-code-governance layer to your clients, that's the operating model Provenance is designed for.

See it on your estate

The decision layer above your scanners.

Provenance connects to your GitHub org and Azure DevOps in minutes. No code changes, no instrumentation. First AI-Code Risk Briefing in a day.