Diwo
DIWO PROVENANCEAI Code Governance · Above All Your Scanners

Your scanners detect.
Provenance decides.

Provenance sits above every scanner you already run, correlates their findings against business criticality, and gives the CISO and the board one defensible, continuous picture of what actually matters — with every decision on record.

36/100
the Provenance Score — one number for the estate
52
repositories under continuous watch
LIVE · THE CONTINUOUS WATCHprovenance.diwo.ai
Estate · 52 repositories · continuous watch
payments-stripe-connector · payment-critical
DETECT2,387
GitHub Advanced Security raises 2,387 findings
built for every scanner you run — Snyk · Wiz · GitGuardian next
CORRELATE→ 1
One hotspot — not three separate alerts
code + secret + dependency findings agree · payment-critical weighting
DECIDEDO NOW
Rotate exposed secrets — owner assigned, SLA set
fix · waive · accept — rationale recorded, evidence snapshotted
PROVE36/100
Score updated · board record appended
EU AI Act · NIST AI RMF · auditor & insurer evidence
t+2.2s · watching 52 repos
Decision logged to audit trail
Found in week one
25 AI-PRs merged · 0 human reviews
The problem

A smoke detector tells you about one room. Nobody watches the building.

Every enterprise runs 4–8 scanners, each with its own screaming queue. 50,000 open findings — and no defensible way to say which 50 actually matter.

Your scanners today — one room each
GitHub Advanced Security
1,204 alerts
Dependabot
873 alerts
Snyk
612 alerts
Wiz
418 alerts
GitGuardian
97 alerts
= 3,204 alarms · no owner · no order
Provenance — the whole building
WATCHING
on fire · load-bearing covered blind
These 3 matter this week — here’s why, here’s the owner, here’s the decision on record.
Not a scanner — never will be. The decision, trust, and audit layer above the ones you already run.
Proven on a real org

AI is writing your code. Who signed off?

Found in the first continuous watch of a real 52-repo engineering org. Adopted fast, governed late — the pattern Provenance exists to catch.

0
AI-authored PRs merged
shipped without human sign-off
0
recorded human reviews
on those 25 merges
0/52
repositories ungraded
blind until scanning is enabled
How it works

Connect → Contextualize → Decide → Prove

01Connect

Pull signal from where code lives.

One-class onboarding for GitHub and Azure DevOps today; independent scanners next.

Provenance consumes findings — it never generates them.

Sources
synced 2d ago
AD
AZURE DEVOPS
MERIDIAN-AZ-CORE
1 repo
GH
GITHUB
meridian-platform
52 repos
Snyk · Wiz · GitGuardianROADMAP
AUTHGitHub connection resolvedscopes granted
PULL52 repositories discoveredmeridian-platform
CORRELATEai-ml-workload priority16 repos match
POSTURE2,387 findings ready to prioritize52 repos
THE ESTATE· UNDER WATCH
ALLALERTSUNSEEN
INTERNAL
PUBLIC-FACING
CUSTOMER-DATA
REGULATED
PAYMENT-CRITICAL
the core
THE ESTATE · THIS WEEK
52
REPOSITORIES
12
OPEN FINDINGS
1
AI-PR ALERT
ASSET CLASSES · NEAREST THE CORE FIRST
Payment-critical5 repos · 5 open
Regulated6 repos · 18 open
Customer-data12 repos · 1 alert · 2 open
Public-facing9 repos · 1 open
Internal20 repos · 7 open
1 alert 11 findings 5 clear · watched 35 unseensize = open findings · distance from core = criticality
02Contextualize

Map every repo to what it's worth.

Business criticality, asset classes, regulatory weight, blind spots.

Distance from the core is criticality — the radar shows which rooms are load-bearing.

03Decide

Prioritize, assign, and put the decision on record.

Recommendations in order — fix, waive, or accept, each with owner, rationale, SLA, and an evidence snapshot.

The decision loop closes where work happens.

Recommended — in order3 open
01
Rotate exposed secrets
2 open hardcoded credential findings on payments-stripe-connector, a payment-critical repo.
DO NOW
02
Require human approval on AI-authored merges
25 AI-generated pull requests merged with zero approving reviews.
THIS WEEK
03
Enable scanning where AI is writing the most code
untagged has the most unreviewed AI activity (17 PRs) but includes unscanned repos.
THIS WEEK
Standing decision: require a human approving review on AI-authored PRs
in force · recorded
SCORE 36/100
Provenanceby diwo
AI-CODE RISK BRIEFING
Last 6 months · 17 July 2026
TO THE BOARD OF DIRECTORS · FROM PROVENANCE, AI RISK OFFICERCONFIDENTIAL
AI-Code Risk Briefing
Reporting period: Last 6 months · estate of 52 repositories
EXECUTIVE SUMMARY

I observed 179 pull requests merged this period. Evidence shows 26 (15%) were AI-authored — 25 merged without a recorded human review.

Unreviewed by tool: claude (23), copilot (1), devin (1). Pace rising — 10 in the last month.

SAVE AS PDF
04Prove

The number your board can stand behind.

The Provenance Score, the Risk Office memo, the board-ready PDF.

Continuous evidence for auditors and insurers, mapped to EU AI Act and NIST AI RMF.

Pricing

Priced as governance, not as a scanner.

Start free. See your own estate before you spend a dollar.

Mirror
$0
Free forever
See your estate (up to 50 repositories), your score, your blind spots. 1 source · 1 user · weekly score email.
Connect your estate free
Work email + read-only connect. No credit card, no call.
MOST POPULAR
Team
$750/month
billed annually · or $900/month billed monthly
1 organization · up to 100 repositories · 5 users. Everything included: Briefing, Govern, policies, reports, Ask.
Start your 14-day trial
Full product, auto-starts when you connect. No card.
Enterprise
From $36,000/year
101+ repositories, banded. SSO/SCIM · unlimited users · BYO-LLM · audit exports · DPA & security review.
Talk to us
Scoped on two numbers from your own estate — repositories and AI workloads under governance.
Partner (white-label)
Custom
Your brand, your clients, multi-client management. The advisory margin is yours.
Partner with us
Every framework we ship is included. We don't sell compliance à la carte.
What happens when my trial ends?
Mirror keeps working, free, forever. We never hold your data hostage.
What do you read from our repos?
Signals, never source. Repository and pull-request metadata plus your scanners' findings. Source code never leaves your estate.
Will this make us EU AI Act compliant?
We grade evidence readiness against the frameworks; your counsel makes the legal call. Evidence readiness, not a legal determination.
Ask Provenance

Ask your estate anything

Plain-language answers over a read-only view of your estate — grounded in the same evidence that goes to your board. The same Catalyst pipeline, second product, one engine.

ASK PROVENANCEcontinuous watch
I’ve been watching your estate — 25 unreviewed AI PRs, 15% of 179 merged pull requests AI-authored, 47/52 repositories ungraded. Where should we start?
How did unreviewed AI-PRs trend over 6 months?Which repos do AI tools touch most?What should we do first?
Ask about your estate…
What Provenance is

Scanners find. Provenance decides.

Scanners are the oracles. Provenance is the coach — accumulated, contextual judgment with the decision loop closed.

A scanner that finds secrets and CVEs
The layer above the scanners that decides which findings matter
Yet another per-repo findings dashboard
One cross-estate posture: the number, the trend, the top decisions
A tool engineers ignore
A coach that pushes the top-N to where work happens
A point-in-time audit
Continuous monitoring with a defensible decision trail
A compliance questionnaire
Derived, not declared — the posture comes from the estate's own evidence, never from a survey
“Provenance is a forensics product wearing a governance suit.”

Chain of custody for AI-written code — who wrote it, who reviewed it, what the evidence shows, frozen so it can't be rewritten.

Why now

Your auditor, your insurer, and the SEC already require this

Continuous, defensible posture is no longer a preference — it’s the condition for staying insured, certified, and audit-ready.

100%of enterprises surveyed have AI-generated code in production
81%of security teams lack visibility into it (2026 survey of 400+ CISOs)
SEC
SEC cyber disclosure
Material incidents disclosed within 4 business days — you need the record before the clock starts.
EU
DORA
Continuous ICT risk monitoring and third-party oversight for financial entities.
NYDFS
Part 500
The CISO personally certifies the program. Certification wants evidence, not assurances.
UNDERWRITING
Cyber insurance
Premiums up 40–60% without continuous posture evidence at underwriting.
AUDIT
SOC 2 Type II / ISO 27001
Evidence over time, not a screenshot the week before the audit.
AI
EU AI Act / NIST AI RMF
AI-specific governance — findings and policies mapped to the framework your regulator reads. The EU AI Act's next obligations land August 2, 2026.
See where your estate stands before your auditor asks.
Solutions

One engine. The conversation your board is having.

AI Governance & Compliance
Govern AI-written code, mapped to EU AI Act and NIST AI RMF.
ROADMAP
SOC 2 Evidence
Continuous control evidence — SOC 2 in weeks, not months.
ROADMAP
Cyber-Insurance Readiness
The posture evidence underwriters price against.
ROADMAP
DORA Compliance
Continuous ICT risk monitoring for financial entities.
Get started

See your AI-code posture this afternoon.

Connect your first source in minutes — read-only, no credit card, no sales call. Your Provenance Score, your blind spots, and your first briefing, from your own estate.

Provenance — the governance layer for AI-written code.

Evidence readiness, not a legal determination. Provenance reads code signals — never your data.