Diwo
DIWO PROVENANCEAI Code Governance · Two Surfaces, One Loop

Who approved the AI-written code you shipped?

Provenance keeps the record of who approved every AI-written change — derived from what actually happened in your repos, not what someone declared. Connect in the morning, see your evidence by the afternoon.

36/100
the Provenance Score — one number for the estate
52
repositories under continuous watch
LIVE · THE CONTINUOUS WATCHprovenance.diwo.ai
Estate · 52 repositories · continuous watch
payments-stripe-connector · payment-critical
DETECT2,387
GitHub Advanced Security raises 2,387 findings
built for every scanner you run — Snyk · Wiz · GitGuardian next
CORRELATE→ 1
One hotspot — not three separate alerts
code + secret + dependency findings agree · payment-critical weighting
DECIDEDO NOW
Rotate exposed secrets — owner assigned, SLA set
fix · waive · accept — rationale recorded, evidence snapshotted
PROVE36/100
Score updated · board record appended
EU AI Act · NIST AI RMF · auditor & insurer evidence
t+2.2s · watching 52 repos
Decision logged to audit trail
Found in week one
25 AI-PRs merged · 0 human reviews
Who it’s for
Compliance & Audit

Evidence-ready for every audit. The continuous record your auditors and regulators expect — not a screenshot the week before.

Legal

Attestation and accountability, on record. Know who approved what, and when — a defensible answer before anyone has to give one.

Engineering & Security

Connect your repos; the record keeps itself. Read-only, no new scanner, no new agent in your pipeline.

The problem

A smoke detector tells you about one room. Nobody watches the building.

Every enterprise runs 4–8 scanners, each with its own screaming queue. 50,000 open findings — and no defensible way to say which 50 actually matter.

Your scanners today — one room each
GitHub Advanced Security
1,204 alerts
Dependabot
873 alerts
Snyk
612 alerts
Wiz
418 alerts
GitGuardian
97 alerts
= 3,204 alarms · no owner · no order
→
Provenance — the whole building
WATCHING
● on fire · load-bearing● covered● blind
These 3 matter this week — here’s why, here’s the owner, here’s the decision on record.
Not a scanner — never will be. The decision, trust, and audit layer above the ones you already run.
Proven on a real org

25 AI-written PRs merged. Zero recorded approvals.

Found in the first continuous watch of a real 52-repo engineering org. Adopted fast, governed late — the pattern Provenance exists to catch.

0
AI-authored PRs merged
shipped without human sign-off
0
recorded human reviews
on those 25 merges
0/52
repositories ungraded
blind until scanning is enabled
Two surfaces · one loop

The behaviour points back at the code that caused it.

In August 2026 the frontier AI labs themselves disclosed that their agents had escaped test sandboxes and acted on outside systems — one lab found its incidents only after reviewing 141,006 test sessions. Same root cause as every publicly reported agent incident before it: ungoverned when the code was written, unrecorded once the agent was live, nobody decided. Every other tool stops at one end. Provenance closes the loop.

Surface one · The code
AI-WRITTEN CODE
Who wrote it, who reviewed it, what the scanners found, what it’s worth.

Authorship, review discipline, scanner findings, business criticality — the governed record of the code before it ships.

merged · AI-authored · 0 approving reviews · payment-critical
→
←
Surface two · The agent
DATADOG · LIVE
What the agent actually did in production, the moment it did it.

A runtime alert resolves to the exact merge commit that shipped — the author, the review record, the AI attribution. Observed, then attributed, then decided.

P2 alert → deploy version → PR · AI-authored: true · decision on record
Scanners govern code they can’t watch. Observability watches behaviour it can’t attribute. Provenance is the layer that closes the loop.
signals, never telemetry payloads
How it works

Connect → Contextualize → Decide → Prove

01Connect

Pull signal from where code lives.

One-class onboarding for GitHub and Azure DevOps; Datadog for runtime — two keys and a webhook, not a migration.

Provenance consumes findings and signals — it never generates them, and never reads your telemetry payloads.

Sources
synced 2d ago
AD
AZURE DEVOPS
MERIDIAN-AZ-CORE
1 repo
GH
GITHUB
meridian-platform
52 repos
DD
DATADOG · RUNTIME
meridian-observability
live
Snyk · Wiz · GitGuardianROADMAP
AUTHGitHub connection resolvedscopes granted
PULL52 repositories discoveredmeridian-platform
CORRELATEai-ml-workload priority16 repos match
POSTURE2,387 findings ready to prioritize52 repos
RUNTIMEAlert attributed to its merge commitAI-authored · decided
THE ESTATE· UNDER WATCH
ALLALERTSUNSEEN
INTERNAL
PUBLIC-FACING
CUSTOMER-DATA
REGULATED
PAYMENT-CRITICAL
the core
THE ESTATE · THIS WEEK
52
REPOSITORIES
12
OPEN FINDINGS
1
AI-PR ALERT
ASSET CLASSES · NEAREST THE CORE FIRST
Payment-critical5 repos · 5 open
Regulated6 repos · 18 open
Customer-data12 repos · 1 alert · 2 open
Public-facing9 repos · 1 open
Internal20 repos · 7 open
● 1 alert● 11 findings● 5 clear · watched● 35 unseensize = open findings · distance from core = criticality
02Contextualize

Map every repo to what it's worth.

Business criticality, asset classes, regulatory weight, blind spots.

Distance from the core is criticality — the radar shows which rooms are load-bearing.

03Decide

Prioritize, assign, and put the decision on record.

Recommendations in order — fix, waive, or accept, each with owner, rationale, SLA, and an evidence snapshot.

The decision loop closes where work happens.

Recommended — in order3 open
01
Rotate exposed secrets
2 open hardcoded credential findings on payments-stripe-connector, a payment-critical repo.
DO NOW
02
Require human approval on AI-authored merges
25 AI-generated pull requests merged with zero approving reviews.
THIS WEEK
03
Enable scanning where AI is writing the most code
untagged has the most unreviewed AI activity (17 PRs) but includes unscanned repos.
THIS WEEK
Standing decision: require a human approving review on AI-authored PRs
in force · recorded
SCORE 36/100
Provenanceby diwo
AI-CODE RISK BRIEFING
Last 6 months · 17 July 2026
TO THE BOARD OF DIRECTORS · FROM PROVENANCE, AI RISK OFFICERCONFIDENTIAL
AI-Code Risk Briefing
Reporting period: Last 6 months · estate of 52 repositories
EXECUTIVE SUMMARY

I observed 179 pull requests merged this period. Evidence shows 26 (15%) were AI-authored — 25 merged without a recorded human review.

Unreviewed by tool: claude (23), copilot (1), devin (1). Pace rising — 10 in the last month.

SAVE AS PDF
04Prove

The number your board can stand behind.

The Provenance Score, the Risk Office memo, the board-ready PDF.

Continuous evidence for auditors and insurers, mapped to EU AI Act and NIST AI RMF.

Pricing

Priced as governance, not as a scanner.

Start free. See your own estate before you spend a dollar.

FREE
Assessment
Free
Read-only, no card, no call
See your estate, your score and your blind spots. One organization, read-only connect, weekly score email. It is a diagnostic, not a trial that expires.
Connect your estate free
Work email + read-only connect. No credit card, no call.
MOST RELEVANT
Enterprise
Annual
Scoped to what you are governing
Business units, frameworks in scope, engineering population, reporting cadence. SSO/SCIM · unlimited users · BYO-LLM · audit exports · DPA & security review.
Talk to us
We scope it against your own estate, then put a number on it.
Partner (white-label)
Custom
Your brand, your clients
Multi-client management under your own brand. White-label is a setting in the product today, not a project. The advisory margin is yours.
Partner with us
Every framework we ship is included — and so is every runtime connector. We don't sell compliance à la carte.
Onboarding: “The Watch” — two weeks to your number, included.
What happens after the assessment?
It keeps working, free, for as long as you want it. We never hold your data hostage.
What do you read from our repos?
Signals, never source. Repository and pull-request metadata plus your scanners' findings. Source code never leaves your estate.
Will this make us EU AI Act compliant?
We grade evidence readiness against the frameworks; your counsel makes the legal call. Evidence readiness, not a legal determination.
Ask Provenance

Ask your estate anything

Plain-language answers over a read-only view of your estate — grounded in the same evidence that goes to your board. The same Catalyst pipeline, second product, one engine — and now from Claude Desktop too, via MCP.

ASK PROVENANCEcontinuous watch
I’ve been watching your estate — 25 unreviewed AI PRs, 15% of 179 merged pull requests AI-authored, 47/52 repositories ungraded. Where should we start?
How did unreviewed AI-PRs trend over 6 months?Which repos do AI tools touch most?What should we do first?
Ask about your estate…
→
What Provenance is

Scanners find. Provenance decides.

Scanners are the oracles. Provenance is the coach — accumulated, contextual judgment with the decision loop closed.

A scanner that finds secrets and CVEs
The layer above the scanners that decides which findings matter
Yet another per-repo findings dashboard
One cross-estate posture: the number, the trend, the top decisions
A tool engineers ignore
A coach that pushes the top-N to where work happens
A point-in-time audit
Continuous monitoring with a defensible decision trail
A compliance questionnaire
Derived, not declared — the posture comes from the estate's own evidence, never from a survey
“Provenance is a forensics product wearing a governance suit.”

Chain of custody for AI-written code — who wrote it, who reviewed it, what the evidence shows, frozen so it can't be rewritten.

Companion Guide · 2026

A Guide to AI Code Governance in the Agentic Era.

Why detecting AI-written code stops short of governing it — and what a provable accountability layer actually does. The four jobs, code + agents on one estate, and evidence you can put in front of an auditor.

  • Attribute → Classify → Decide → Prove
  • The code + the agent
  • EU AI Act · NIST · ISO 42001
  • Diwo Provenance
Free · 18 pages · PDF
Read on the web· No email required
Why now

Your auditor, your insurer, and the SEC already require this

Continuous, defensible posture is no longer a preference — it’s the condition for staying insured, certified, and audit-ready.

100%of enterprises surveyed have AI-generated code in production
81%of security teams lack visibility into it (2026 survey of 400+ CISOs)
SEC
SEC cyber disclosure
Material incidents disclosed within 4 business days — you need the record before the clock starts.
EU
DORA
Continuous ICT risk monitoring and third-party oversight for financial entities.
NYDFS
Part 500
The CISO personally certifies the program. Certification wants evidence, not assurances.
UNDERWRITING
Cyber insurance
Premiums up 40–60% without continuous posture evidence at underwriting.
AUDIT
SOC 2 Type II / ISO 27001
Evidence over time, not a screenshot the week before the audit.
AI
EU AI Act / NIST AI RMF
AI-specific governance — findings and policies mapped to the framework your regulator reads. The EU AI Act's GPAI obligations have been in force since August 2, 2026.
See where your estate stands before your auditor asks.
Solutions

One engine. The conversation your board is having.

AI Governance & Compliance
Govern AI-written code, mapped to EU AI Act and NIST AI RMF.
ROADMAP
SOC 2 Evidence
Continuous control evidence — SOC 2 in weeks, not months.
ROADMAP
Cyber-Insurance Readiness
The posture evidence underwriters price against.
ROADMAP
DORA Compliance
Continuous ICT risk monitoring for financial entities.
Get started

See your AI-code posture this afternoon.

Connect your first source in minutes — read-only, no credit card, no sales call. Your Provenance Score, your blind spots, and your first briefing, from your own estate.

Provenance — the governance layer for AI-written code, at build time and runtime.

Evidence readiness, not a legal determination. Provenance reads code signals — never your data.