Verifiable AI Code Governance
01 / 07

Code is also
accountable.

Many developers, many branches, one central repository. With each analysis, Code Governance reviews the changes before they reach the branch, builds the project's technical history, and records its checks in the same governance registry as the rest of your AI.

163branches in a single repository
446commits from 4 authors, with their history
466functionality glossary entries
3release-note languages

Data from a V-PROOF repository analyzed using the platform in September 2026.

Before the branch
02 / 07

Catch the problem before the pull request.

In each analysis, Code Governance reviews the changes before the pull request is created and flags any rule violation, before the code is reviewed and before it reaches production.

Audited in accordance with its rules

Each change is analyzed against the development standards that the organization defines in AI Library, not against generic rules.

Secrets and Vulnerabilities

Detects credentials, passwords, and sensitive variables in the code, as well as dependencies with known, publicly reported vulnerabilities.

Flagged before the branch

When a change violates a rule or reveals a secret, it is flagged and recorded as evidence. Controls monitor; they do not hinder the team's work.

Demo · 1:30Verifiable AI Code Governance

Ninety seconds.From commit to evidence.

Every change is attributed to its author, whether human or AI assistant; reviews and tests are recorded as evidence; and the seal is preserved from development to production. Recorded on the V-PROOF portal, without mockups.

  1. 00:36
    Repository audit: architecture, branches and sealed commits
  2. 00:48
    History by developer and commit V-Seals
  3. 01:06
    Human-to-AI Ratio and Architecture Map
  4. 01:15
    Sealed commit and public verification
Video · V-PROOF Code Governance
V-PROOF Portal · Live Recording
Automatic Controls
03 / 07

Each analysis leaves a record in the log.

For each completed analysis, the platform evaluates the organization’s code controls and records the result as evidence and a self-assessment of the control in the governance module. The code is entered into the same record, the same audit trail, and the same proof as the rest of the AI.

Secrets

Credentials in the code. The analysis identifies them, and the check ensures that there are none.

Branches

Permitted licenses, licenses under review, unregistered licenses, prohibited licenses, and known vulnerabilities.

declared AI use

What percentage of the new lines come from commits that list an AI as a co-author?

Tests by Area

Test files versus code files, in each part of the project.

Each control is classified as "Implemented," "Partially Implemented," or "Not Implemented," along with the figures supporting that classification.

Declared AI use: measuring code authorship.

For the technical team, it’s a governance issue. For the legal team, it’s an intellectual property issue. Knowing which part of the code was written by an AI is the starting point for determining who the author is, and it ties in with the authorship that the platform already records for its other assets.

Release Notes
04 / 07

Between two versions, in business language.

Two points from the repository are selected for analysis, and the platform explains what has changed functionally: what was added, modified and removed. It then generates release notes in Spanish, Catalan, or English, ready for the client or the committee.

V-PROOF Portal · Compare & Release NotesLive Screen · September 24, 2026
Comparison of two versions of a repository, showing what was added, changed, and removed1234
  1. 1Two points: The branch and the source and target commits being compared
  2. 2What's included: Summaries from the glossary and commit messages; never code or files
  3. 3Measured cost: Input and output tokens for each comparison
  4. 4Result: 280 added, 121 changed, 246 removed, and 63 unchanged
The project's technical report
05 / 07

What exists, who changed it, and how it all fits together.

The functionality that already exists

Organized by branch, linked to the exact lines, and exportable to Word. Before developing anything new, the team knows whether it has already been done.

Who changed what, and when?

Commits, authors, and comments for each branch, sorted chronologically. A 360-degree view, regardless of the number of developers.

The architecture map

The modules and their dependencies, generated from the glossary. Can be exported as SVG, PNG, or Mermaid.

V-PROOF Portal · Architecture MapLive Screen
Architecture map of a branch, showing its modules and dependencies1234
  1. 1Two views: by area, or by module within an area
  2. 2Exportable in SVG, PNG, or Mermaid, for documentation
  3. 3Each area: Its modules, glossary entries, and types
  4. 4Dependencies: Relationships between areas as defined in the glossary, not based on code imports
Prove
06 / 07

The commit, backed by cryptographic evidence.

A commit is associated with cryptographic evidence, along with its glossary and history: it records what code was there, what it did, and who changed it, all at a single moment. It is verified on the public portal and exported for an auditor or client.

V-PROOF Portal · Code AuditLive Screen · September 23, 2026
Branch with glossary, development history, and verifiable cryptographic evidence of the commit 1 2 3 4
  1. 1Branches: 163 in a single repository
  2. 2Glossary with 466 entries, exportable to Word
  3. 3Commit history: 446 commits by 4 authors
  4. 4 Evidence The commit associated with its glossary and its history through verifiable cryptographic evidence
In plain terms
07 / 07

What it does and what it doesn't do.

Automatic checks are self-assessments. The status is determined based on the analysis and is recorded in AI Governance, where the owner reviews it.
"declared AI use" measures what is declared. AI usage that is not included in the commit does not appear.
The map reflects what the model read in the glossary, not the imports in the code: it serves as a guide, not a substitute for static analysis.
Detecting secrets and vulnerabilities is not a penetration test. It does not replace a security review.
The functional analysis is written by a language model, and the screen identifies it as having been written by AI.
Your organization chooses the model. V-PROOF does not decide which provider the summaries are sent to.
The Full View

The entire project on one screen, without having to rely on anyone who knows it by heart.

Fewer hours of review

Branches, pull requests, and changes, explained in business terms.

Secrets and Dependencies

Controls evaluated in each analysis, with evidence recorded in the governance registry.

Authorship and Licenses

Which parts of the code are marked as AI co-authored, and what licenses do the dependencies carry?

How much of your code do you really know?

A technical demo on one of your repositories, with your organization's policies.