Your code already has a history. Strategic Provenance turns that history into evidence.
Your code already has a history. Strategic Provenance turns that history into evidence.
What a CIO Should Be Able to Demonstrate About Their Repository in 2026, and How to Achieve It V-PROOF.
As of September 11, 2026, the Cyber Resilience Act already requires manufacturers of products with digital components to report actively exploited vulnerabilities and serious incidents. This is the first direct obligation for manufacturers under a regulation that will take full effect on December 11, 2027. At the same time, a growing portion of new code is written using AI-powered tools, and this is often not disclosed.
The auditor's question has changed. It is no longer, "Do you have a secure development policy?"
Most organizations are unable to respond. Not because of a lack of data—the repository stores everything—but because of the lack of a layer that turns that history into evidence.
In the code, the distance is the same.
Three blind spots that don't appear on any dashboard
Concentrated Knowledge
There are areas of the system that only one person understands. No one decides this; it just happens. The day that person leaves, the risk is no longer just theoretical.
Undeclared AI
The commit says “fix.” No one knows whether those 600 lines were written by a developer or an assistant. To your auditor, your insurance provider, and your client, the difference matters.
Changes That No One Explains
There are hundreds of changes between two versions. Management, clients, and auditors need to know what has changed in business terms, not in terms of diffs.
What Is Strategic Provenance?
Strategic Provenance is the module in V-PROOF that reads the repository and converts it into six governance views. Each one answers a specific question, and each result can be stamped as evidence.
Who knows what
System areas, commits read, authors, and bus factor by area (how many people would have to leave before no one understands that part of the system). When an area depends on a single person, or when only one author has made changes to it in recent months, the platform triggers an alert.
And it doesn't just stay on the screen: it goes directly into the risk log with a traceable identifier. The concentration risk goes from being a hunch to becoming a control.
Facts and opinions, separately
This is the issue we’re asked about most often—and the one that requires the most care. V-PROOF distinguishes between two figures that almost the entire market conflates:
- declared AI use. Lines added by commits whose message lists an AI co-author. This is a documented fact: it is recorded in the commit itself.
- Estimated AI. What the language model considers likely to have been written by AI. This is an opinion and is displayed separately, along with its confidence level.
If your team reports 1% and the estimate comes in at 30%, the difference alone does not prove that anything has been hidden: the estimate is simply the model’s opinion. But it does point to where to look—likely at the reporting culture. The view breaks down the data by month and by author, excludes lock files, generated files, vendor files, binary files, and secret files, and separates out lines from bots.
An auditor can dispute an estimate. They cannot dispute what's in the commit. That's why we never merge them.
The system, as depicted
Repository modules and their dependencies, visualized based on the glossary generated by the scan. View by area or by modules within an area, with components highlighted, and export to SVG, PNG, or Mermaid for technical documentation.
And it honestly states what it is: what the model read, not the code imports. Transparency regarding the method also serves as evidence.
Change, in business terms
You select two scanned points from the repository, and V-PROOF returns:
- A summary of what was added, modified, deleted, and left unchanged.
- What has changed functionally, written in business language.
- Release notes in Spanish, English, and Catalan, in two formats: technical and for customers.
What used to take a product manager one afternoon is now a document ready for the committee, the client, and the technical file.
Code checks, on every scan
Each completed scan automatically runs the code checks defined in Govern, the governance module of V-PROOF where the checks and risk log are stored:
- Secrets: credentials in the repository, detected and masked by the scan itself.
- Dependencies: permitted licenses, under observation, no registered license, or not permitted, and known vulnerabilities with public advisories.
- declared AI use: percentage of recent lines originating from commits that declare AI co-authorship.
- Tests by area: test files versus source files, area by area.
ImplementedPartiallyNot implemented
Each execution records evidence and a self-assessment of the control in Govern. The control is no longer just a box that someone checks once a year; it becomes a continuous measurement.
Evidence You Shouldn't Believe
The results are exported to a Word document (.docx) for the record and are are sealed with V-Seal®: SHA-256 hash, blockchain registration (L1/L2), and public third-party verification. The auditor doesn't have to take our word for it. They can verify it.
Privacy by Design: Your Code Stays Private
The first objection any CTO might raise is a legitimate one: “Are you sending my code to a model?”
Only glossary summaries and commit messages are sent to the model. Never code. Never emails.
Secrets are masked during the scan, before anything leaves your environment. Which model is used and what data is sent to it is displayed on screen for every operation that uses AI, because a privacy principle that isn’t visible isn’t a principle—it’s a promise.
The Auditor's Judgment: Six Questions
If we were to evaluate a code governance platform from an analyst's perspective, these would be the questions. And these are our answers.
| Question from the auditor | Response from V-PROOF |
|---|---|
| Does it distinguish between verifiable facts and estimates? | Yes. The " declared AI use " and "Estimated AI" are always displayed separately, with confidence levels shown. |
| Do findings become managed risks? | Yes. Awareness alerts are entered into the risk registry with their own identifier. |
| Are the controls evaluated on an ongoing basis? | Yes. For each completed scan, with written documentation in Govern. |
| Is the evidence verifiable by a third party? | Yes. Sealed at V-Seal with hash and anchored on the blockchain, publicly verifiable. |
| Does it protect the intellectual property rights associated with the code? | Yes. The code is never sent to the model; the secrets are masked. |
| Is it useful for business, not just for engineering? | Yes. Release notes in three languages and two formats, and a functional summary of each change. |
And what it doesn’t do, to put it plainly. The AI assessment is the model’s opinion, not proof; that’s why it’s listed separately. The architecture map reflects what the model read, not a static analysis of the code. And an AI co-authorship statement in a commit is a documented fact: it attests that the team made the statement, not that the statement is complete. Saying so is also evidence.
What Changes for Each Role
CIO
For the first time, a look at software risks that can be brought to the board: concentration of knowledge, Exposure dependencies, use of AI, and test coverage—with evidence sealed behind each figure.
CTO and Engineering
Identify areas with a bus factor of 1 before it's too late, and document the architecture without dedicating a sprint to it.
Developers
Fewer manual reports. Release notes, architecture maps, and checks are generated directly from the repository. And declaring AI is no longer just a possibility—it’s now a team standard.
Compliance, Risk, and the DPO
Technical evidence that does not rely on interviews or spreadsheets, aligned with the frameworks they already use for auditing.
Regulatory Framework
The repository already knows everything. Now it can prove it.
For years, code has been the most valuable—and worst-managed—asset in tech organizations. We kept it all, but we couldn't test anything.
Strategic Provenance changes that equation. Who understands each part of the system, how much the AI wrote, what changed in each version, and which controls are being followed—all measured with every scan, timestamped, and verifiable by anyone.
The code is written.
The source is verified.
