Your code already has a history. Strategic Provenance turns that history into evidence.

Strategic Provenance AI Governance AI Risk Management Regulatory Intelligence
For CIOs · CTOs · Development Teams

Your code already has a history. Strategic Provenance turns that history into evidence.

What a CIO Should Be Able to Demonstrate About Their Repository in 2026, and How to Achieve It V-PROOF.

September 24, 2026V-PROOF Protocol8-minute read

As of September 11, 2026, the Cyber Resilience Act already requires manufacturers of products with digital components to report actively exploited vulnerabilities and serious incidents. This is the first direct obligation for manufacturers under a regulation that will take full effect on December 11, 2027. At the same time, a growing portion of new code is written using AI-powered tools, and this is often not disclosed.

The auditor's question has changed. It is no longer, "Do you have a secure development policy?"

"Show me what happened in this version, who understood it, and how much of it was written by a machine."

Most organizations are unable to respond. Not because of a lack of data—the repository stores everything—but because of the lack of a layer that turns that history into evidence.

60 %of companies actively scaling AI
Gartner · 2024 AI Adoption Survey
4 %governs it with verifiable evidence
Gartner · AI Governance Maturity 2024
3 %can demonstrate this to a regulator
Gartner · Regulatory Readiness Report 2024

In the code, the distance is the same.

Three blind spots that don't appear on any dashboard

01

Concentrated Knowledge

There are areas of the system that only one person understands. No one decides this; it just happens. The day that person leaves, the risk is no longer just theoretical.

02

Undeclared AI

The commit says “fix.” No one knows whether those 600 lines were written by a developer or an assistant. To your auditor, your insurance provider, and your client, the difference matters.

03

Changes That No One Explains

There are hundreds of changes between two versions. Management, clients, and auditors need to know what has changed in business terms, not in terms of diffs.

What Is Strategic Provenance?

Strategic Provenance is the module in V-PROOF that reads the repository and converts it into six governance views. Each one answers a specific question, and each result can be stamped as evidence.

01 · Knowledge Map

Who knows what

System areas, commits read, authors, and bus factor by area (how many people would have to leave before no one understands that part of the system). When an area depends on a single person, or when only one author has made changes to it in recent months, the platform triggers an alert.

And it doesn't just stay on the screen: it goes directly into the risk log with a traceable identifier. The concentration risk goes from being a hunch to becoming a control.

02 · Human-to-AI Ratio

Facts and opinions, separately

This is the issue we’re asked about most often—and the one that requires the most care. V-PROOF distinguishes between two figures that almost the entire market conflates:

  • declared AI use. Lines added by commits whose message lists an AI co-author. This is a documented fact: it is recorded in the commit itself.
  • Estimated AI. What the language model considers likely to have been written by AI. This is an opinion and is displayed separately, along with its confidence level.
1%declared AI use · done
up to 30%estimated IA· opinion
70% Human
Humandeclared AI useEstimated AIBots · aside
Illustrative example.

If your team reports 1% and the estimate comes in at 30%, the difference alone does not prove that anything has been hidden: the estimate is simply the model’s opinion. But it does point to where to look—likely at the reporting culture. The view breaks down the data by month and by author, excludes lock files, generated files, vendor files, binary files, and secret files, and separates out lines from bots.

An auditor can dispute an estimate. They cannot dispute what's in the commit. That's why we never merge them.

03 · Architecture Map

The system, as depicted

Repository modules and their dependencies, visualized based on the glossary generated by the scan. View by area or by modules within an area, with components highlighted, and export to SVG, PNG, or Mermaid for technical documentation.

And it honestly states what it is: what the model read, not the code imports. Transparency regarding the method also serves as evidence.

04 · Comparison and Release Notes

Change, in business terms

You select two scanned points from the repository, and V-PROOF returns:

  • A summary of what was added, modified, deleted, and left unchanged.
  • What has changed functionally, written in business language.
  • Release notes in Spanish, English, and Catalan, in two formats: technical and for customers.

What used to take a product manager one afternoon is now a document ready for the committee, the client, and the technical file.

05 · Policy Checks

Code checks, on every scan

Each completed scan automatically runs the code checks defined in Govern, the governance module of V-PROOF where the checks and risk log are stored:

  • Secrets: credentials in the repository, detected and masked by the scan itself.
  • Dependencies: permitted licenses, under observation, no registered license, or not permitted, and known vulnerabilities with public advisories.
  • declared AI use: percentage of recent lines originating from commits that declare AI co-authorship.
  • Tests by area: test files versus source files, area by area.

ImplementedPartiallyNot implemented

Each execution records evidence and a self-assessment of the control in Govern. The control is no longer just a box that someone checks once a year; it becomes a continuous measurement.

06 · Sealing and Export

Evidence You Shouldn't Believe

The results are exported to a Word document (.docx) for the record and are are sealed with V-Seal®: SHA-256 hash, blockchain registration (L1/L2), and public third-party verification. The auditor doesn't have to take our word for it. They can verify it.

Privacy by Design: Your Code Stays Private

The first objection any CTO might raise is a legitimate one: “Are you sending my code to a model?”

Verification without revealing the content

Only glossary summaries and commit messages are sent to the model. Never code. Never emails.

Secrets are masked during the scan, before anything leaves your environment. Which model is used and what data is sent to it is displayed on screen for every operation that uses AI, because a privacy principle that isn’t visible isn’t a principle—it’s a promise.

The Auditor's Judgment: Six Questions

If we were to evaluate a code governance platform from an analyst's perspective, these would be the questions. And these are our answers.

Question from the auditorResponse from V-PROOF
Does it distinguish between verifiable facts and estimates?Yes. The " declared AI use " and "Estimated AI" are always displayed separately, with confidence levels shown.
Do findings become managed risks?Yes. Awareness alerts are entered into the risk registry with their own identifier.
Are the controls evaluated on an ongoing basis?Yes. For each completed scan, with written documentation in Govern.
Is the evidence verifiable by a third party?Yes. Sealed at V-Seal with hash and anchored on the blockchain, publicly verifiable.
Does it protect the intellectual property rights associated with the code?Yes. The code is never sent to the model; the secrets are masked.
Is it useful for business, not just for engineering?Yes. Release notes in three languages and two formats, and a functional summary of each change.

And what it doesn’t do, to put it plainly. The AI assessment is the model’s opinion, not proof; that’s why it’s listed separately. The architecture map reflects what the model read, not a static analysis of the code. And an AI co-authorship statement in a commit is a documented fact: it attests that the team made the statement, not that the statement is complete. Saying so is also evidence.

What Changes for Each Role

CIO

For the first time, a look at software risks that can be brought to the board: concentration of knowledge, Exposure dependencies, use of AI, and test coverage—with evidence sealed behind each figure.

CTO and Engineering

Identify areas with a bus factor of 1 before it's too late, and document the architecture without dedicating a sprint to it.

Developers

Fewer manual reports. Release notes, architecture maps, and checks are generated directly from the repository. And declaring AI is no longer just a possibility—it’s now a team standard.

Compliance, Risk, and the DPO

Technical evidence that does not rely on interviews or spreadsheets, aligned with the frameworks they already use for auditing.

Regulatory Framework

EU CRAVulnerability management, component knowledge, and technical product documentation.
EU AI ActTechnical documentation, registration, and traceability of high-risk AI systems (Articles 11 and 12), including evidence of how the system was built and modified.
NIS2Supply chain security and system development (Art. 21).
DORAICT Risk and Third-Party Risk Management in the Financial Sector.
ISO 42001AI management system controls with ongoing evidence.

The repository already knows everything. Now it can prove it.

For years, code has been the most valuable—and worst-managed—asset in tech organizations. We kept it all, but we couldn't test anything.

Strategic Provenance changes that equation. Who understands each part of the system, how much the AI wrote, what changed in each version, and which controls are being followed—all measured with every scan, timestamped, and verifiable by anyone.

The code is written.
The source is verified.

Humans Are Always Ahead of AI
Previous
Previous

We are finalists for the 2026 Innovacat Awards

Next
Next

AI Systems Inventory: A Practical Guide to Compliance | V-PROOF