Prove where every release came from. Create a traceable scan record for a repository today. Join early access for archive scanning, AI-origin evidence, dependency lineage, policy decisions, and audit-ready exports as each capability becomes available.
Provenance confidence
87%
Source provenance
Illustrative — not live outputTop evidence signals
Dependency lineage
Available now47 dependencies traced across npm + PyPI
3 known vulnerabilities matched (OSV.dev) · 1 high · 2 medium
Policy decision
Pass — 0 policy violations
Block critical-severity dependencies on release branches
Signed evidence ID
EV-2026-07-11-A1B2C3
2026-07-11T14:32:00Z
Availability
SOC 2 Ready
Built to SOC 2 controls — independent audit not yet started
Encrypted at rest
By our infrastructure providers
TLS 1.3
In transit
One platform for the four questions every security, legal, and engineering team needs answered before shipping.
Scan intake is live now. AI-origin scoring, stylometric evidence, and explainable confidence reports are planned for a future analysis-worker phase.
Define provenance rules for review today, with automated log, warn, block, and require-review actions planned for the worker-backed policy phase.
Per-scan dependency resolution across npm and PyPI with OSV.dev vulnerability matching is live now for repository scans. Transitive lineage graphs and additional ecosystems beyond npm/PyPI are planned for a future analysis-worker phase.
Prepare evidence intake now. SOC 2, EU AI Act, GDPR, and HIPAA report generation will unlock once scan results are produced.
Workflow
From signed-in upload intake to queued analysis workflow, with generated results rolling out in phases.
Submit a repository URL from the authenticated app and ProvenanceOS creates a durable queued scan job. Archive scanning is planned; archive analysis is not available yet.
View your scan request, source metadata, and queued status while the static-analysis worker rollout continues.
AI-origin evidence, dependency lineage, policy evaluation, and compliance exports arrive as the worker-backed phases ship.
Questions? Talk to our team
See how ProvenanceOS traces code provenance from intake to audit
ProvenanceOS is rolling out in phases. Get launch updates as AI-origin scoring, lineage, policy, and compliance reports come online.