Provenance Lens
Content Provenance for Compliance
Record reproducible provenance checks for governance and compliance without turning missing signals into authorship claims.
A reproducible control
- Pin the scanner and inspector versions.
- Store the report with the governed asset and decision record.
- Define review rules for VALID, INVALID, INCONCLUSIVE and UNSUPPORTED separately.
For developers
Install the local scanner. It runs offline, reads the same signals as the hosted version, and emits the same JSON report schema.
What a report cannot prove
- A valid signature proves who signed a manifest, not that the manifest's claims are true.
- Metadata is trivially editable. Treat generator fields as an indication, never as proof.
- Hidden Unicode characters have many innocent causes, including ordinary copy-paste.