Code Provenance Engine
Automated code-level compliance assessment
Scope: This report covers code-level controls only — static analysis of source code,
dependency scanning, and provenance chain verification. It does not assess infrastructure configuration,
organizational policies, access management, or process controls. This is a development aid, not a
certification or audit opinion.
Overall Posture Score:
86/100
— Good
Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
Executive Summary
| Framework | Score | Verdict |
| OWASP Top 10 (2021) |
75/100 |
Needs Attention |
| SOC 2 Type II |
83/100 |
Good |
| PCI-DSS v4.0 |
88/100 |
Good |
| EU AI Act — Article 12 |
92/100 |
Good |
| ISO/IEC 42001:2023 |
94/100 |
Good |
OWASP Top 10 (2021) 2021
75/100
Needs Attention
3 passed •
0 failed •
3 partial •
1 not covered
| ID | Control | Description | Status | Findings |
A01:2021 |
Broken Access Control |
Restrictions on what authenticated users are allowed to do are often not properly enforced. |
PARTIAL |
2 finding(s) |
A02:2021 |
Cryptographic Failures |
Weak cryptography and exposed sensitive data (hardcoded keys/secrets, MD5/SHA-1). |
PARTIAL |
2 finding(s) |
A03:2021 |
Injection |
SQL/command injection and XSS from untrusted input reaching an interpreter. |
PASS |
— |
A05:2021 |
Security Misconfiguration |
Permissive CORS, disabled TLS verification, and committed env secrets. |
PARTIAL |
3 finding(s) |
A07:2021 |
Identification & Authentication Failures |
Hardcoded credentials, tokens, and connection-string passwords. |
PASS |
— |
A08:2021 |
Software & Data Integrity Failures |
Use of known-vulnerable dependencies. |
PASS |
— |
A09:2021 |
Security Logging & Monitoring Failures |
RepoScope does not analyze logging or monitoring configuration. |
NOT COVERED |
— |
SOC 2 Type II Type II
83/100
Good
4 passed •
0 failed •
2 partial •
7 not covered
| ID | Control | Description | Status | Findings |
CC1.1 |
COSO Principle 1 — Integrity & Ethics |
Not covered by code scanning — requires organizational evidence (policies, training records). |
NOT COVERED |
— |
CC2.1 |
Information for Internal Use |
Not covered by code scanning — requires process evidence. |
NOT COVERED |
— |
CC3.1 |
Risk Assessment |
Not covered by code scanning — requires organizational risk register. |
NOT COVERED |
— |
CC4.1 |
Design & Operate Monitoring Controls |
Not covered by code scanning — RepoScope scan history can serve as supporting evidence of continuous monitoring. |
NOT COVERED |
— |
CC5.1 |
Technology General Controls |
Deployed technology controls — no hardcoded credentials, enforced TLS, no weak cryptography. |
PARTIAL |
2 finding(s) |
CC6.1 |
Logical Access Security |
Logical access controls — no hardcoded keys, passwords, tokens, or committed env secrets. |
PASS |
— |
CC6.2 |
Credentials & Secrets Management |
Prior to issuing credentials, registered or authorized — code-level: no hardcoded credentials, secrets, or tokens in source. |
PASS |
— |
CC6.3 |
Access Removal |
Removal of access rights. Not covered by code scanning — requires IAM evidence. |
NOT COVERED |
— |
CC6.6 |
System Boundaries |
Boundary protection — restrictive CORS and enforced TLS verification. |
PARTIAL |
2 finding(s) |
CC6.8 |
Software Security |
Prevention of unauthorized/malicious code paths — injection and unsafe execution. |
PASS |
— |
CC7.1 |
Monitoring of Controls |
Not covered by code scanning — the security-score trend can serve as supporting evidence. |
NOT COVERED |
— |
CC8.1 |
Change Management |
Not covered by code scanning — the git-aware repo map and scan history can serve as evidence. |
NOT COVERED |
— |
CC9.1 |
Risk Mitigation Procedures |
Identify and assess risks — known-vulnerable dependency scanning serves as partial evidence. |
PASS |
— |
PCI-DSS v4.0 v4.0
88/100
Good
3 passed •
0 failed •
1 partial •
0 not covered
| ID | Control | Description | Status | Findings |
6.2.4 |
Software Security (Injection/XSS) |
Protect against injection and XSS in bespoke and custom software. |
PASS |
— |
6.5.1 |
Vulnerability Management |
Address known vulnerabilities in software components. |
PASS |
— |
8.3.6 |
Authentication |
No hardcoded passwords; use strong cryptography for credentials. |
PARTIAL |
2 finding(s) |
3.5.1 |
Protect Stored Account Data |
No hardcoded keys, connection-string credentials, or committed env secrets. |
PASS |
— |
EU AI Act — Article 12 2024/1689
92/100
Good
5 passed •
0 failed •
1 partial •
0 not covered
| ID | Control | Description | Status | Findings |
Art12.1.a |
Automatic Event Logging |
High-risk AI systems shall support automatic recording of events (logs) over their lifetime. Art. 12(1). |
PASS |
— |
Art12.1.b |
Traceability of AI Outputs |
Logging capabilities shall ensure traceability of the functioning of the AI system throughout its lifecycle. Art. 12(1). |
PASS |
— |
Art12.2.a |
Identification of Input Data |
Logging shall include recording of the input data or a reference to it. Art. 12(2)(a). |
PARTIAL |
1 finding(s) |
Art12.2.b |
Tamper-Evidence |
Logs shall be tamper-evident. The integrity of logged events must be verifiable. Art. 12(2). |
PASS |
— |
Art12.3 |
Retention & Accessibility |
Logs shall be kept for a period appropriate to the intended purpose. Art. 12(3). |
PASS |
— |
Art12.4 |
National Authority Access |
Logs shall be available to national competent authorities upon request. Art. 12(4). |
PASS |
— |
Note: Code-level provenance controls only. This assessment identifies where AI-generated code exists and whether provenance records are in place. It is a development aid for Article 12 readiness, not a legal compliance determination — consult qualified legal counsel for formal compliance assessment.
ISO/IEC 42001:2023 2023
94/100
Good
8 passed •
0 failed •
1 partial •
8 not covered
| ID | Control | Description | Status | Findings |
A.5.3 |
AI System Impact Assessment |
Assess the potential impacts of AI systems. Not covered by code scanning — requires organizational risk assessment. |
NOT COVERED |
— |
A.6.1.3 |
Responsible AI Design & Development |
Code injection prevention and secure development practices for AI systems. A.6.1.3. |
PASS |
— |
A.6.1.4 |
AI System Documentation |
Technical documentation of AI systems. Not fully covered by code scanning — RepoScope detects provenance gaps as a proxy. |
PASS |
— |
A.6.2.4 |
AI System Testing & Validation |
Testing and validation of AI system outputs. Not covered by code scanning — requires test result evidence. |
NOT COVERED |
— |
A.6.2.6 |
AI System Deployment Criteria |
Defined criteria for deploying AI systems. Not covered by code scanning — requires deployment policy evidence. |
NOT COVERED |
— |
A.6.2.8 |
AI System Event Logging |
Maintain logs of AI system events to support traceability and auditability. A.6.2.8 — directly corresponds to the provenance ledger and audit trail. |
PASS |
— |
A.7.2 |
Data Quality for AI |
Ensure data quality for AI system training and operation. Not covered by code scanning — requires data pipeline evidence. |
NOT COVERED |
— |
A.7.3 |
Data Provenance |
Record and maintain the provenance of data used by AI systems. Covered by the hash-chained provenance ledger and input-reference tracking. |
PARTIAL |
1 finding(s) |
A.7.4 |
Data Preparation |
Documented procedures for data preparation. Not covered by code scanning. |
NOT COVERED |
— |
A.7.5 |
Data Acquisition |
Controls over how data is acquired for AI systems. Code-level: no hardcoded secrets in AI data pipelines, no committed env secrets. |
PASS |
— |
A.8.2 |
AI System Transparency |
Provide information about AI system use. Code-level: provenance export demonstrates AI-origin disclosure capability. |
PASS |
— |
A.8.4 |
Reporting AI System Issues |
Mechanisms for reporting issues with AI systems. Not covered by code scanning — requires process evidence. |
NOT COVERED |
— |
A.9.2 |
AI System Use Procedures |
Procedures for appropriate use of AI systems. Not covered by code scanning. |
NOT COVERED |
— |
A.9.3 |
Human Oversight of AI |
Appropriate human oversight of AI system operation. Not covered by code scanning. |
NOT COVERED |
— |
A.9.4 |
AI System Monitoring |
Ongoing monitoring of AI system performance and impact. Code-level: provenance chain integrity and retention policy serve as partial evidence. |
PASS |
— |
A.10.2 |
Third-Party AI Components |
Controls over third-party AI components. Code-level: known-vulnerable dependency scanning. |
PASS |
— |
A.10.3 |
Supply Chain Security |
Secure AI supply chain. Code-level: no hardcoded secrets in third-party integrations, enforce TLS. |
PASS |
— |
Note: Code-level AI management controls only. ISO/IEC 42001 requires organizational policies, risk assessments, and process evidence that are beyond the scope of code scanning. This is a development aid for identifying code-level control gaps, not a certification tool — consult a qualified auditor for formal certification.
Code Provenance Summary
Derived from the Code Provenance Engine (CPE) ledger.
| Total ledger entries | 4 |
| AI-generated entries | 3 |
| Chain integrity | Entries present — run a Provenance scan to verify |
| Latest entry | 2026-06-27T08:22:00.000Z |
Legal Notices
Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
This report was generated by RepoScope (RepoScope v5.9.0). It reflects code-level
controls at the point in time shown above and does not constitute a formal
compliance certification. Consult a qualified auditor for certification decisions.