ProvenanceEvidence, validation & provenance

Turn findings into defensible decisions.

Trace each finding to exact source, replay the evidence independently, expose counter-evidence and preserve who decided what happens next.

Provenance keeps the evidence behind a finding inspectable. Detection, validation, human review and remediation state remain distinct.

PROVENANCE / PROJECT EVIDENCEDemonstration project
Provenance supply-chain view connecting repository evidence to dependency, cryptographic and decision paths.

Actual product capture · Sanitized project

LocateOpen the exact source and dependency context
ReplayTest the frozen evidence independently
ChallengeRecord assumptions and counter-evidence
DecidePreserve an attributable human outcome
Why Breakwater Provenance

Move from scanner output to a finding you can defend.

What evidence makes the finding defensible?

Most application security workflows preserve the alert and lose the reasoning. Provenance keeps the exact source, independent replay, challenge history and accountable decision together.

01LocateExact source and dependency context
02ReplayIndependent evidence validation
03ChallengeAssumptions and counter-evidence
04DecideNamed human disposition
01 / SOURCEExact evidenceLine · dependency · cryptographic use
02 / VALIDATIONIndependent replayFrozen input · hash · result
03 / DECISIONAttributable outcomeReviewer · rationale · state
Provenance supply-chain view connecting frozen repository evidence to software, cryptographic cohorts and reviewable decision paths.
Carry source evidence into the decision.Software identities, dependency paths and cryptographic use remain connected to the frozen repository surface that produced them.
Your existing layerIt providesBreakwater addsDecision enabled
SAST, SCA and secrets toolsA rule match and severityExact source, content identity and replay stateWhether the finding still matches the evidence
Developer workflowA ticket or remediation requestPrerequisites, counter-evidence and minimal changeWhat must be fixed and why
Governance and auditStatus and ownership fieldsChallenge history and attributable dispositionWho decided, on which evidence
Evidence that survives scrutiny

Every decision keeps its supporting record.

Provenance moves beyond a scanner result by binding the finding to the source it cites, replaying the evidence, exposing challenge state and retaining the human decision that follows.

1V
Detector match
Rule, source location and the evidence that produced the finding.
FOUND
2V
Independent replay
Re-evaluate the frozen source and verify that the cited evidence still matches.
MATCHED / FAILED
3V
Adversarial review
Inspect assumptions, prerequisites, contradictions and recorded counter-evidence.
CHALLENGED
4V
Attributable human decision
Preserve who accepted, rejected, suppressed, deferred or escalated the finding and why.
GOVERNED
Application evidence

Know what supports the finding.

Provenance brings source analysis, dependency intelligence, validation and remediation review into one inspectable chain.

01 / SOURCE

Exact source context

Open the cited source in context and retain content identity so a later review can tell whether the evidence changed.

02 / REPLAY

Independent validation

Replay findings against frozen evidence and fail closed when source, context or required inputs no longer match.

03 / CHALLENGE

Assumptions and counter-evidence

Make the conditions behind a finding visible and preserve evidence that weakens, qualifies or refutes the claim.

04 / DEPENDENCIES

Software provenance

Examine direct and transitive dependencies, origin and repository context alongside the findings they influence.

05 / CRYPTOGRAPHY

PQC readiness in source

Locate cryptographic use in software and organize the code, dependency and ownership questions that shape migration.

06 / REMEDIATION

Governed change review

Review a minimal proposed change, prerequisites, verification result, rollback plan and approval state before action.

The product, on screen

Follow the finding from evidence to decision.

Selected recorded workflows show how Provenance preserves exact evidence, independent validation, unresolved questions and the human decision boundary.

Provenance finding view showing assumptions, counter-evidence, matched evidence replay and a pending human 4V review.
01 / EVIDENCE REPLAY

Replay the exact evidence.

Recheck the frozen source identity and retain assumptions, counter-evidence and replay state before human review.

Provenance view showing standards correlation, source replay state and a finding that remains marked as needing human review.
02 / DEPENDENCY PROVENANCE

Connect the finding to signed context.

Keep standards correlation, advisory identity and validator state attached without promoting an unresolved match to certainty.

Provenance view showing a model-generated security brief alongside deterministic validation and evidence replay.
03 / AI SECURITY BRIEF

Use AI without giving it authority.

A marked security brief can explain an established finding while the evidence record and human disposition remain outside model control.

From result to rationale

Give reviewers the same source of truth.

Engineering, security and governance teams can examine the same finding at different depths without losing the chain that connects evidence to decision.

  1. Register the source

    Define repository, revision, authorized scope and the exact material the analysis can inspect.

  2. Analyze and replay

    Run the applicable analysis and bind each material claim to evidence that can be replayed.

  3. Challenge the claim

    Review prerequisites, alternative explanations, impact and any counter-evidence before disposition.

  4. Govern the outcome

    Record the decision, remediation proposal, verification result and accountable owner.

Coverage with provenance

Bring different analysis surfaces into one evidence model.

Coverage is release-dependent and should be confirmed during evaluation. The value is the consistent record around each result: source, scope, evidence, replay, challenge and decision.

PROVENANCE / CBOM + SBOMDemonstration data
Provenance view showing a cryptographic bill of materials beside a software bill of materials, including evidence and assurance state.

Actual product capture · Demonstration data · Evidence boundary shown

Source and dependency analysis

Review application code, open-source components, secrets and infrastructure definitions with the cited source available.

Container and deployment material

Carry container and configuration findings into the same validation and decision process.

Authorized dynamic testing

Keep rules of engagement, target scope and test evidence with results from approved running applications.

Cryptographic inventory

Connect cryptographic use in code and dependencies to post-quantum readiness and migration planning.

Where it fits

Add a trust layer across AppSec.

Provenance complements the tools that find weaknesses. It helps teams determine what the result can support, what still needs review and how to preserve the decision.

SAST, SCA and secrets tools

Normalize results into a review process that keeps exact source, validation and disposition available after the scan completes.

Developer workflows

Give engineers the cited evidence, prerequisites and smallest reviewable change instead of a detached ticket summary.

Governance and audit

Preserve who decided, which evidence they reviewed and whether the source changed after the decision.

Runtime and edge protection

Use runtime findings as another source of evidence. Provenance does not replace WAF, WAAP, EDR or live traffic enforcement.

Operating boundary

The limits remain visible.

A defensible result includes what the current evidence cannot establish.

  • A detector match is a claim to review, not an automatic verdict.
  • Repository analysis does not prove which software version is installed on a device.
  • Coverage varies by language, framework, analysis surface and selected release.
  • Optional model assistance does not replace deterministic validation or human disposition.
  • A proposed remediation remains separate from authorization, execution and fresh verification.
Before an evaluation

Questions worth asking.

What should we evaluate first?

Choose a repository and a small set of findings that currently require manual reconstruction. Agree how replay, challenge and human disposition will be judged.

Does Provenance replace a mature AppSec suite?

It can provide analysis surfaces, but mature suites may offer broader language, IDE, registry and runtime coverage. Evaluate the selected release against your required ecosystems and use Provenance where decision-grade evidence matters.

Does AI decide whether a finding is valid?

The evaluation should distinguish deterministic analysis and validation from any optional model assistance. A model response should not silently become a verdict or an authorization.

Can Provenance remediate code automatically?

Remediation is governed and capability-dependent. Review the proposed diff, scope, tests, rollback and approval route. A generated change is not permission to modify a repository.

One ASOC platform

Carry the decision into operations.

Discover establishes the connected exposure. Provenance determines what supports the finding. Response governs the operational next step and verifies the result.

Start with one disputed finding

Plan a focused Provenance evaluation.

Bring a repository, an authorized scope and a result your team needs to defend. We will define what evidence and validation should establish.

Product view