Written for the person who has to sign it

Auditors are not persuaded by dashboards. They ask where a number came from, whether the source can be altered and what the gaps are. The report answers those three questions before it shows anything else.
Book a demo

What a report contains

Scope and period, AI contribution by repository and file, the tools and models seen, redaction statistics, the chain verification result and the proportion of lines that could not be attributed.

  • Repository and period
  • Tools and models observed
  • Chain verification result
  • Unknown proportion
  • Redaction statistics

Every figure is defined

The methodology section states what counts as AI-authored, how ambiguous matches are resolved and what unknown means. A reader who disagrees with a definition can see it rather than infer it.

Formats that survive a handover

JSON for pipelines, HTML for review and PDF for the file that ends up attached to an audit response. All three carry the same hash so copies can be compared.

  • JSON
  • HTML
  • PDF

What it will not do

Invent a number

If a metric was not measured it is left empty with a note, rather than defaulted to zero.

Hide the gaps

Unmonitored repositories are listed as unmonitored. Silence is not treated as compliance.

Claim a certification

The report is evidence you can submit. It is not an attestation, and it does not pretend to be one.

Questions before you buy

Can we produce this for a specific audit window?

Yes. Reports take a from and to date and cover only events inside it, with the window printed on the first page.

Does the report prove nothing was altered?

It carries the result of chain verification for the period it covers. If the chain is intact the report says so and names the range; if it is broken the report says where.

Will it satisfy our regulator?

That depends on your regulator and your control framework, and anybody who answers otherwise is guessing. What the report does is turn an unanswerable question into a documented one.

See a report generated from a real repository.

Bring a codebase you have questions about. The gaps are usually the interesting part.