- source code & diffs
- prompt text
- specification documents
- review comments
- test output & logs
AI agents now write a growing share of your code. OLOBOLO records the evidence as it happens — spec, author, review, tests — in a tamper-evident chain, and turns it into audit-ready reports your customers, auditors and acquirers will ask for.
Git history shows what changed and who committed. It doesn't show which agent wrote it, from which instruction, or how it was verified. Three doors this question walks through:
"What share of your codebase is AI-generated, and how is it reviewed?"
Enterprise procurement · vendor assessment"Document your development and QA trail for software placed on the EU market."
EU Product Liability (recast) · from Dec 2026"We need the provenance of this codebase before we can price the deal."
Technical due diligence · M&APassive by design — your team doesn't change how it works. OLOBOLO enriches the events that already happen in git, CI and your agent tooling.
A GitHub App plus a lightweight CLI hook capture authorship, agent identity, spec links, reviews and test runs the moment they happen.
Every event becomes an entry in an append-only, hash-linked log. Nothing can be edited afterwards — corrections are new entries, on the record.
Each release closes its chain with a seal. One click turns it into a release report, a vendor profile or a due diligence package.
OLOBOLO records fingerprints and metadata — hashes that prove your material existed, unchanged, at a point in time. The material itself stays where it belongs: with you.
To verify, an auditor hashes your local material and compares it with the chain — no trust in OLOBOLO required. The chain export is open format; verification needs nothing but a hash utility.
Procurement officers, auditors and deal teams don't read dashboards. They read documents — reproducible, exception-disclosing, independently verifiable.
The same recorded chain answers questions from regulators, customers, auditors and acquirers. You record once — and reuse the evidence wherever the question comes from.
Software is now explicitly a "product". In a liability case, your development and quality-assurance trail becomes evidence — and courts can order disclosure of it.
OLOBOLO provides: a contemporaneous, tamper-evident record of how each release was built, reviewed and tested — recorded before any incident, not reconstructed after.
Read the guide →Where AI systems or AI-assisted development are in scope, documentation of human oversight and development provenance is part of the compliance picture.
OLOBOLO provides: per-change attribution of agent vs. human authorship, and proof that agent output passed human review — the oversight trail, on the record.
Read the guide →Products with digital elements sold in the EU will require technical documentation of secure development and ongoing vulnerability handling.
OLOBOLO provides: evidence that changes — including AI-authored ones — went through your defined review and test gates, release by release.
Read the guide →Supply-chain security duties (NIS2) and ICT risk management in finance (DORA) push documentation demands down onto software vendors — you, if you sell to those sectors.
OLOBOLO provides: vendor-profile answers about your development controls, backed by verifiable data instead of a questionnaire promise.
Read the guide →Certification and attestation audits ask for evidence that your change-management and review controls actually operate — every period, every sample.
OLOBOLO provides: sampled chain entries as audit evidence: authorship, approval and test linkage per change, exportable for your auditor.
Read the guide →Enterprise procurement and public tenders increasingly ask: "What share of your code is AI-generated, and how is it quality-assured?" A shrug loses the deal.
OLOBOLO provides: a standing vendor profile with verified numbers — AI share, review coverage, test evidence — ready before the question arrives.
Read the guide →A necessary honesty: OLOBOLO is evidence, not a legal opinion. We attest to what was recorded — mapping notes show where the chain supports each framework, and your counsel decides what compliance requires. No tool can promise the latter; be wary of any that does.
Verified organisations get a mark for their website footer, decks and business plans. It always links to a live, public verification page — and it glows only while your chain verifies.
You're looking at one right now — see ours in the footer below ↓
Evidence has to be recorded before it's needed — it can't be reconstructed afterwards. That's why starting is free, private repositories included. When the question arrives, your chain already exists — upgrading unlocks the reports on the history you've been recording all along.
You can't reconstruct a chain you never recorded. Install today, and every change from this moment is on the record.