The flight recorder for AI-built software

Prove who wrote every change — human or agent.

AI agents now write a growing share of your code. OLOBOLO records the evidence as it happens — spec, author, review, tests — in a tamper-evident chain, and turns it into audit-ready reports your customers, auditors and acquirers will ask for.

Free for open source. Five-minute setup. Your code never leaves your infrastructure.
Recording · payments-api · liveevidence/chain.jsonl
  1. 1041spec.linkedactor:a91f · SPEC-231 v3c4e1…9b02
  2. 1042change.authoredagent:claude-code · 7f3a21c88d0…41aa
  3. 1043change.reviewedactor:b204 · PR 318 approved1b7e…c6d3
  4. 1044test.evidencedci:run 5127 · 214 passede930…07f8
  5. 1045release.sealedv2.14.0 · RFC 3161 timestampf2a9…d114
chain verified · 1045 entries · offline verifierolobolo verify chain.jsonl →
We record our own build. See the chain, live →
Open-source verifier. Runs offline — you never have to trust us.
EU-hosted, EU-owned. Timestamps from an independent European TSA.
The question is coming

Your next audit will ask something
you can't answer today.

Git history shows what changed and who committed. It doesn't show which agent wrote it, from which instruction, or how it was verified. Three doors this question walks through:

"What share of your codebase is AI-generated, and how is it reviewed?"

Enterprise procurement · vendor assessment

"Document your development and QA trail for software placed on the EU market."

EU Product Liability (recast) · from Dec 2026

"We need the provenance of this codebase before we can price the deal."

Technical due diligence · M&A
How it works

Record. Chain. Report.

Passive by design — your team doesn't change how it works. OLOBOLO enriches the events that already happen in git, CI and your agent tooling.

Read the transcript
  • Five events. One tamper-evident chain.
  • It starts with an approved spec — the instruction is part of the record.
  • An AI agent writes the change. Authorship is recorded — not claimed.
  • A human reviews and approves. The decision lands in the chain.
  • Tests run. The results are chained to the exact change they prove.
  • The release is sealed — one fingerprint over the whole story.
  • Anyone can verify the chain offline — without trusting us.
  • OLOBOLO — the flight recorder for AI-built software.
01

Record at the source

A GitHub App plus a lightweight CLI hook capture authorship, agent identity, spec links, reviews and test runs the moment they happen.

change.authoredspec.linked
02

Chain the evidence

Every event becomes an entry in an append-only, hash-linked log. Nothing can be edited afterwards — corrections are new entries, on the record.

change.reviewedtest.evidenced
03

Seal and report

Each release closes its chain with a seal. One click turns it into a release report, a vendor profile or a due diligence package.

release.sealed
Data principles

We store proof. Never content.

OLOBOLO records fingerprints and metadata — hashes that prove your material existed, unchanged, at a point in time. The material itself stays where it belongs: with you.

Never stored
  • source code & diffs
  • prompt text
  • specification documents
  • review comments
  • test output & logs
How an auditor checks

To verify, an auditor hashes your local material and compares it with the chain — no trust in OLOBOLO required. The chain export is open format; verification needs nothing but a hash utility.

Audit-ready output

Reports written for the people who ask.

Procurement officers, auditors and deal teams don't read dashboards. They read documents — reproducible, exception-disclosing, independently verifiable.

  • Release evidence report — authorship, review coverage, test evidence, disclosed exceptions
  • Vendor profile — organisation-level answers for tenders and assessments
  • Due diligence package — codebase provenance for transactions
  • Mapped to EU Product Liability, AI Act and ISO/IEC context — evidence, not legal opinion
SEALED
Release evidence report · v2.14.0
AI-authored share31%
Review coverage100%
Test evidence95%
Disclosed exceptions2 · on record
Chain integrityVerified ⌗ 0d55…ee
Regulations & use cases

One evidence chain.
Many people asking for it.

The same recorded chain answers questions from regulators, customers, auditors and acquirers. You record once — and reuse the evidence wherever the question comes from.

EU Product Liability Directive (recast)

From Dec 2026

Software is now explicitly a "product". In a liability case, your development and quality-assurance trail becomes evidence — and courts can order disclosure of it.

OLOBOLO provides: a contemporaneous, tamper-evident record of how each release was built, reviewed and tested — recorded before any incident, not reconstructed after.

Read the guide →

EU AI Act

Phasing in now

Where AI systems or AI-assisted development are in scope, documentation of human oversight and development provenance is part of the compliance picture.

OLOBOLO provides: per-change attribution of agent vs. human authorship, and proof that agent output passed human review — the oversight trail, on the record.

Read the guide →

Cyber Resilience Act (CRA)

Main duties 2027

Products with digital elements sold in the EU will require technical documentation of secure development and ongoing vulnerability handling.

OLOBOLO provides: evidence that changes — including AI-authored ones — went through your defined review and test gates, release by release.

Read the guide →

NIS2 & DORA

In force

Supply-chain security duties (NIS2) and ICT risk management in finance (DORA) push documentation demands down onto software vendors — you, if you sell to those sectors.

OLOBOLO provides: vendor-profile answers about your development controls, backed by verifiable data instead of a questionnaire promise.

Read the guide →

ISO/IEC & SOC 2 audits

Recurring

Certification and attestation audits ask for evidence that your change-management and review controls actually operate — every period, every sample.

OLOBOLO provides: sampled chain entries as audit evidence: authorship, approval and test linkage per change, exportable for your auditor.

Read the guide →

Customer & tender requirements

Already here

Enterprise procurement and public tenders increasingly ask: "What share of your code is AI-generated, and how is it quality-assured?" A shrug loses the deal.

OLOBOLO provides: a standing vendor profile with verified numbers — AI share, review coverage, test evidence — ready before the question arrives.

Read the guide →
Beyond compliance — same chain, more doors
M&A due diligenceCodebase provenance as a deal document — AI share, controls and gaps, priced in with confidence instead of discounted for uncertainty.Read the guide →
Insurance & liability coverDemonstrable development controls when negotiating tech E&O and cyber policies for AI-assisted development.Read the guide →
Internal AI governanceBoard-level visibility: where agents write code, which tools and models, and whether your review policy holds in practice.Read the guide →
Agency & consultancy deliveriesHand clients an evidence report with every delivery — proof of process as part of the product.Read the guide →
Open source trustA public badge and chain for your project: contributors and users see how agent contributions are reviewed.Read the guide →
Incident forensicsWhen something breaks in production, trace the change to its spec, author, review and test evidence in minutes.Read the guide →

A necessary honesty: OLOBOLO is evidence, not a legal opinion. We attest to what was recorded — mapping notes show where the chain supports each framework, and your counsel decides what compliance requires. No tool can promise the latter; be wary of any that does.

The trust mark

Show it. Don't just file it.

Verified organisations get a mark for their website footer, decks and business plans. It always links to a live, public verification page — and it glows only while your chain verifies.

ACME Industries · Payments infrastructureSecurity · Terms · Privacy
In a customer footer — next to the copyright line, where trust marks live.
  • Always live, never static. The mark resolves to olobolo.com/v/your-org — verification status, latest sealed release and external anchor, generated from the chain. Report IDs in your business plan resolve to the same page.
  • Revocable — that's why it means something. If verification fails or recording stops, the mark turns neutral. A mark that cannot be lost proves nothing.
  • Evidence, not compliance. The wording is contractual: it says what was recorded, and it may never be upgraded into approval claims no tool can make.
  • Free for open source — public projects carry the mark and the public chain at no cost.

You're looking at one right now — see ours in the footer below ↓

Pricing

Start free. Pay when it matters.

Evidence has to be recorded before it's needed — it can't be reconstructed afterwards. That's why starting is free, private repositories included. When the question arrives, your chain already exists — upgrading unlocks the reports on the history you've been recording all along.

Record — free

€0 forever
  • Unlimited public repositories
  • Up to 3 private repositories
  • Full evidence chain — recorded completely, never truncated
  • Chain export, verifier & badge — always free
  • Dashboard: last 90 days
Start recording

Team

€79 / month per team
or €790/year — two months free
  • Unlimited private repositories
  • Full dashboard history
  • Release evidence reports
  • PR checks & API
Start 30-day trial

Compliance

€490 / month per organisation
or €4,900/year — two months free
  • Everything in Team
  • Vendor profiles & regulatory mapping
  • Due diligence packages
  • Priority support & onboarding
Talk to us

The question is coming. The evidence starts now.

You can't reconstruct a chain you never recorded. Install today, and every change from this moment is on the record.

Install GitHub App