| Model artifacts in the release |
Files observed in the build: format, hash, size and how strongly the format was identifiedIdentified from bytes and written to the AI evidence record on every analyze and audit run |
Available today |
| Model & external-service inventory |
Declared models, deployment aliases and external AI services, reconciled against what was observedYou supply the declaration; the run shows where it disagrees with the observation and never resolves the disagreement for you. A run given no declaration says that nothing was compared |
Available today |
| Datasets & provenance |
Dataset identity, provenance, licences, transformations, declared limitations |
Available today |
| Prompts & prompt bundles |
Prompt artifacts where they are genuine release artifacts, hashed and versioned |
Available today |
| Agents, tools & MCP dependencies |
Agents, tools, services and MCP servers observed in the release treeSBOMFlow finds the agents, tools, services and MCP servers a release declares in its configuration and dependencies, and says what it could not see. A declared permission is a supplier claim, never a verified fact. When what you declared and what was found differ, you see both — the tool never decides which is right, and none of it reaches a gate. How the record is kept → |
Available today |
| Frameworks, runtimes & supporting software |
The conventional software around the models — already first-class composition evidence |
Available today |
| Evaluation & test evidence |
Evaluation results, thresholds and human acceptance recorded as evidence, never as verdictsEvaluation records already in the release tree are read on every run and recorded exactly as supplied. SBOMFlow read an account of an evaluation rather than watching one happen, and the record says so |
Available today |
| AI-specific release drift |
Model and AI-evidence changes between releasesAI changes ride the same drift engine as everything else, and “nothing changed” is reported separately from “nothing was compared” |
Available today |
| Human review & AI-aware gates |
The live review queue, approvals and explainable gates extended with AI-aware policiesOpt-in policy controls, off by default: every AI control stays informational until an operator enforces it, an enforced control that could not run blocks with its reason instead of passing, and the reviewer console carries an AI evidence section |
Available today |
| Standards-based AI/ML BOM output |
Linked software SBOM plus CycloneDX ML-BOM and SPDX 3.0.1 AI profile outputOpt-in exports built from the same AI evidence record, linking to the SBOM instead of copying it |
Available today |
| Redacted AI evidence sharing |
A verifiable, redaction-audited AI evidence pack, following today’s passport pattern |
Available today |