Gradle Technologies is now Develocity — read the announcement

On-Demand Auditing

Compliance answers from signed facts, on demand.

Provenance Governor package view showing gate topology, dependency compliance score, and vulnerability deductions.

Feature overview

On-Demand Auditing

Ask any question about an artifact's compliance and get an answer from signed facts immediately. Which dependencies does this artifact carry? Did it pass every gate? When was it last evaluated? Answers trace to signed records at every gate, not logs or scanners. Fact Connectors and Fact Evaluators extend answers beyond the build to include deployment events, IT Service Management (ITSM) tickets, and live vulnerability status. Your policies define what compliance means. The EU Cyber Resilience Act and US Executive Order 14028 require per-package supply chain answers.

Answer any supply chain question on demand

  • Trace any artifact's compliance from its signed facts.
  • Each answer is grounded in signed attestations recorded at every gate.
  • Reconstruct what was known at decision time, including the policy evaluation and recommended action.
Learn how policies are evaluated (opens in new tab)
Gate topology showing an artifact's journey through build, staging, and production with pass-fail status and cycle time.

Confident answers from the full delivery lifecycle

  • Audit answers include deployment events, ITSM tickets, and CD pipeline signals fed through Fact Connectors.
  • Answers reflect live data from vulnerability databases, approval workflows, and change management systems, not just build-time snapshots.
  • Answers span signed facts from the full delivery lifecycle.
Set up CI/CD integration (opens in new tab)
Fact Connectors and Fact Evaluators contributing external data to the Governance Record as signed facts.
Governance

Compliance answers an auditor can verify

  • Answers resolve to signed attestation records an auditor can trace to the original gate evaluation.
  • Your policies decide each answer, so the rules you write are the rules enforced at every gate.
  • Meet EU Cyber Resilience Act and US Executive Order 14028 requirements with per-package supply chain answers.
View the verification summary format (opens in new tab)
On-demand audit showing gate results, compliance summary, and recommended action for a Maven artifact.
Agent Context

AI agents act on verified compliance context

  • Investigate compliance risk and triage vulnerabilities across dependencies, toolchains, and build tools.
  • Get accurate remediation recommendations through progressive disclosure, with upgrades defaulting to patch-level and tunable per package pattern.
  • Limit each actor to only the artifacts and gates they need through fine-grained authorization.
  • RoadmapTrace a vulnerability's blast radius across the organization to identify every affected artifact and gate.
View the MCP tools (opens in new tab)
Agentic audit session showing investigation, triage, authorization patterns, and roadmap blast radius analysis.

Resources

Supply Chain Observability with Develocity Provenance Governor
Blog

What's next

Get started today with a 30-day free trial of the entire Develocity product suite.

Start Free Trial

© 2026 Gradle, Inc. Gradle®, Develocity®, Build Scan®, and the Gradlephant logo are registered trademarks of Gradle, Inc.

Get an AI summary of Develocity: