Evidence

Source-free evidence reviewers can inspect before your first upload.

Faultline evidence is designed to answer governance questions without requiring source upload: what was scanned, which repos need review, what changed, who received the digest, and what export can be verified.

sample evidence pack

Sanitized. Downloadable. Source-free.

Review the example receipt, governance map, weekly digest, and audit export before connecting real repos.

Proof

See the evidence chain before you start a trial.

A qualified visitor should not have to imagine the product. This is the first-value path Faultline is built to produce: local scan, source-free receipt, governance map, weekly digest, and signed evidence.

local scanner commandsource stays local
faultline scan ./...
  --format snapshot
  --out faultline.snapshot.json
  --enterprise-url https://api.gofaultline.dev
  --enterprise-org-id ce28dedc-be2e-410a-b65d-4b51be891f47

Source-free snapshot receipt

The scanner emits metadata that Enterprise can govern without receiving source code.

accepted
repos
5
packages
148
findings
37
source uploaded
no

Governance map

One view shows the repos that need ownership, suppression, policy, or evidence review before risk is accepted again.

2 high-risk repos
RepoRiskOwner gapsSuppressionsPolicyEvidence
payments-apiHigh32 expiringdriftneeds export
identity-gatewayMedium2currentCODEOWNERS staledigest queued
billing-workerHigh14 stalereview requiredowner review
audit-exporterLow0nonecurrentsigned
weekly governance digestverified recipients
Risk changespayments-api +8.3 points since last scan
Owner gapsidentity-gateway, billing-worker, data-loader
Suppressions14 expire within 30 days
Policy driftplatform/base-go drift in 3 repos
Evidenceaudit-exporter export signed and downloadable

Signed audit export

Exportable records let leadership, customers, and compliance reviewers inspect what changed and verify the bytes they received.

verified
generated
2026-05-05T20:26:45Z
records
26
digest
sha256: verified
signature
current
includes
snapshots, tokens, policy events, exports

This is the conversion point: if the first few repos reveal real gaps, the rollout question changes from "what is Faultline?" to "why is this not watching every production Go repo?"

Identify Orphaned Findings

Evidence boundary

The evidence model is intentionally metadata-first.

The point is not to become another source repository. The point is to preserve the governance facts a reviewer needs.

Included in the sample evidence model

  • Snapshot receipts with repository, package, finding, and signal counts
  • Repo-level governance maps with ownership, suppression, policy, and evidence status
  • Weekly digest summaries for verified governance recipients
  • Audit export records with timestamped actions and digest verification notes
  • Source-free metadata proving what was reviewed and when

Not included by default

  • Source code
  • Full ASTs or compiled artifacts
  • Runtime traces or production logs
  • Developer workstation contents
  • Private incident notes unless explicitly supplied by the customer

Reviewer questions

Each artifact answers a different stakeholder question.

VP Engineering

Which Go repos are risky, who owns them, and what changed since the last review?

Platform Engineering

What work should we route: owner gaps, stale suppressions, policy drift, or dependency health?

Security / Compliance

Can we inspect evidence without granting source access to another vendor?

Customer Diligence

Can we provide timestamped, exportable records that show governance activity?

Find the continuity gaps your current tooling cannot prove away.

You may have findings, scanners, and tickets. Under scrutiny, that still may not prove governance continuity.