EVIDENT

For developers

Governance you can fail a build on

Compliance findings usually reach engineering months late, as a PDF, describing a system that has since changed. This is the version that arrives as an exit code.

Where this is today

This page describes a command line and a set of gates. Part of it you can use this afternoon and part of it is specified and not built, so here is which is which before you read the rest.

  • AvailableThe HTTP API. Everything the interface does is a call you can make yourself, documented through OpenAPI.
  • AvailableAnalysis, correlation, reports and exports. Built and running. Everything below rests on them.
  • AvailableFindings that name a file, a table and a column. True of every finding the product produces today.
  • AvailableThe route from a finding back to its evidence. GET /evidence/path returns what was read and from where, what was concluded and by which rule at what confidence, and who decided what.
  • AvailableA map and one tool for an agent. /llms.txt says what this product is and where every page is, in both languages, and every page registers one WebMCP tool that asks a person here to get in touch.
  • AvailableComparison against a previous run. Subject by subject, in six states: new, unchanged, changed, resolved, came back, and needs another look. Read from the evidence record, which is written per run, so the answer survives a restart. GET /change/diff returns the same thing the screen shows.
  • AvailableWhy a person is needed, and why an old decision still holds. Every unresolved field carries one reason from a short vocabulary, ordered by how much judgement it takes. A field somebody decided, whose material context has not moved, is absent from the queue — which is the part that matters. GET /change/why-me and GET /change/why-still.
  • PreviewRemediation, verified by a later analysis. A person records a corrective action and claims the change is made; a later analysis re-reads the system and writes verified, still there, or came back. The API refuses to let anybody write verified by hand. Reachable over HTTP; the screens for it are next.
  • PlannedThe evident command line. Specified down to the exit codes below, and built as a distinct piece of work.
  • PlannedGovernance gates in a pipeline. They depend on the command line above and arrive with it.
  • AvailableA public demonstration, with no account. A disposable Nébula Shop session, isolated per visitor, that resets to a known seed and expires on its own. Twenty minutes, no account, no card, and the copy is deleted when the session ends. The evidence engine behind it is the one described above.

Available is in the product today. Preview is built and reachable, and still changing shape. Planned is specified and not built — published in advance so it can be judged before it exists.

The reason governance drifts is not that engineers ignore it. It is that the feedback loop is measured in quarters, arrives in prose, and points at a schema that moved three sprints ago.

Everything EVIDENT knows is available without opening the interface.

The command

evident scan --connection-env EVIDENT_DATABASE_URL \
              --framework gdpr \
              --output ./evidence

exit 0   the gate passed
exit 2   the governance gate failed
exit 3   configuration or assessment error

What the command line gives you

  • A stable JSON schema and stable exit codes, so a pipeline can depend on them across upgrades.
  • Ruleset and regulatory framework pinning, so a rule change cannot silently alter what your build considers acceptable.
  • Baseline comparison against a previous snapshot: fail on what is new, not on what you already accepted.
  • Evidence coverage thresholds, so a pull request that removes the evidence for a control is caught like any other regression.
  • Machine-readable evidence references, so a finding can be resolved to a file, a table and a column without a human reading a document.
  • Secrets excluded from output, always — an artefact a pipeline uploads must be safe to upload.

Findings that point at a line, not at a chapter

A finding names the column, the entity in code that maps to it, and the rule version that produced it. Nobody has to read a hundred-page audit report to work out which field is being talked about.

Where the finding is about a log, it names the call. Where it is about an API, it names the operation and, if the risk comes from reachability, the exact path through the type graph that gets there.