Skip to main content
Reference — generated from the toolkit

Source of truth: toolkit/templates/release-evidence-pack.md. Edit it there; this page is regenerated on build.

Release evidence pack — {product} {version}

  • Product / version:Release date: {YYYY-MM-DD} Assembled by: pipeline

Contents

ItemSourceStatus
SBOM (CycloneDX)buildauto
Gate results (merge + production readiness)CI/CDauto
Test coverage + mutation summaryCIauto
Threat-model referenceDesignlink
DPIA statuscompliance packlink
Human authorisations (deploy, migrations)provenance trailauto
Provenance summary (agent/model/prompt per change)provenance trailauto

How it's used

Handed to a client's procurement / vendor-risk team on request, or to an auditor. Because it assembles automatically from the AI provenance trail and the security gates, it's always complete and costs nothing per release.