Falden

FLD-0001

Which agent wrote this change, and who approved it?

Most regulated firms have written down that agent-written code gets independent human review. Almost none can produce the record.

The tooling is getting worse, not better

Under Anthropic’s Zero Data Retention, and on Bedrock, Google Cloud Agent Platform and Microsoft Foundry, your AI vendor cannot tell you which changes an agent wrote. Contribution metrics are unavailable, the compliance API returns nothing for sessions, and developer identity collapses to an anonymous identifier stored in a local file.

That is the standard deployment shape in regulated finance. It is vendor policy, not a gap a product release closes.

And you cannot infer it from outside

Public corpus counts. Numerals are observations, not any firm’s disclosure rate.
Merged pull requests 6,869
Public repositories 332
Regulated fintechs 15
Attribution-signal range 0%–41%

That is a corpus observation, not any firm’s disclosure rate. Public GitHub organisations are not internal software development. What the range shows is that disclosure is a policy choice, and that nothing about a firm’s actual agent usage can be read from the outside.

Nine in ten developers report using AI at work. Fewer than three in ten merged pull requests say so.

The Agent Change Control Assessment

A read-only app on one organisation. Ninety days back. Every merged change in the window, not a sample.

Mapped to DORA Article 9(4)(e) and RTS (EU) 2024/1774 Article 17(1)(b).

Six to eight weeks.

What you keep

A sealed evidence pack. PDF, machine-readable JSON, and a hash chain.

Your auditor verifies the seal with a standalone binary, without contacting us.

We supply the record. Your auditor signs it. We are not the attestor, and we will not design the control we assess.

Contents of the sealed evidence pack.
PDF document
JSON machine-readable
Hash chain sequential
Attestor
Written Falden agent
Approved Alexander Theruviparambil

HMAC-SHA256 · FLD-0001

Who this is for

Compliance engineering, DevSecOps and technology risk at firms where agents are already writing merged code and someone has to answer for it.

Request an assessment