Signed proof of who approved what.
UPDATED · AUGUST 2026
Nothing new to install: it's the same linebreak-gate already running in your CI, unlocked with a license key. Once unlocked, every gated approval is issued as an Ed25519 signature by the governance service: over the approver, their role, and the exact content hash of what they approved. The record is filed in git next to the code it governs, and the gate verifies the signature offline on every run, from a bare clone, with no call to us.
How it works
- 1 · A human approves: Someone with the right role approves a gated phase: the spec, the architecture, the release.
- 2 · The service signs: The governance service issues the Ed25519 signature. Clients can't author or forge one; self-approvals are disclosed inside the signed payload.
- 3 · Git files it: The signed record lands in your repo next to the code: a folder, not a dashboard.
- 4 · The gate verifies, forever: On every CI run, linebreak-gate checks the signature offline. Content edited after approval? Tamper-evident, fail-closed.
It's the change-management evidence a SOC 2 or ISO 27001 audit asks for, produced as a byproduct of working, not a pre-audit scramble.
Selling development to US clients? When their security questionnaire asks how you control AI-written code, answer with a signed record in the deliverable itself, not a slide deck.
How do you get a license key? Buy Pro on the pricing page and your key arrives by email within seconds, ready to paste into CI. Founding-cohort teams also get white-glove onboarding:
Get Pro: from $99/mo Talk to us about attestationsNew to the practice? Read: what is governed AI development →
phase: architecture sha256: 9f2c…e41a approved: eng-lead@acme.com (architect) self_approved: false signature: ed25519:Kq3v…9dHw ✓ verified offline