Pages
Policy Config — Provenance Pinning
Source: c65 policy-definitions.md P14 — list-editor shape
‹ Policy Catalog
Provenance Pinning
RoadmapModels and tools must match pinned, verified sources. Pin at load — sourcing is build-time, so this is honest-partial coverage, never full.
Input & Output Integrity
medium
P14Satisfies
OWASP LLM
ISO 42001
EU AI Act
Underlying control— show
run: model pinned-source verdictedit as custom control →Pinned sources
3 entries · patterns supported (* and ?)
| Source | Added by | Last matched | |
|---|---|---|---|
| anthropic/claude-fable-5 | mark | 3m ago | |
| anthropic/claude-sonnet-5 | mark | 22m ago | |
| anthropic/claude-haiku-4-5@*any point release | seed | 1h ago | |
| you |
Exceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| No exceptions — the policy applies everywhere. | ||||
Remediation shown on findings: Re-pin to the verified source, or approve the new source explicitly.