| Primary focus | Dependencies, builds, provenance, SBOMs | Application-security posture | Evidence for release decisions |
| Core question | Is the software build and its components trustworthy? | What is our application risk posture? | Does evidence satisfy policy? |
| Input | Package manifests, build logs, signatures, SBOMs | Scanner, cloud, runtime, agent signals | Qualified evidence from existing tools |
| Output | SBOMs, attestations, dependency risk lists | Prioritized findings and posture score | Proceed, Stop, Escalate, Require authorization |
| Evidence model | Provenance, attestation, reproducibility | Correlation, context, risk rank | Corroboration, freshness, policy version |
| Remediation proof | Updated dependency, signed build | State tracked in posture | Validated fixes, not just ticket closure |