Register 09 · Compliance controls

SLSA v1.0.

SLSA v1.0 is a provenance standard: it cares about where an artifact came from and whether the chain is unbroken. Planisphere's evidence record can preserve sha-pinned, Merkle-rooted provenance in the format SLSA v1.0 expects for review.

register 09 · Compliance controls· Supply-chain / provenance standard

Reviewed 2026-07-08

01 ·

What this is.

Seventy-two regulatory cite-anchors, organized for evidence lookup and review

Use. supply-chain levels for software artifacts.

Register. 09 · Compliance controls — one of the 17 registers of the PLANiSPHERE corpus library.

02 ·

See it work.

Evidence record you can check — not code you have to trust.

Planisphere measures your tool deployment against SLSA v1.0 and seals the result into a signed, Merkle-rooted evidence record. The grade recomputes on your own hardware; the model state never crosses the boundary.

03 ·

Promise. compliance

The contract this mark binds — derived, not asserted.

SLSA v1.0 is a provenance standard: it cares about where an artifact came from and whether the chain is unbroken. Planisphere's evidence record can preserve sha-pinned, Merkle-rooted provenance in the format SLSA v1.0 expects for review.

Answers: How does a Planisphere evidence record support SLSA v1.0 review?

04 ·

Where this provenance chain ships.

Related marks, and the surface this one funnels to.

SLSA v1.0 (supply-chain levels for software artifacts) asks for an evidence record: SLSA v1.0 is a provenance standard: it cares about where an artifact came from and whether the chain is unbroken. Read the related defense AI workflow product context at /defense.

C-SCRM reg 09 · supply-chain risk · NIST SP 800-161r1 FIPS 140-3 reg 09 · crypto module validation · 4 security levels SBOM reg 09 · software bill of materials · NTIA + CISA SCITT reg 09 · supply-chain integrity, transparency, trust · IETF SHA-256 / FIPS 180-4 reg 09 · hash algorithm · per-file pinning primitive
05 ·

Routes here from.

Where this mark is referenced in the Planisphere surface.

Any internal link in the Planisphere site that names "SLSA v1.0" canonicalises here.

See the record SLSA v1.0 asks for.

The console shows the evidence; the docs show the endpoints; the briefing shows what the product does and does not claim.

API ·

When SLSA v1.0 asks for proof, hand over records — not assurances.

record the duty · seal the receipt · verify offline

Planisphere records each duty event — an output marked, a disclosure shown, a review made — and seals it into a receipt that verifies offline against our published keys. You send hashes, never content. A record is evidence a third party can check; it is not a certification and not a legal determination.

See how a record is checked