In conjunction with

Developer security posture management built on deterministic code provenance

Archipelo is a San Francisco-based company building the system of record for how modern software actually gets made. As software production shifts to a multi-actor model where human developers, AI copilots and autonomous agents all write and change code, Archipelo establishes execution provenance so organizations know deterministically who or what produced every change, rather than reconstructing responsibility after the fact from logs and telemetry.

The platform is powered by Salmon, an execution provenance protocol that records and verifies every event of software production, from code changes and AI interactions to agent actions and pipeline executions. On top of this canonical record, Archipelo delivers developer security posture management capabilities including developer vulnerability attribution that links CVE findings to the responsible developer or agent, an AI and agent actions monitor, a centralized developer tool inventory, and developer-centric risk visibility for governance teams.

Archipelo's differentiator is the shift from inference to deterministic attribution. Where traditional AppSec tooling scans artifacts and guesses at root cause, Archipelo captures provenance at the moment of execution, giving security, engineering and compliance leaders a verifiable chain of custody for their code. That foundation becomes increasingly critical as enterprises adopt AI-driven development and need to govern the security posture of both their people and their machine collaborators.

Market Segment:

Application Security

Categories:

Developer Security Posture ManagementSoftware Supply Chain Security