---
title: "Build provenance (SLSA)"
description: "A verifiable record, in the SLSA format, of what built an artefact, by what process and from which top-level inputs."
canonical: https://aigovernanceengineer.com/glossary/build-provenance-slsa
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Build provenance (SLSA)

A verifiable record, in the SLSA format, of what built an artefact, by what process and from which top-level inputs. Its build levels run from L1, provenance exists, through L2, signed by a hosted build platform, to L3, hardened builds whose provenance is very hard to forge [1]. For a model, inputs include the base model's digest and dataset admission records.

- Developed in: [ch. 05, Pattern: Model Artefact Integrity](https://aigovernanceengineer.com/patterns/model-artefact-integrity)
- Chapters: [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns)
- Contrast with: [Model signing](https://aigovernanceengineer.com/glossary/model-signing)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-build-provenance-slsa

## Sources

[1] SLSA specification v1.2, Build track basics (provenance: what built the artefact, by what process and from which top-level inputs; Build L1 provenance exists, L2 hosted build platform, L3 hardened builds). OpenSSF SLSA project. n.d. (accessed 2026-09-25). https://slsa.dev/spec/v1.2/build-track-basics (verified: primary)
