ML supply chain integrity + tamper-evident audit trails. Yoruba: otito = truth
# OtitoChain
> *(Yoruba: otito = truth)* ML supply chain integrity and tamper-evident audit trails on AWS.
**Production** · BAMG Studio
---
## What It Does
OtitoChain instruments the ML model lifecycle — training data, model weights, dependency graphs, and deployment artifacts — with cryptographic integrity checks and SBOM generation. Every artifact in the pipeline has a verifiable chain of custody before it reaches production.
## Key Metrics
| Metric | Value |
|---|---|
| Vulnerability classes blocked pre-deployment | 200+ |
| Deployment speed improvement | 75% faster |
| False-positive rate on supply chain alerts | <2% |
## Architecture
```
CI/CD Pipeline → OtitoChain agent → SBOM generation (CycloneDX/SPDX)
→ Dependency graph scan → SHA-256 artifact signing
→ AWS KMS key management → OPA policy gate
→ Tamper-evident audit log (immutable S3 + CloudTrail)
```
**Stack:** `Python` `AWS` `KMS` `OPA` `SHA-256` `CycloneDX` `GitHub Actions`
## Problem Statement
Nigerian fintech and government ML deployments have no standardized supply chain integrity tooling. A model trained on tampered data, or a dependency with a malicious patch, reaches production undetected. OtitoChain applies SLSA Level 3 principles to the African ML deployment context.
---
**BAMG Studio** · Precision-built on the continent ·
github.com