Local-first AI code provenance: line-level attribution, PR risk reports, policy checks, and tamper-evident audit trails for AI-assisted software.