The document describes SECProv, a system for securely managing provenance data in untrusted clouds. It presents a generic provenance model called CloProv and identifies attacks from dishonest cloud providers and users. SECProv addresses these by constructing provenance chains using hash chains and aggregate signatures, and publishing system provenance proofs. It was implemented on OpenStack Swift for efficiency evaluations, showing overhead of only 2% compared to 5.7% for prior work. SECProv provides integrity and privacy for provenance records in untrusted clouds.