Skip to main content
Earnie scans your code and finds the open-source components, licences, vulnerabilities, cryptography, and AI models in it. It checks each result against rules your team writes and records every decision, so months later you can show why a component was accepted or rejected. This page covers Earnie’s model, the terms the rest of the guide uses, and where to go next. You don’t need to set anything up yet.

One policy, everywhere code changes

A scanner gives you a list of matches and leaves the follow-up to you. Earnie connects each finding to a decision and keeps the evidence for it. The same policy applies in three places: A licence rule that blocks a pull request is the same rule a coding agent receives while it writes code, and the same rule an auditor sees in the project’s history. Earnie covers three domains in one list of findings: open source, cryptography, and AI provenance. Which ones you see depends on what your organisation has enabled.

Key terms

A project is scanned. The scan produces findings. Earnie checks each finding against your policies, and the result is a verdict.

How a scan becomes a verdict

  1. Earnie fingerprints each file. A fingerprint identifies the content without being a copy of it.
  2. SCANOSS matches the fingerprints against its knowledge base of open-source code.
  3. Earnie adds licence, vulnerability, and provenance data to each match. Each enriched match is a finding.
  4. Earnie checks each finding against your policies.
  5. The policies produce the verdict.

Other terms

Who uses what

  • Security and compliance leads (AppSec, platform security, OSPO) use the web app to triage findings, write policies, read posture, and manage the team.
  • Developers and coding agents mostly never open the web app. They get policy context and Self-checks through the CLI, hooks, and MCP, and results on their pull requests.
  • People who need the records, such as CISOs, legal counsel, and AI risk owners, use what Earnie exports: SBOMs, notice files, and the audit log.
Inside the web app, what someone can do depends on their role: Admin, Operator, or Viewer. See Team & roles.
Earnie doesn’t send your source code to SCANOSS. It sends file fingerprints, each with the file’s checksum, size, and path, plus the package identifiers of components it found. See Deployment & data flow for exactly what leaves your environment.

Where to go next

The sidebar follows the same three places. If you’re setting Earnie up, start with Workspace setup. If you’re a developer, go to Development and Pull requests & CI. If you’re moving off scanoss-py, the SCANOSS GitHub Action, or the SCANOSS pre-commit hook, read Migrating from SCANOSS tools.

Coding agents (MCP)

Connect Claude Code, Cursor, VS Code, or Codex, and use Earnie’s tools from the agent.

Earnie CLI

Scan from the command line, install the pre-commit hook, and run Earnie in CI.

Merge gate

What Earnie posts on a pull request, and what to do when a policy blocks a merge.

Triaging findings

Work through the backlog and record a decision on each finding.

Setting policies

Turn a decision you keep making by hand into a rule.

Using the API

Call Earnie’s REST API with an API key.