One policy, everywhere code changes
A scanner gives you a list of matches and leaves the follow-up to you. Earnie connects each finding to a decision and keeps the evidence for it. The same policy applies in three places:
A licence rule that blocks a pull request is the same rule a coding agent receives while it writes code, and the same rule an auditor sees in the project’s history.
Earnie covers three domains in one list of findings: open source, cryptography, and AI provenance. Which ones you see depends on what your organisation has enabled.
Key terms
A project is scanned. The scan produces findings. Earnie checks each finding against your policies, and the result is a verdict.How a scan becomes a verdict
- Earnie fingerprints each file. A fingerprint identifies the content without being a copy of it.
- SCANOSS matches the fingerprints against its knowledge base of open-source code.
- Earnie adds licence, vulnerability, and provenance data to each match. Each enriched match is a finding.
- Earnie checks each finding against your policies.
- The policies produce the verdict.
Other terms
Who uses what
- Security and compliance leads (AppSec, platform security, OSPO) use the web app to triage findings, write policies, read posture, and manage the team.
- Developers and coding agents mostly never open the web app. They get policy context and Self-checks through the CLI, hooks, and MCP, and results on their pull requests.
- People who need the records, such as CISOs, legal counsel, and AI risk owners, use what Earnie exports: SBOMs, notice files, and the audit log.
Earnie doesn’t send your source code to SCANOSS. It sends file fingerprints, each with the file’s
checksum, size, and path, plus the package identifiers of components it found. See
Deployment & data flow for exactly what leaves your environment.
Where to go next
The sidebar follows the same three places. If you’re setting Earnie up, start with Workspace setup. If you’re a developer, go to Development and Pull requests & CI. If you’re moving off scanoss-py, the SCANOSS GitHub Action, or the SCANOSS pre-commit hook, read Migrating from SCANOSS tools.Coding agents (MCP)
Connect Claude Code, Cursor, VS Code, or Codex, and use Earnie’s tools from the agent.
Earnie CLI
Scan from the command line, install the pre-commit hook, and run Earnie in CI.
Merge gate
What Earnie posts on a pull request, and what to do when a policy blocks a merge.
Triaging findings
Work through the backlog and record a decision on each finding.
Setting policies
Turn a decision you keep making by hand into a rule.
Using the API
Call Earnie’s REST API with an API key.