Key Capabilities
Supply Chain Security
Identify AI models, frameworks, SDKs, APIs and dependencies used throughout your software ecosystem to improve visibility and reduce supply chain risk.AI Compliance and Governance
Generate AI-focused SBOMs and compliance reports to support regulatory frameworks such as the EU AI Act and internal governance policies.Risk Assessment and Provenance Analysis
Detect AI service integrations, exposed model endpoints, API keys, model origins and usage patterns to support security reviews and risk management.Features
SDK Detection (12 languages)
AI Package Detection (150+ packages)
Comprehensive detection across categories:Model File Detection (12 formats)
GGUF, SafeTensors, ONNX, PyTorch, TensorFlow, TFLite, CoreML, JAX, Keras, MXNet, PaddlePaddle, PickleManifest Parsing (11 formats)
requirements.txt, pyproject.toml, package.json, go.mod, Cargo.toml, pom.xml, build.gradle, Gemfile, composer.json, *.csproj, Package.swiftOutput Formats
- JSON - Machine-readable findings
- CycloneDX 1.6 - OWASP SBOM format with ML-BOM support
- SPDX 2.3 - Linux Foundation SBOM format
- SPDX 3.0 - Latest SPDX specification with JSON-LD
SBOM Compliance
Generated SBOMs are compliant with major standards:License Handling
- Licenses are automatically enriched from PyPI, npm, and HuggingFace
- Unknown licenses are marked as
NOASSERTIONper SPDX specification - Supports SPDX license expressions