Skip to main content

Key Capabilities

Supply Chain Security

Identify AI models, frameworks, SDKs, APIs and dependencies used throughout your software ecosystem to improve visibility and reduce supply chain risk.

AI Compliance and Governance

Generate AI-focused SBOMs and compliance reports to support regulatory frameworks such as the EU AI Act and internal governance policies.

Risk Assessment and Provenance Analysis

Detect AI service integrations, exposed model endpoints, API keys, model origins and usage patterns to support security reviews and risk management.

Features

SDK Detection (12 languages)

AI Package Detection (150+ packages)

Comprehensive detection across categories:

Model File Detection (12 formats)

GGUF, SafeTensors, ONNX, PyTorch, TensorFlow, TFLite, CoreML, JAX, Keras, MXNet, PaddlePaddle, Pickle

Manifest Parsing (11 formats)

requirements.txt, pyproject.toml, package.json, go.mod, Cargo.toml, pom.xml, build.gradle, Gemfile, composer.json, *.csproj, Package.swift

Output Formats

  • JSON - Machine-readable findings
  • CycloneDX 1.6 - OWASP SBOM format with ML-BOM support
  • SPDX 2.3 - Linux Foundation SBOM format
  • SPDX 3.0 - Latest SPDX specification with JSON-LD

SBOM Compliance

Generated SBOMs are compliant with major standards:

License Handling

  • Licenses are automatically enriched from PyPI, npm, and HuggingFace
  • Unknown licenses are marked as NOASSERTION per SPDX specification
  • Supports SPDX license expressions