Starter
Scoped after discovery
Direct product use for one organization with repeatable scanning, exports, and evidence.
Add selected Workbench capabilities through bounded OEM and partner integrations
AI Security Workbench · Graph-Backed AI Code Analysis
Graph-backed AI code analysis for RAG, agents, MCP, browser automation, model integrations, and tool-calling applications. Correlate source, sink, data, tool, permission, and missing-control signals into reviewable code-risk paths, structured findings, validation plans, SARIF, and remediation evidence.
AI-specific code analysis
Analyze AI application patterns, trust boundaries, orchestration, tools, retrieval, model use, and consequential sinks.
Static signals correlated into code-risk paths
Connect sources, transformations, model decisions, tools, permissions, guards, sinks, and affected actions without calling every relationship an attack path.
MCP / RAG / agents
Analyze LLM applications, RAG pipelines, browser agents, coding agents, MCP servers, model gateways, and tool-calling workflows.
SARIF / VS Code / Jira
Return diagnostics, tickets, structured findings, validation requirements, and remediation evidence through developer workflows.
Review-ready evidence
Support buyer review, marketplace preparation, partner assessment, and disclosure triage without claiming approval, certification, or official vulnerability status.
AI Security Workbench · AI-Specific Code Analysis
Code Scanner
Code-risk-path correlation
Static signals correlated into source → sink → missing-guard paths.
Path and evidence context
Validation evidence for app review, pre-submission, and buyer security review.
CVE candidate triage
Rank likely research candidates without overstating exploitability.
Developer exports
SARIF, VS Code diagnostics, Jira tickets, Markdown, and control matrices.
Graph-backed AI code analysis
Static signals grouped into source → sink → missing-guard paths
Marketplace readiness
Evidence for app review, buyer review, and submission blockers
CVE candidate triage
Rank likely research candidates without overclaiming
SARIF / VS Code / Jira
Developer exports and remediation queues
Core capabilities
Identify AI application patterns, model providers, retrieval systems, agent frameworks, MCP servers, browser components, tool-calling workflows, output sinks, and supply-chain surfaces.
Identify untrusted inputs, retrieved content, model-controlled values, privileged instructions, tool arguments, external actions, sensitive outputs, and consequence-bearing sinks.
Connect entry points, sources, transformations, model decisions, tools, permissions, controls, sinks, and affected actions.
Group related static evidence into reviewable routes through the implementation. Preserve uncertainty and do not present static routes as validated attack paths.
Separate raw signals, supported findings, control gaps, test noise, and deeper validation candidates.
Generate bounded plans for confirming reachability, preconditions, authorization state, tool behavior, output handling, and actual consequence.
Export structured findings, code references, relationship context, remediation, validation requirements, and claim state.
Evidence & signals
Risk Classes
Outputs
Evidence Levels
Red team + Blue team
Red Team Use
Blue Team Use
AI application risk emerges across prompt construction, retrieval, identities, permissions, agents, tools, configuration, dependencies, output sinks, and downstream actions. Code Scanner connects those implementation relationships into reviewable findings and code-risk paths.
The scanner evaluates AI-specific code and workflow surfaces that conventional AppSec categories do not fully describe.
Matrix showing scanner coverage across prompts, retrieval, agents, tools, MCP, authority, evidence, and lifecycle stages.
| Discovery | Analysis | Evidence | Retest | |
|---|---|---|---|---|
| Prompts and instructionsSystem prompts, templates, policy text, and instruction boundaries. | Covered | Covered | Covered | Covered |
| Retrieval and contextCorpus access, provenance, tenant boundaries, and prompt assembly. | Covered | Covered | Covered | Partial |
| Agents and orchestrationPlanning, delegation, memory, and workflow transitions. | Covered | Partial | Partial | Planned |
| Tools and MCPTool schemas, invocation boundaries, and consequence-bearing actions. | Covered | Covered | Covered | Partial |
| Identity and authorityUser, agent, service, and delegated permissions. | Covered | Partial | Partial | Planned |
| Evidence and lifecycleFinding state, provenance, remediation, and rescan behavior. | Not applicable | Covered | Covered | Covered |
This expands conventional code review without pretending every signal is a confirmed vulnerability. Candidates become findings only after the available code, configuration, data-flow, and control evidence supports the claim.
Risk classes
Code Scanner looks for the places where AI code creates delegated action, data exposure, unsafe rendering, policy bypass, or evidence gaps. The output is not a pile of isolated signals. It is a connected finding and validation workflow.
MCP tool side effects without approval
Browser-agent actions without domain or action policy
RAG/vector retrieval without tenant boundaries
Model-generated JSON controlling trusted actions
Prompt, log, trace, and cache exposure before redaction
Streaming model output rendered as unsafe HTML or markdown
AI gateway auth, budget, and model-policy gaps
Unsafe model artifact loading and unpinned supply-chain paths
Missing forensic evidence for AI actions
Outputs
The deliverable set is built for engineering, pre-submission validation, buyer security review, and disclosure triage when the evidence supports it.
AI Code Path Analysis Report
CVE Candidate Register
Safe Validation Plan
Harness Plan
Disclosure Case Draft
Developer Export & Remediation Evidence Pack
Pre-Submission Evidence Pack
Control Matrix
Jira Tickets
VS Code Diagnostics
SARIF
Attack Path Analysis handoff
Differentiation
Conventional SAST often emits isolated calls or patterns. Code Scanner connects model inputs, retrieved data, tool arguments, permissions, controls, sinks, and downstream actions into reviewable code-risk paths. Attack Path Analysis can then combine supported findings with system, authority, runtime, partner, and evidence context to determine whether a defensible multi-step attack path exists.
Generic SAST
dangerous calls
Code Scanner
AI-specific findings with connected source, sink, tool, permission, control, and action context
Generic SAST
raw findings
Code Scanner
supported findings and code-risk paths
Generic SAST
generic remediation
Code Scanner
relationship-aware remediation and validation requirements
Generic SAST
pass or fail
Code Scanner
claim state, validation state, engineering exports, and evidence context
Evidence levels stay explicit
Code Scanner distinguishes raw signals, supported findings, code-risk paths, fixture-validated behavior, runtime-supported findings, and disclosure candidates. A static relationship becomes an attack path only when the relevant reachability, preconditions, authority, consequence, and evidence support that claim.
CVE-likelihood scoring identifies candidates for private validation and pre-disclosure review. It does not constitute a CVE assignment, official vulnerability confirmation, or disclosure recommendation. Human review by a qualified practitioner is required before any submission to a CVE numbering authority or public disclosure program.
Pre-submission and review evidence
Use Code Scanner for pre-submission evidence packs, submission blocker reports, buyer security review artifacts, and remediation planning for AI-enabled apps, managed packages, partner apps, extensions, and integrations.
It supports pre-submission and validation workflows. It does not replace official Salesforce, Splunk, GitHub, AWS, partner, or marketplace security review.
A pattern match is a candidate. A useful finding connects the signal to affected code or configuration, explains the relevant trust boundary, records confidence and limitations, and identifies what should be verified next.
One scan can produce machine-readable findings, reviewable evidence, path inputs, and remediation-ready artifacts.
Layered scanner output stack from raw analysis evidence through structured findings, path inputs, remediation records, and reports.
The scanner should make uncertainty explicit. Unsupported candidates remain candidates; qualified findings carry enough provenance for engineering review, remediation, retest, and downstream evidence use.
Architecture
Code Scanner combines native AI security rules, source-context enrichment, code-risk-path correlation, validation planning, and evidence export. It can also ingest customer-owned scanner output when the customer has the right to use it.
Import support does not mean AI Security LLC bundles or resells third-party commercial tools or maintained rule sets.
Engine stages
Inputs it can consume
Commercial paths
Expert-led review for teams that need triage now. Repeatable scanning for ongoing use. OEM for scanner vendors who need the AI-specific detection layer.
Expert-Led Review
Scanner runs inside a Launch Security Review, red-team engagement, or product security assessment. Code risk turned into buyer-ready findings with human triage.
Scope an AI Security ReviewRepeatable Scanning
Recurring scanning across your organization. Developer exports, Jira backlog integration, SARIF, VS Code diagnostics, and safe validation plans.
View PricingScanner Providers · MSSP
Embed Code Scanner behind an existing scanner, AppSec product, CI workflow, or review process. Return structured findings, code-risk paths, evidence references, lifecycle state, and an optional handoff to Attack Path Analysis for cross-source correlation and path qualification.
Explore OEM licensingFindings should leave the scanner with stable identity, evidence, confidence, remediation context, and machine-readable structure so they can move into engineering, AppSec, partner products, reporting, and retest workflows.
AI-native analysis extends conventional code scanning by following prompts, retrieval, tools, agents, and authority through application logic.
Comparison of conventional application security analysis and AI-native analysis across code, prompt, retrieval, agent, tool, and authority relationships.
Structured output is the integration boundary. It allows teams and OEM partners to consume useful results without requiring access to internal prompts, detector implementation, rule catalogs, scoring logic, or proprietary engine internals.
OEM and scanner-provider packaging
The OEM Engine adds the AI layer. Packaged as a headless binary, localhost sidecar, private worker, or white-label module. Outputs in SARIF, JSON, Markdown, and evidence bundles that fit the existing scanner workflow — no shared code ownership, no scanner rebuild required.
OEM Engine outputs are designed for scanner-native ingestion and human-reviewed triage. Findings flow into the partner's existing review workflow — not directly to end customers as automated claims.
Pricing & access
Use a license for repeatable scanning and developer exports, or scope a Workbench-backed review when a marketplace submission, enterprise buyer, or disclosure candidate needs human triage.
Starter
Scoped after discovery
Direct product use for one organization with repeatable scanning, exports, and evidence.
Team
Scoped after discovery
Team usage with VS Code/SARIF/Jira exports, developer export, validation evidence, and control matrices.
Review Pro
Scoped after discovery
Expanded review support, pre-submission evidence packs, white-label outputs, CVE triage, and patch-diff checks.
AI Code Path Review
Scoped after discovery one-time
Find and prioritize AI-specific code findings and code-risk paths in one private repository. Receive structured findings, an AI Code Path Analysis Report, SARIF, Markdown, remediation priorities, and validation requirements.
Delivery & licensing
Expert-led engagement
AI Security LLC runs the scanner directly against a scoped codebase as part of an assessment.
Bounded partner pilot
One repository or target class is scanned headlessly and returned through an agreed output contract.
OEM or licensed capability
The scanner engine runs headless behind a partner's existing AppSec product, keeping their UI, workflow, and customer relationship.
Accepts
A repository, CLI invocation, or localhost API call against a target codebase.
Returns
Structured findings as JSON, SARIF, and evidence bundles.
Current maturity
Fixture-tested
AI SECURITY WORKBENCH
Start with one repository or bounded application surface. Code Scanner will identify AI-specific findings, connect related implementation signals into code-risk paths, define what requires validation, and produce engineering-ready remediation and evidence.
Continue through the Workbench
Continue through the Workbench
Threat Canvas
Place code findings and affected components inside the wider system and flow model.
Continue through the Workbench
Adversarial Range
Exercise the failure conditions suggested by supported code findings.
Continue through the Workbench
Attack Path Analysis
Combine supported findings with system, authority, runtime, and partner context.
Continue through the Workbench
Evidence System
Preserve findings, remediation, validation, and retest outcomes for engineering and review.