AI APPLICATION SECURITY ASSESSMENT & RED-TEAM
23 battle-tested security sensors orchestrated into one platform — from source code to LLM agents. Normalized findings, contextual risk, release gates, and evidence you can defend. Open-source sensors, proprietary core. Zero vendor lock-in.
AISG IN NUMBERS
Not another scanner. A decision engine that orchestrates the best open-source sensors and turns raw findings into auditable security decisions.
23 security sensors across source code, dependencies, secrets, infrastructure, web, and LLM agents — normalized into one schema. Sensors complement, never duplicate.
SAST · SCA · SECRETS · LLM · WEBRaw CVSS is not a decision. AISG scores with 8 risk factors — exposure, data classification, AI components — and tracks residual risk after controls.
RISK ENGINEFindings across tools are correlated into attack chains with confidence levels — from indication to confirmed — instead of isolated alerts.
CORRELATIONPolicy gates evaluate automatically: severity gates, secrets, missing controls, and the Vibe-Coding Gate block unsafe releases.
GOVERNANCE18-step release gate, human approval matrix, generated-code provenance, and release manifest — evidence for auditors, not vibes.
AUDIT TRAILTrend & delta tracking, version drift detection (model/prompt/RAG changes re-trigger evaluation), CI & pre-commit templates.
CLOSED-LOOPFrom discovering assets to continuous monitoring — every stage leaves auditable evidence.
Scan your AI app — then go deeper. One optional field (your API key, encrypted, never leaves your machine) unlocks live red-team attacks on the model itself.
Full code-level assessment of your AI application. The core mission of AISG.
Everything in Standard, plus LIVE red-team attacks against your model endpoint.
API key is optional — leave it empty and everything still runs. Free/local models (Ollama, vLLM) need no key. Keys are encrypted at rest and never shown again. No key = LLM layer skipped transparently.
AISG doesn't just throw a number at you. Every finding is weighted by severity, then the score is capped by the worst issue found — so a pile of low-severity notes can never masquerade as a critical breach.
Every finding contributes to the score by severity — the more severe an issue, the heavier its weight. The result is a single score in the range 0–100 that is fully reproducible: re-scan the same code and you get the same score.
A pile of low-severity notes can never masquerade as a critical breach. The score reflects both how many issues you have and how severe the worst one is — it only reaches the top of the scale when a truly critical issue is present.
Every sensor, rule and weight is pinned to a versioned engine — reproducible and verifiable on demand. Risk score is an indicator of finding count & severity, not a proof of exploitability.
From solo developer to enterprise — pick the depth you need. Your code & keys never leave your machine.
Paid tiers & scan packs are coming soon — grab the free early-access slot while it lasts.
Straight answers — including the one you're thinking about.
Open-source = the sensor engines are free. What you pay for is the system around them: orchestrating 23 sensors, routing, parallelism, deduplication, contextual risk scoring, tiered reports, release gates, audit evidence, and ongoing updates — maintained for you. The AISG core (engine, correlation, policy, decision logic) is proprietary; sensors are open-source with full attribution. Like paying for a finished car, not loose engine parts. Building this yourself takes weeks, and you'd maintain it forever.
Yes — these are the same engines used across the industry (many are OWASP/CNCF standard), and being open-source means they can be audited. What raw tools lack is the system: AISG normalizes, deduplicates, scores risk, and supports deterministic re-scans (same input → same findings, verifiable). Every finding records its tool, version, and context (provenance). Results are indicative and meant for human review — as stated in Trust & Legal.
No. API keys are optional and only used for red-teaming paid LLM endpoints — and even then they are yours (BYOK), encrypted at rest, and never shown again. Free/local models (Ollama, vLLM) need no key at all. Without a key, the LLM layer is skipped transparently — everything else still scans.
No. Local scans run in-place where your code lives — code never leaves your machine. AISG only receives the findings (what was found, where, how severe), never your source code or keys.
You stay on your tier — nothing is downgraded. You simply can't start new scans until you top up (Scan Pack) or upgrade. AISG tells you exactly where you stand and what to do next, right on your dashboard.
Depth of report. Community shows findings count only (plus a free deep first scan). Beginner unlocks detailed findings + risk score + PDF report. Expert adds release gate, checklist, trends. Enterprise adds audit trail, signed reports, full 24-section report. Same engine — deeper decisions as you go up.
We play by the rules — for your protection and ours.
Scan disclaimer. Results are indicative, not proof of exploitability. Every finding must be reviewed and validated by a human security professional before any remediation decision. AISG is an assessment tool: you are solely responsible for ensuring you are authorized to scan any target. Unauthorized scanning may violate applicable laws. AISG provides no warranty, express or implied, on completeness or accuracy of results.
Proprietary core, open-source sensors. AISG is a systematic assessment platform: we orchestrate proven open-source sensors into one auditable pipeline — you pay for the system, the decisions, and the evidence, not for components. The AISG core (engine, correlation, policy, decision logic) remains proprietary. Third-party attribution is maintained in our Open Source Notices.