AI APPLICATION SECURITY ASSESSMENT & RED-TEAM
23 battle-tested security sensors orchestrated into one platform — from source code to LLM agents. Normalized findings, contextual risk, release gates, and evidence you can defend. Open-source sensors, proprietary core. Zero vendor lock-in.
AISG IN NUMBERS
Press one button and AISG assesses this very website in front of you — the public security surface: TLS, security headers, redirects, robots, sitemap and DNS. Results appear below in seconds, straight from our production endpoint.
No score without evidence. Every AISG report is assembled from real findings, ordered by impact, with the limits written down. These numbers come from our own scans (archived 30 September 2026).
Risk score, severity breakdown and the exact sensor status — including the ones that did not run. Our repository scan: 4,418 files · 966,090 lines · 1,476 findings, split into 41 critical · 98 high · 405 medium · 932 low.
Sensor status is stated honestly: dependency scanners reported “skipped — no lock files found” rather than staying silent.
Each item carries the sensor, the rule, the severity, the file and line, and a validation state (unverified by default — we never present triage we did not do). CVE-backed findings are enriched with CISA KEV and EPSS probability.
Test fixtures and duplicate sensors are called out explicitly, so 1,476 findings do not read like 1,476 emergencies.
A prioritised fix plan with before/after code examples, a 20-item security checklist showing which controls were actually covered and which stay manual, plus an audit-grade export (Markdown + PDF).
AISG is layer-1 prevention, not a penetration test: nothing is exploited, and results require human review.
Public-URL sample from the same session: 11 findings from httpx, dnsx, subfinder, nuclei and ZAP — mostly informational, including one verified false positive that we published instead of hiding.
Not another scanner. A decision engine that orchestrates the best open-source sensors and turns raw findings into auditable security decisions.
23 security sensors across source code, dependencies, secrets, infrastructure, web, and LLM agents — normalized into one schema. Sensors complement, never duplicate.
SAST · SCA · SECRETS · LLM · WEBRaw CVSS is not a decision. AISG scores with 8 risk factors — exposure, data classification, AI components — and tracks residual risk after controls.
RISK ENGINEFindings across tools are correlated into attack chains with confidence levels — from indication to confirmed — instead of isolated alerts.
CORRELATIONPolicy gates evaluate automatically: severity gates, secrets, missing controls, and the Vibe-Coding Gate block unsafe releases.
GOVERNANCE18-step release gate, human approval matrix, generated-code provenance, and release manifest — evidence for auditors, not vibes.
AUDIT TRAILTrend & delta tracking, version drift detection (model/prompt/RAG changes re-trigger evaluation), CI & pre-commit templates.
CLOSED-LOOPFrom discovering assets to continuous monitoring — every stage leaves auditable evidence.
Scan your AI app — then go deeper. One optional field (your API key, encrypted, never leaves your machine) unlocks live red-team attacks on the model itself.
Full code-level assessment of your AI application. The core mission of AISG.
Everything in Standard, plus LIVE red-team attacks against your model endpoint.
API key is optional — leave it empty and everything still runs. Free/local models (Ollama, vLLM) need no key. Keys are encrypted at rest and never shown again. No key = LLM layer skipped transparently.
AISG doesn't just throw a number at you. Every finding is weighted by severity, then the score is capped by the worst issue found — so a pile of low-severity notes can never masquerade as a critical breach.
Every finding contributes to the score by severity — the more severe an issue, the heavier its weight. The result is a single score in the range 0–100 that is fully reproducible: re-scan the same code and you get the same score.
A pile of low-severity notes can never masquerade as a critical breach. The score reflects both how many issues you have and how severe the worst one is — it only reaches the top of the scale when a truly critical issue is present.
Every sensor, rule and weight is pinned to a versioned engine — reproducible and verifiable on demand. Risk score is an indicator of finding count & severity, not a proof of exploitability.
From solo developer to enterprise — pick the depth you need. Your code & keys never leave your machine.
Pay securely via Virtual Account (BRI, CIMB Niaga, Permata, Mandiri) — choose your own bank and pay from its m-banking (inter-bank transfer also works). Beginner, Expert & Scan Pack are available now.
More payment options coming soon. Need more? Scan Pack — Rp 20rb / 15 scans · 2 targets (detailed findings + location, 30 days, after your tier quota).
Straight answers — including the one you're thinking about.
Open-source = the sensor engines are free. What you pay for is the system around them: orchestrating 23 sensors, routing, parallelism, deduplication, contextual risk scoring, tiered reports, release gates, audit evidence, and ongoing updates — maintained for you. The AISG core (engine, correlation, policy, decision logic) is proprietary; sensors are open-source with full attribution. Like paying for a finished car, not loose engine parts. Building this yourself takes weeks, and you'd maintain it forever.
Yes — these are the same engines used across the industry (many are OWASP/CNCF standard), and being open-source means they can be audited. What raw tools lack is the system: AISG normalizes, deduplicates, scores risk, and supports deterministic re-scans (same input → same findings, verifiable). Every finding records its tool, version, and context (provenance). Results are indicative and meant for human review — as stated in Trust & Legal.
No. API keys are optional and only used for red-teaming paid LLM endpoints — and even then they are yours (BYOK), encrypted at rest, and never shown again. Free/local models (Ollama, vLLM) need no key at all. Without a key, the LLM layer is skipped transparently — everything else still scans.
No. Local scans run in-place where your code lives — code never leaves your machine. AISG only receives the findings (what was found, where, how severe), never your source code or keys.
You stay on your tier — nothing is downgraded. You simply can't start new scans until you top up (Scan Pack) or upgrade. AISG tells you exactly where you stand and what to do next, right on your dashboard.
Depth of report. Community shows findings count only (plus a free deep first scan). Beginner unlocks detailed findings + risk score + PDF report. Expert adds release gate, checklist, trends. Enterprise is the audit-grade layer: immutable audit trail, signed reports (SHA256), and the full audit report export (Markdown + PDF). Lihat contoh report dari pemindaian nyata.
We play by the rules — for your protection and ours.
Scan disclaimer. Results are indicative, not proof of exploitability. Every finding must be reviewed and validated by a human security professional before any remediation decision. AISG is an assessment tool: you are solely responsible for ensuring you are authorized to scan any target. Unauthorized scanning may violate applicable laws. AISG provides no warranty, express or implied, on completeness or accuracy of results.
Proprietary core, open-source sensors. AISG is a systematic assessment platform: we orchestrate proven open-source sensors into one auditable pipeline — you pay for the system, the decisions, and the evidence, not for components. The AISG core (engine, correlation, policy, decision logic) remains proprietary. Third-party attribution is maintained in our Open Source Notices.