AI APPLICATION SECURITY ASSESSMENT & RED-TEAM

Your AI stack. Every angle.
One auditable gate.

23 battle-tested security sensors orchestrated into one platform — from source code to LLM agents. Normalized findings, contextual risk, release gates, and evidence you can defend. Open-source sensors, proprietary core. Zero vendor lock-in.

Start Free Scan See the Pipeline
aisg — scan pitchflow
LIVE
$ aisg scan my-app --profile pr
SAST (pattern rules)3 findings
SAST (data-flow)2 findings
SCA (dependencies)1 CVE
Infra & secrets1 critical
LLM (red-team)4 issues
Release gate: BLOCKED (vibe-gate policy)
Report: 24 sections + evidence + provenanceready

AISG IN NUMBERS

23Security Sensors
11Sensor Categories
20+Checklist Items
18Release Gate Steps
100%Audit Evidence

Capabilities.

Not another scanner. A decision engine that orchestrates the best open-source sensors and turns raw findings into auditable security decisions.

01Orchestrated Detection

23 security sensors across source code, dependencies, secrets, infrastructure, web, and LLM agents — normalized into one schema. Sensors complement, never duplicate.

SAST · SCA · SECRETS · LLM · WEB

02Contextual Risk

Raw CVSS is not a decision. AISG scores with 8 risk factors — exposure, data classification, AI components — and tracks residual risk after controls.

RISK ENGINE

03Attack-Path Correlation

Findings across tools are correlated into attack chains with confidence levels — from indication to confirmed — instead of isolated alerts.

CORRELATION

04Policy-as-Code

Policy gates evaluate automatically: severity gates, secrets, missing controls, and the Vibe-Coding Gate block unsafe releases.

GOVERNANCE

05Release Gate & Provenance

18-step release gate, human approval matrix, generated-code provenance, and release manifest — evidence for auditors, not vibes.

AUDIT TRAIL

06Continuous Evaluation

Trend & delta tracking, version drift detection (model/prompt/RAG changes re-trigger evaluation), CI & pre-commit templates.

CLOSED-LOOP
SASTSCASECRETSINFRAWEBLLM RED-TEAMMCPRECONMISCONFIGAPI FUZZTLSEXPLOITABILITY+ 23 SENSORS · ONE GATE SASTSCASECRETSINFRAWEBLLM RED-TEAMMCPRECONMISCONFIGAPI FUZZTLSEXPLOITABILITY+ 23 SENSORS · ONE GATE

One Pipeline. Total Visibility.

From discovering assets to continuous monitoring — every stage leaves auditable evidence.

DISCOVERassets & AI-BOM
CLASSIFY8-factor risk
THREAT MODELSTRIDE·ATLAS·ATT&CK
CONTROL43 remediation playbooks
ASSESS23 sensors
AUTHORIZEhuman approval
GATErelease + vibe-gate
MONITORcontinuous eval

LLM Depth. Your Choice.

Scan your AI app — then go deeper. One optional field (your API key, encrypted, never leaves your machine) unlocks live red-team attacks on the model itself.

STANDARD — NO KEY

Full code-level assessment of your AI application. The core mission of AISG.

  • 23-sensor catalog — SAST, SCA, secrets, infra, DAST, API & asset, LLM (routed by target type)
  • Hardcoded API keys & secrets in your code
  • Insecure RAG flow & LLM integration (prompt-injection sinks)
  • Vulnerable AI libraries & outdated dependencies
  • Live app & API surface scan (DAST)
  • Layered reports: summary → governance → audit-grade
DEEP — WITH KEY (OPTIONAL)

Everything in Standard, plus LIVE red-team attacks against your model endpoint.

  • Everything in Standard
  • Jailbreak — model forced out of its rules
  • Prompt injection (direct + indirect / RAG poisoning)
  • Data leak / PII exposure & system-prompt extraction
  • Multi-turn attack chains + app-level input-path evals
  • MCP tool-abuse checks
  • Live evidence: attacks really executed against your model

API key is optional — leave it empty and everything still runs. Free/local models (Ollama, vLLM) need no key. Keys are encrypted at rest and never shown again. No key = LLM layer skipped transparently.

Transparent Risk Scoring.

AISG doesn't just throw a number at you. Every finding is weighted by severity, then the score is capped by the worst issue found — so a pile of low-severity notes can never masquerade as a critical breach.

Severity-weighted & deterministic

Every finding contributes to the score by severity — the more severe an issue, the heavier its weight. The result is a single score in the range 0–100 that is fully reproducible: re-scan the same code and you get the same score.

Anchored by the worst issue

A pile of low-severity notes can never masquerade as a critical breach. The score reflects both how many issues you have and how severe the worst one is — it only reaches the top of the scale when a truly critical issue is present.

Deterministic & auditable

Every sensor, rule and weight is pinned to a versioned engine — reproducible and verifiable on demand. Risk score is an indicator of finding count & severity, not a proof of exploitability.

Free Test.

From solo developer to enterprise — pick the depth you need. Your code & keys never leave your machine.

🎁
EARLY ACCESS — FREE for the first 25 developers

7 days FREE — Beginner-level scan: 2 targets · 4 scan runs (2 scans per target) · full report.
Fair use: one slot per account, max 2 claims per network.

Claim Free Test

Paid tiers & scan packs are coming soon — grab the free early-access slot while it lasts.

FAQ.

Straight answers — including the one you're thinking about.

Why pay if the sensors are open-source?

Open-source = the sensor engines are free. What you pay for is the system around them: orchestrating 23 sensors, routing, parallelism, deduplication, contextual risk scoring, tiered reports, release gates, audit evidence, and ongoing updates — maintained for you. The AISG core (engine, correlation, policy, decision logic) is proprietary; sensors are open-source with full attribution. Like paying for a finished car, not loose engine parts. Building this yourself takes weeks, and you'd maintain it forever.

Can I trust results from CLI / Community-Edition tools?

Yes — these are the same engines used across the industry (many are OWASP/CNCF standard), and being open-source means they can be audited. What raw tools lack is the system: AISG normalizes, deduplicates, scores risk, and supports deterministic re-scans (same input → same findings, verifiable). Every finding records its tool, version, and context (provenance). Results are indicative and meant for human review — as stated in Trust & Legal.

Do I need to give you my API keys?

No. API keys are optional and only used for red-teaming paid LLM endpoints — and even then they are yours (BYOK), encrypted at rest, and never shown again. Free/local models (Ollama, vLLM) need no key at all. Without a key, the LLM layer is skipped transparently — everything else still scans.

Does AISG get access to my code?

No. Local scans run in-place where your code lives — code never leaves your machine. AISG only receives the findings (what was found, where, how severe), never your source code or keys.

What happens when my quota runs out?

You stay on your tier — nothing is downgraded. You simply can't start new scans until you top up (Scan Pack) or upgrade. AISG tells you exactly where you stand and what to do next, right on your dashboard.

What's the real difference between tiers?

Depth of report. Community shows findings count only (plus a free deep first scan). Beginner unlocks detailed findings + risk score + PDF report. Expert adds release gate, checklist, trends. Enterprise adds audit trail, signed reports, full 24-section report. Same engine — deeper decisions as you go up.