Legal

Transparency and compliance — how we operate, and how we protect you and ourselves.

Scan Disclaimer

Results are indicative, not proof of exploitability. Every finding must be reviewed and validated by a human security professional before any remediation decision. AISG is an assessment tool: you are solely responsible for ensuring you are authorized to scan any target. Unauthorized scanning may violate applicable laws. AISG provides no warranty, express or implied, on the completeness or accuracy of results.

Intellectual Property & Open Source

AISG is a proprietary assessment platform. It orchestrates proven security techniques and open-source components, each executed as an isolated external process without modification. AISG does not claim ownership of, or endorsement from, any third-party project. Trademarks belong to their respective owners.

Full third-party attribution, license texts, and component notices are maintained below, as required by the applicable open-source licenses. The AISG core — engine, correlation, policy, and decision logic — remains proprietary.

Third-Party Notices — Scanner Components

Every scanner below runs as an unmodified, isolated external process (Docker CLI). Licenses verified 2026-08-08.

ComponentLicenseUsed forSource
banditApache-2.0Python SAST (Beginner+)PyCQA/bandit
semgrepLGPL-2.1Multi-language SAST incl. AISG LLM/RAG rulessemgrep/semgrep
codeqlMIT (packs) / GitHub CLI termsDeep-flow SAST (Python/JS)github/codeql
gitleaksMITSecrets in git historygitleaks/gitleaks
trufflehogAGPL-3.0Deep secret scan (Expert+)trufflesecurity/trufflehog
checkovApache-2.0IaC misconfig (Terraform/CFN)bridgecrewio/checkov
grypeApache-2.0Known-vuln dependenciesanchore/grype
osv-scannerApache-2.0Known-vuln dependencies (OSV)google/osv-scanner
syftApache-2.0SBOM generation (Expert+)anchore/syft
trivyApache-2.0Infra misconfig + filesystem secrets (Expert+)aquasecurity/trivy
httpxMITEndpoint/tech discovery (URL)projectdiscovery/httpx
nucleiMITCVE/template scanning (URL)projectdiscovery/nuclei
testssl.shGPL-2.0TLS configuration audit (URL)drwetter/testssl.sh
dnsxMITDNS enumeration (URL)projectdiscovery/dnsx
subfinderMITPassive subdomain discovery (Deep URL)projectdiscovery/subfinder
zapApache-2.0Active DAST crawl (Deep URL)zaproxy/zaproxy
schemathesisMITAPI schema fuzzing (Deep URL)schemathesis/schemathesis
sqlmapGPL-2.0SQLi assessment (catalog, opt-in)sqlmapproject/sqlmap
nmapNPSLPort/network scan (catalog)nmap.org
garakApache-2.0LLM model-level red-teamNVIDIA/garak
pyritMITLLM multi-turn attacks (Microsoft)Azure/PyRIT
promptfooMITLLM app-level tests (incl. RAG/agent)promptfoo/promptfoo

Third-Party Notices — Runtime & Models

ComponentLicenseUsed forSource
Llama 3.1 (via Ollama)Llama Community LicenseLocal LLM inferencellama.com
FastAPI / Uvicorn / PydanticMIT / BSD-3 / MITAPI serverfastapi
PyJWT / python-dotenv / PyYAMLMIT / BSD-3 / MITAuth & configpypi.org
reportlab / pypdfBSD-3 / BSD-3PDF report generation & validationreportlab
docker SDK / cryptography / google-authApache-2.0 / Apache-2.0·BSD / Apache-2.0Container orchestration, secret encryption, Google loginpypi.org
Compliance note: AGPL (trufflehog) and custom-license (nmap, codeql CLI) components are executed strictly as unmodified external processes — never embedded, linked, or redistributed in modified form. Full license texts are available at each source repository above.
By using AISG you acknowledge the disclaimer above and agree that scanning is performed only against targets you are authorized to assess.