RiskwareSupplyChain
Software supply chain risk intelligence for open-source dependencies.
Scan packages across npm, PyPI, Go, Maven, and Rust for CVEs, public exploits, supply chain compromises, and breach history. Multi-source scanning, AI risk scoring, transitive dependency graphs, watchlists, and SBOM export.
Built for developers, application security engineers, and GRC professionals.
grepScope
Secure the AI you didn't write.
Scan the model artifacts you download and audit the agent manifests you wire up. grepScope catches malicious payloads and dangerous capability chains before they run. This is two focused APIs, per-API pricing, self-serve.
Built for ML engineers, AI platform teams, and security engineers.
Model Scanning
Detects malicious payloads in serialized ML models (pickle, PyTorch, safetensors) by statically parsing the artifact and never executing it.
Agent Audit
Analyzes MCP and agent tool manifests for dangerous capabilities, overbroad scopes, and injection-to-exfiltration tool chains.