AI Agent Security Vulnerability Scanner
Code and design, audited together.
Runtime scanning joined with design-phase audit. 67 RT rules sweep code and tools; 103 atomic requirements cover governance and regulation. A single report shows 8 trustworthiness axes and EU AI Act 101-article mapping on the same page.
See trustworthiness as a shape, not a single score.
Security is not one number. Splitting it into 8 attributes lets the weakest axis show on page one of the report.
Trustworthiness is shown as a shape, not a number. The weakest axis is visible on page one.
Catch AI-agent risk on the code side and the design side.
A code scanner alone misses governance and regulation. A design audit alone cannot tell what the code really does. The two tracks are joined.
DP Audit (Design Phase) track
Automated audit of governance, data protection, output guardrails, and fairness against documents and SRS. 103 atomic rules ship as a 1:1 report.
67 RT rules + 11 analysis engines
SAST · SCA · DAST · MCP tool · permission · behavior · malware · prompt injection · API · RAG · multimodal. Code and runtime surface in one scan.
103 atomic 1:1 report
Six states: PASS · PARTIAL · WARNING · FAIL · N/A · INSUFFICIENT. A composite A-to-F grade sits at the top.
EU AI Act 101-article auto-mapping
Three coverage types (Direct · Procedural · Supportive) automate compliance reporting. South Korea, NIST AI RMF, ISO 42001 expansion planned.
Boardroom PDF report
A 4-to-6 page executive PDF is generated when the audit completes. Korean fonts embedded. Prints cleanly in air-gapped environments.
Portable consultant box
Laptop or USB form factor for on-site audits in closed networks. Same engines and report format as the SaaS; immediate PDF output.
103 requirements become 103 lines in the report.
Leaving trustworthiness abstract makes nobody accountable. Every requirement decomposes into an atomic row with a color and a grade.
A weighted aggregation of the 103 atomic rows produces a 6-tier composite (A · B · C · D · E · F). The same grade lands in external reports and internal KPIs.
DP audit and RT analysis, same isolated environment.
The target is loaded into isolation once. Eleven RT engines inspect code and runtime; the DP track audits design documents and SRS. Results merge into a single report.
All analysis terminates inside the isolation container. The target never leaks calls or network requests outward.
EU AI Act 101 articles, in one audit pass.
An 11-group × 3-coverage heatmap. See on one page which articles apply directly and which are only procedurally supported.
Code or document evidence satisfies the article obligation directly
Met through policy or approval flow; automated check still recommended
Classified as reference or best practice; no FAIL outcome
Scans
Recent scan jobs and their outcomes.
| ID | Target | Status | Risk | Score | Vulns | Started |
|---|---|---|---|---|---|---|
| a4f9c2bb… | agent-prod-01.internal | completed | HIGH | 78 | 12 | 05/18, 07:42 AM |
| 8be317cc… | mcp-sandbox-09 | completed | MEDIUM | 42 | 7 | 05/18, 06:18 AM |
| ff21a045… | rag-knowledge | completed | LOW | 19 | 3 | 05/18, 03:02 AM |
| 12c83bb9… | concierge-kiosk | completed | MEDIUM | 48 | 9 | 05/17, 10:55 PM |
| 7d9e2af8… | salesbot-prod | running | — | — | 0 | 05/18, 01:11 PM |
| 63b1a07f… | docs-rag-agent | completed | CRITICAL | 92 | 18 | 05/17, 06:09 PM |
| aa92e110… | support-helpdesk | completed | INFO | 6 | 1 | 05/17, 03:24 PM |
| 5c4f8a30… | finance-analyst | queued | — | — | 0 | 05/18, 01:42 PM |
Industry audit scenarios
Public RFP, financial compliance, manufacturing safety, telecom regulation. The same audit produces an industry-specific report.
Public-sector RFP response
EU AI Act 101-article auto-mapping and AI framework-act alignment included in the report.
Financial compliance audit
8 trustworthiness axes plus a 6-state status enum delivered to executives, legal, and engineering with the same data.
Safety-critical manufacturing agents
Audit AI-agent systems on STPA and FMEA criteria. The portable box runs on-site.
Telecom and air-gapped consulting
Air-gapped audit support. No internet required: the portable box prints a Korean PDF on the spot.
Three deployment shapes. Pick the one that fits.
From a free SaaS start to a portable consultant box. Engines and report format are identical across all three.
SaaS
Start instantly at vs.aiclude.com. First audit within five minutes of signup.
On-premise
Same engines inside your datacenter or VPC. SSO, BYOK, and audit log isolation.
Portable consultant box
Laptop or USB form factor. Audits run in closed networks; Korean PDF prints on the spot.
Code and governance in one tool.
Audit your agent's code and design, in five minutes.
Start a free audit at vs.aiclude.com. Results arrive as an 8-axis radar and a 4-to-6 page PDF.