ASVS
NEW

AI Agent Security Vulnerability Scanner

Code and design, audited together.

Runtime scanning joined with design-phase audit. 67 RT rules sweep code and tools; 103 atomic requirements cover governance and regulation. A single report shows 8 trustworthiness axes and EU AI Act 101-article mapping on the same page.

DP + RT dual track103 atomic checklistEU AI Act 101-article mapping8 trustworthiness axes scoredPortable consultant box
8 Trustworthy Axes

See trustworthiness as a shape, not a single score.

Security is not one number. Splitting it into 8 attributes lets the weakest axis show on page one of the report.

SecuritySafetyReliabilityTransparencyAccountabilityFairnessHuman CentricityPrivacy Protection

Trustworthiness is shown as a shape, not a number. The weakest axis is visible on page one.

Security
Supply chain, IAM, secrets, runtime defense. 67 RT rules catch them directly in code and images.
Safety
System safety, output guardrails, emergency stop. Bad outputs do not escalate into operational risk.
Reliability
Resilience, drift, reproducibility. Confirm the same model returns the same answer over time.
Transparency
Model card, data card, reasoning trace. Executives and external auditors review the same document.
Accountability
RACI, audit log, responsibility trace. Who approved what answers directly in the report.
Fairness
Bias, discrimination, data sampling. Quantify the impact on protected groups.
Human Centricity
HITL, oversight, user control. Insertion points for humans are mandated at design time.
Privacy Protection
Minimization, regional retention, DSR, re-identification. GDPR and local privacy laws sit in the same rule set.
Capabilities

Catch AI-agent risk on the code side and the design side.

A code scanner alone misses governance and regulation. A design audit alone cannot tell what the code really does. The two tracks are joined.

DP Audit (Design Phase) track

Automated audit of governance, data protection, output guardrails, and fairness against documents and SRS. 103 atomic rules ship as a 1:1 report.

67 RT rules + 11 analysis engines

SAST · SCA · DAST · MCP tool · permission · behavior · malware · prompt injection · API · RAG · multimodal. Code and runtime surface in one scan.

103 atomic 1:1 report

Six states: PASS · PARTIAL · WARNING · FAIL · N/A · INSUFFICIENT. A composite A-to-F grade sits at the top.

EU AI Act 101-article auto-mapping

Three coverage types (Direct · Procedural · Supportive) automate compliance reporting. South Korea, NIST AI RMF, ISO 42001 expansion planned.

Boardroom PDF report

A 4-to-6 page executive PDF is generated when the audit completes. Korean fonts embedded. Prints cleanly in air-gapped environments.

Portable consultant box

Laptop or USB form factor for on-site audits in closed networks. Same engines and report format as the SaaS; immediate PDF output.

Atomic Checklist

103 requirements become 103 lines in the report.

Leaving trustworthiness abstract makes nobody accountable. Every requirement decomposes into an atomic row with a color and a grade.

103 atomic requirements
1 audit. 103 rows. 6 states.
live demo
PASS (58)
Evidence and automated check both satisfied
PARTIAL (18)
Evidence exists, only some criteria met
WARNING (12)
Evidence exists, with operational risk signal
FAIL (8)
Mandatory requirement missing
N/A (4)
Out of scope (rationale mandatory)
INSUFFICIENT (3)
Evidence request auto-generated
Composite Grade
B+
composite of 103 rows
A
B
C
D
E
F

A weighted aggregation of the 103 atomic rows produces a 6-tier composite (A · B · C · D · E · F). The same grade lands in external reports and internal KPIs.

How it works

DP audit and RT analysis, same isolated environment.

The target is loaded into isolation once. Eleven RT engines inspect code and runtime; the DP track audits design documents and SRS. Results merge into a single report.

Stage 1
Load target
Agent code · MCP tool · API · design doc · SRS
Stage 2
Isolated sandbox
Container + syscall filter shield production
Stage 3
Unified report
AIVSS · 8-axis radar · EU AI Act map · 4-6p PDF
DP + RT Engines
SAST
SCA
MCP Tool
DAST
Permission
Behavior
Malware
Prompt Injection
API
RAG
Multimodal
Vendor-neutral isolated execution
Any LLM or agent framework runs in the same container. No trace is left in production.
gVisorContainerNetwork EgressRead-only FSSyscall filter

All analysis terminates inside the isolation container. The target never leaks calls or network requests outward.

Regulatory Mapping

EU AI Act 101 articles, in one audit pass.

An 11-group × 3-coverage heatmap. See on one page which articles apply directly and which are only procedurally supported.

EU AI Act × ASVS coverage
101 articles
Direct
Procedural
Supportive
Total
Prohibited practices
2
2
4
High-risk classification
7
1
8
Risk management
14
1
15
Data governance
17
1
1
19
Technical documentation
1
1
1
3
Record keeping
8
8
Transparency to users
14
14
Human oversight
10
10
Accuracy & robustness
4
1
5
Post-market monitoring
6
1
7
Conformity & registration
8
8
Σ
91
7
3
101
DirectDirect

Code or document evidence satisfies the article obligation directly

ProceduralProcedural

Met through policy or approval flow; automated check still recommended

SupportiveSupportive

Classified as reference or best practice; no FAIL outcome

Korea AI Framework Act, NIST AI RMF, ISO 42001, and MAS FEAT mappings are rolling out in phases.
vs.aiclude.com / scans
Search scans · targets…

Scans

Recent scan jobs and their outcomes.

IDTargetStatusRiskScoreVulnsStarted
a4f9c2bb…agent-prod-01.internalcompletedHIGH781205/18, 07:42 AM
8be317cc…mcp-sandbox-09completedMEDIUM42705/18, 06:18 AM
ff21a045…rag-knowledgecompletedLOW19305/18, 03:02 AM
12c83bb9…concierge-kioskcompletedMEDIUM48905/17, 10:55 PM
7d9e2af8…salesbot-prodrunning005/18, 01:11 PM
63b1a07f…docs-rag-agentcompletedCRITICAL921805/17, 06:09 PM
aa92e110…support-helpdeskcompletedINFO6105/17, 03:24 PM
5c4f8a30…finance-analystqueued005/18, 01:42 PM
Use Cases

Industry audit scenarios

Public RFP, financial compliance, manufacturing safety, telecom regulation. The same audit produces an industry-specific report.

Public-sector RFP response

EU AI Act 101-article auto-mapping and AI framework-act alignment included in the report.

Compliance-ready RFP

Financial compliance audit

8 trustworthiness axes plus a 6-state status enum delivered to executives, legal, and engineering with the same data.

Executive + legal aligned

Safety-critical manufacturing agents

Audit AI-agent systems on STPA and FMEA criteria. The portable box runs on-site.

On-site audit

Telecom and air-gapped consulting

Air-gapped audit support. No internet required: the portable box prints a Korean PDF on the spot.

Air-gapped instant PDF
Delivery Modes

Three deployment shapes. Pick the one that fits.

From a free SaaS start to a portable consultant box. Engines and report format are identical across all three.

Free start

SaaS

Start instantly at vs.aiclude.com. First audit within five minutes of signup.

best fit: Startups, fast validation, demos
Customer infra

On-premise

Same engines inside your datacenter or VPC. SSO, BYOK, and audit log isolation.

best fit: Finance, government, enterprise security
Air-gapped

Portable consultant box

Laptop or USB form factor. Audits run in closed networks; Korean PDF prints on the spot.

best fit: Telecom, manufacturing, security consulting
Why ASVS

Code and governance in one tool.

DP + RT dual track
Design-phase audit and runtime scanning merge into one report. Competing code-only scanners cannot do this.
Eight-method matrix
STRIDE, LINDDUN, STPA, FMEA, IEEE 7001, RACI, HITL, and Canada AIA in one checklist. Multi-axis catches risks that any single method misses.
8 trustworthiness axes
Not collapsed into one Security number. An eight-axis radar surfaces the weakest axis on the first page.
EU AI Act 101-article auto-mapping
The 101 articles you used to trace by hand are categorized PASS / PARTIAL / WARNING / FAIL in a single audit pass.
Korean PDF 4-6 pages
Executive PDF generated the moment the audit ends. Korean fonts embedded; prints cleanly in air-gapped environments.
Portable consultant box
Same engines as the SaaS, on a laptop or USB. Field audits run without internet.
Automated detection 47%
Up from 28% (RT alone) to 47% with DP static audit. Less human-interview overhead.
Vendor-neutral
OpenAI, Anthropic, or local LLMs. Any combination runs in the same container and produces the same report.
Get started

Audit your agent's code and design, in five minutes.

Start a free audit at vs.aiclude.com. Results arrive as an 8-axis radar and a 4-to-6 page PDF.