AI-bom

See every AI component in your software with one scan

Invicti AI-BOM automatically identifies the frameworks, model providers, agentic libraries, vector databases, MCP SDKs and embedded model files in use. No new tools required.

Get a Demo
Your information will be kept private

Thank you!

We received your message and contact details.

Oops! Something went wrong while submitting the form. Please try again.

Are you keeping an eye on your AI?

AI is everywhere and regulations are rising to meet new risks.

AI components are invisible by default

Developers add AI frameworks, model providers, and agentic libraries the same way they add any package — fast and without ceremony. Security teams are rarely told.

Most AppSec tools don’t speak AI

SBOMs from other tools treat AI packages like any other dependency. No category. No provider. No context. A long list of components with no way to identify, filter, or act.

Regulators want details

The EU AI Act and NIST AI RMF require documented AI inventories. Auditors and enterprise procurement teams want to see every AI component in the supply chain. Most orgs would take weeks to meet that need manually.

See what, where, and why AI is in your software

The industry's most detailed AI taxonomy

Most tools list AI packages. We tell you exactly what they are.

Competitors' SBOM tools list AI packages as generic libraries. AI-BOM treats them as a distinct, structured category with evidence and standards-native export

Every entry includes evidence and a PURL

Filterable by category, provider, and application so you can triage without wading through noise

Dedicated taxonomy covering frameworks, agentic libs, RAG/vector DBs, MCP SDKs, model providers, and embedded models

Built on the SBOM pipeline already running in production

AI-BOM extends the existing component graph with a post-scan catalogue-matching step.

AI components surface from your existing SBOM data. No separate tool, scan, or additional configuration

AI components get the same licence and vulnerability treatment as any other dependency

Coverage across 20+ programming languages for declared dependencies

Get a complete AI inventory on your next scan

Answer the board question "what AI do we run and where does it come from?" in minutes, not weeks.

Portfolio-level AI Dashboard showing AI exposure across all scanned applications, provider distribution, and agentic risk

Export in CycloneDX 1.6 and SPDX 3.0 — the formats your auditors already recognise

Standards alignment: CycloneDX 1.6, SPDX 3.0, OWASP AIBOM

EU AI Act and NIST AI RMF both require documented AI inventories — yours builds automatically on every scan

coverage

What we detect

AI/ML Frameworks

LangChain, LlamaIndex, PyTorch, Transformers, Semantic Kernel, Spring AI and others.

Agentic Libraries

CrewAI, LangGraph, AutoGen, Strands Agents, Amazon Nova Act, Google ADK.

RAG & Vector DBs

Pinecone, ChromaDB, Weaviate, Qdrant, Milvus, FAISS. Flags retrieval-augmented generation patterns.

MCP SDKs

Model Context Protocol SDKs across Python, JS/TS, Go, Java, C#. The emerging standard for AI tool interoperability.

External Model Providers

OpenAI, Anthropic, Gemini, AWS Bedrock, Azure OpenAI, Ollama, Groq, LiteLLM and others.

Embedded Model Files

Locally shipped model files inside the application: .gguf, .safetensors, .onnx, .pt. Apps running AI on-box.

What customers say

“For more websites, we now don’t need to go externally for security testing. We can fire up Invicti, run the tests as often as we like, view the scan results, and mitigate to our hearts’ content. As a result, the budget we were spending every year on penetration testing decreased by approximately 60% almost immediately and went down even more the following year, to about 20% of our initial spending.”

—Brian Brackenborough | CISO, Channel 4

“Invicti detected web vulnerabilities that other solutions did not. It is easy to use and set up...”

—Henk-Jan Angerman | Founder, SECWATCH

“I had the opportunity to compare expertise reports with Invicti ones. Invicti was better, finding more breaches.”

—Andy Gambles | Senior Analyst, OECD

“Invicti is the best web application security scanner in terms of price-benefit balance. It is a very stable software, faster than the previous tool we were using and it is relatively free of false positives, which is exactly what we were looking for.”

—Harald Nandke | Principal Consultant, Unify (now Mitel)

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding