AI Systems Have Unique Attack Surfaces
Traditional security scanners miss AI-specific vulnerabilities like prompt injection, RAG poisoning, and tool abuse.
Traditional Security Scanners
- Miss AI-specific attack patterns
- No prompt injection detection
- No RAG poisoning checks
- No LLM tool abuse detection
HAIEC AI Static Security Scanner
- 91 Semgrep rules across 78 display IDs
- Prompt injection pattern matching
- RAG poisoning detection
- Tool abuse and agent safety checks
What We Detect
12 attack categories, 91 Semgrep rules (78 display IDs), 82 compliance mappings across 9 frameworks
Prompt Injection
CriticalUser input reaches LLM prompts without validation
REST API Detection
MediumDirect AI REST API calls without SDK wrapper or protection
SDK Detection
InfoAI SDK imports detected for system monitoring and change management
Dangerous Tool Abuse
CriticalDangerous tools (PythonREPL, Shell, eval/exec) exposed to AI agents
API Key & Secrets Exposure
CriticalHardcoded API keys, secrets in logs, URLs, or error messages
Agent & Advanced Safety
HighAgent loops, recursive calls, missing guardrails, memory injection
Data Leakage & Privacy
CriticalPII in prompts, sensitive DB fields, training data leakage
RAG & Vector Store Security
HighUnvalidated vector store ops, user-controlled embeddings, metadata injection
Production Security & Config
MediumMissing rate limits, auth, cost tracking, debug mode, error logging
Model Security
HighModel extraction, unverified loading, poisoning, weights exposure
Injection & XSS via AI Output
HighAI-generated content used unsafely in HTML, SQL, or HTTP requests
Multimodal & Misc
MediumImage/audio input injection, AI filesystem access, verbose errors
How the AI Static Scanner Is Built
Five layers from repo clone to compliance evidence. Source code is ephemeral — always deleted after scan.
Security Blueprint
Your Journey to AI Security Evidence
8 steps from scan initiation to compliance evidence. Source code is ephemeral — never persisted.
Initiate Scan
Provide your GitHub repository URL. Authenticate with your HAIEC account. The scan can be triggered from the dashboard, CI/CD pipeline (GitHub Action), or API.
Scan authorization validates session, checks rate limits, and verifies GitHub access token. Scan intent schema enforced. State machine transitions to authorized.
Authorized scan session with validated repository target
Built for Production AI Security
Enterprise-grade features for teams shipping AI to production. Deterministic, reproducible, audit-ready.
Passive Static Analysis
No runtime execution required. Scans your codebase without deploying or running your application.
Baseline & Diff Tracking
Track security improvements over time. Only alert on new or regressed findings.
SARIF Export
Export findings in SARIF format for GitHub Code Scanning and CI/CD integration.
Trust Page Generator
Generate customer-facing security status pages to build trust with prospects.
Questionnaire Auto-fill
Auto-fill security questionnaires from scan results. Save hours on vendor assessments.
CSM6 Integration
Maps findings to HAIEC CSM6 framework layers for comprehensive AI governance.
Simple, Transparent Pricing
Start free, upgrade when you need more. All plans include core security scanning.
Free
Get started with AI security scanning
- 3 scans per month
- Top 5 findings visible
- 1 baseline
- JSON export
- Community support
Professional
For growing teams with AI in production
- 25 scans per month
- All findings visible
- 5 baselines
- SARIF export
- 1 trust page
- Questionnaire auto-fill
- 10 suppressions
- 3 GitHub repos
- Email support
Business
For organizations scaling AI securely
- Unlimited scans
- All findings visible
- Unlimited baselines
- SARIF export
- Unlimited trust pages
- Questionnaire auto-fill
- Unlimited suppressions
- Unlimited GitHub repos
- CI/CD integration
- Priority support