AI Systems Have Unique Attack Surfaces
Traditional security scanners miss AI-specific vulnerabilities like prompt injection, RAG poisoning, and tool abuse.
Traditional Security Scanners
- Miss AI-specific attack patterns
- No prompt injection detection
- No RAG poisoning checks
- No LLM tool abuse detection
HAIEC AI Static Security Scanner
- 121 static security rules across 12 attack categories
- Prompt injection pattern matching
- RAG poisoning detection
- Tool abuse and agent safety checks
What We Detect
12 attack categories with 121 static security rules and compliance mappings across multiple frameworks
Prompt Injection
CriticalUser input reaches LLM prompts without validation
REST API Detection
MediumDirect AI REST API calls without SDK wrapper or protection
SDK Detection
InfoAI SDK imports detected for system monitoring and change management
Dangerous Tool Abuse
CriticalDangerous tools (PythonREPL, Shell, eval/exec) exposed to AI agents
API Key & Secrets Exposure
CriticalHardcoded API keys, secrets in logs, URLs, or error messages
Agent & Advanced Safety
HighAgent loops, recursive calls, missing guardrails, memory injection
Data Leakage & Privacy
CriticalPII in prompts, sensitive DB fields, training data leakage
RAG & Vector Store Security
HighUnvalidated vector store ops, user-controlled embeddings, metadata injection
Production Security & Config
MediumMissing rate limits, auth, cost tracking, debug mode, error logging
Model Security
HighModel extraction, unverified loading, poisoning, weights exposure
Injection & XSS via AI Output
HighAI-generated content used unsafely in HTML, SQL, or HTTP requests
Multimodal & Misc
MediumImage/audio input injection, AI filesystem access, verbose errors
How the AI Static Scanner Is Built
Five layers from repo clone to compliance evidence. Source code is ephemeral — always deleted after scan.
Security Blueprint
Your Journey to AI Security Evidence
8 steps from scan initiation to compliance evidence. Source code is ephemeral — never persisted.
Initiate Scan
Provide your GitHub repository URL. Authenticate with your HAIEC account. The scan can be triggered from the dashboard, CI/CD pipeline (GitHub Action), or API.
Scan authorization validates session, checks rate limits, and verifies GitHub access token. Scan intent schema enforced. State machine transitions to authorized.
Authorized scan session with validated repository target
Built for Production AI Security
Enterprise-grade features for teams shipping AI to production. Deterministic, reproducible, audit-ready.
Passive Static Analysis
No runtime execution required. Scans your codebase without deploying or running your application.
Baseline & Diff Tracking
Track security improvements over time. Only alert on new or regressed findings.
SARIF Export
Export findings in SARIF format for GitHub Code Scanning and CI/CD integration.
Trust Page Generator
Generate customer-facing security status pages to build trust with prospects.
Questionnaire Support
Scan results can support security questionnaire responses. Manual review is still required for comprehensive security assurance.
Evidence Source for Assurance
Static analysis findings feed into HAIEC Evidence and the AI Action & Access Map where supported. The scanner is one evidence source, not the full assurance product.
One evidence source, not the whole product
The AI Security Scanner is one evidence source within HAIEC. Static analysis findings connect to the AI Action & Access Map and Evidence surfaces where supported.
Scanner
Static analysis finds AI-specific vulnerabilities in source code. One evidence source among several.
AI Action & Access Map
Scanner findings contribute to the map showing what the AI can reach, change, and trigger.
Assurance
Evidence feeds assurance — a bounded evaluation within an evaluated scope. The scanner alone is not assurance.
The scanner is not the full HAIEC product. It does not by itself produce assurance, certification, or a compliance guarantee. Learn what HAIEC is and see developer security packages.
Scan Your AI Code
AI security scanning is available across HAIEC's canonical tiers — SCAN, DEFEND, ASSURE, and FIRM. See the full pricing and feature comparison on the pricing page.