AnnexIQ Digital and AI Trust Platform

AI Security

Scan every model, red-team every agent, catch what leaves through a prompt.

Model file scanning, continuous red teaming, and detection across the identities, agents, tool results, and AI conversations in your estate, with every finding attached to a real AI system, a real owner, and a human review queue.

Scan every model, red-team every agent, catch what leaves through a prompt.

AI Security defends the AI you actually run, not just the AI you have registered. A model file scanner inspects ONNX, pickle, safetensors, and GGUF files for deserialization attacks, backdoors, and tampering before a model ever enters your AI registry, without executing or loading anything to find out. Two red team engines, an adaptive engine and a campaign runner, probe your own AI systems the way a real attacker would, only against systems you own and with the campaign runner stopping at its spend cap, including from inside your own CI/CD pipeline through a command line tool.

Because AI Security sits on the same registry as AI Governance, every finding lands against a real AI system with a real owner and a real risk tier, never as a standalone alert nobody can act on. Detectors watch non human identities for behaviour that departs from their own baseline, review whole agent sessions for goal drift and scope violation, screen every agent tool result for secrets and personal data, check AI generated code and SQL before it reaches its destination, and check what people send to AI tools against your own policy categories. All of it writes to one review queue where a person approves or rejects each finding, related findings are grouped into a single alert cluster per system, and a serious cluster becomes an AI Governance incident, raised by the triage agent or escalated by a person.

It detects and reports by default. Nothing blocks, deletes, or silently changes anything on its own: consequential steps wait for a human, incident response is a playbook a person starts, which isolates one affected system by cancelling its runs and revoking its API keys, and where a capability has honest limits, such as judging generated code from its text alone instead of simulating it, the product says so plainly. AI Security is licensed separately, and runs on the same governed agent runtime, kill switch, and audit trail as the rest of the AnnexIQ platform, so it pairs naturally with AI Governance and AI Cost & Chargeback.
The AI Security dashboard, showing open alert clusters, findings awaiting review, incidents raised or linked, model scans, red team coverage, and the time from finding to review, with the queue of what needs your action beginning below.
The AI Security dashboard: open alert clusters, findings awaiting review, incidents raised or linked, model scans, red team coverage, and how long a finding waits for review, all at a glance, with what needs your action next and the top risky AI systems beneath.
Model files scanned before they are ever trusted

Model files scanned before they are ever trusted

Upload a pickle, ONNX, safetensors, or GGUF file and four purpose built, defensive only parsers inspect its structure for deserialization attacks, backdoors, and tampering. Nothing is executed, unpickled, or loaded, and you get either a clean result or a specific, explained finding, never a bare pass or fail.

Red teaming that escalates the way a real attacker does

Red teaming that escalates the way a real attacker does

The adaptive engine escalates each attack from how the target answered the last one, and only against AI systems you own. A person approves a campaign before the campaign runner starts, and the runner stops at its spend cap. Every attempt is recorded as a finding, and a versioned command line tool runs the same testing inside your own CI/CD pipeline.

AI generated code and SQL checked before it goes anywhere

AI generated code and SQL checked before it goes anywhere

Your own application sends an AI generated snippet and its intended destination to a single API and gets back allow, strip, rewrite, or block before it reaches that destination. Static checks catch the common SQL injection, cross site scripting, and shell patterns first, and genuinely ambiguous cases get a second check. It judges the text alone and never claims to simulate what a snippet would do when run.

One review queue for everything a detector flags

One review queue for everything a detector flags

Model scans, red team attempts, non human identity behaviour, agent drift, data loss screening, training data profiling, CVE matches, model extraction patterns, and retrieval audits all write to the same queue, always starting as pending. A reviewer filters by type, severity, or status, sees exactly what was flagged with a short evidence excerpt, and approves or rejects it. No detector approves its own work.

What people send to AI tools, checked against your own policy

What people send to AI tools, checked against your own policy

Detect and report monitoring of what employees send to ChatGPT Enterprise, Claude Enterprise, and Microsoft 365 Copilot through provider sync, or to any AI tool through a companion browser extension, classified against policy categories you write yourself. Nothing is captured until an administrator confirms an exact consent acknowledgement. Only a match becomes a finding, keeping a short excerpt rather than the full conversation. Messages from the browser extension are classified in memory, while provider sync exports are held as connector records.

Many warning signs, one alert, one incident

Many warning signs, one alert, one incident

Related findings on the same AI system, close together in time, are grouped into one alert cluster with a priority score and a short rationale a reviewer can read. A person can dismiss it, and a serious one becomes an AI Governance incident, raised by the triage agent or escalated by a person. From that incident page a person can run a containment playbook that isolates the system and notifies stakeholders, and build a read only forensic timeline from the audit log and dependency graph.