Open source · AI supply chain security

Know what's inside your AI stack.

AIROM discovers AI components across your software supply chain and generates an evidence-backed AI Bill of Materials.

Scan code, containers, and AI infrastructure. Discover models, datasets, prompts, RAG components, frameworks, and more — with evidence for every finding.

$ pip install airom
$ airom scan .
airom scan ./my-ai-application Scanning
AI COMPONENTS DISCOVERED0

Select a finding to see the evidence behind it.

01 · The problem

AI dependencies are hiding in plain sight.

Traditional software inventories list packages and versions. A modern AI application also depends on models, the providers that serve them, the datasets behind them, prompt templates, embedding models, and vector stores.

Many of these are referenced in code and configuration rather than declared as dependencies, so they don't show up in a package list.

AIROM turns this hidden AI dependency graph into a structured inventory.

AI APPLICATION
Frontend
Application
Modelsnot in package list
Providersnot in package list
Datasetsnot in package list
RAGnot in package list
Vector DBnot in package list
Promptsnot in package list
Templatesnot in package list
In a package inventory Not declared as a package Discovered by AIROM
02 · What AIROM discovers

An inventory of every AI component, not just packages.

AIROM organizes its detections into eight AI asset categories, represented by thirteen component kinds, found across source, configuration and manifests.

model

Models

Discover models referenced directly or indirectly by applications.

dataset

Datasets

Identify datasets and training/data dependencies.

prompt

Prompts

Find prompts and prompt-related assets.

embedding

Embeddings

Identify embedding models and embedding dependencies.

vector_store

Vector databases

Discover vector stores used by AI applications.

rag

RAG pipelines

Identify retrieval-augmented generation components.

framework

Frameworks & SDKs

Detect AI frameworks, libraries, and providers.

infrastructure

Infrastructure

Identify AI-related infrastructure and configuration.

03 · Evidence first

Every finding should have a reason.

AIROM doesn't just tell you what it found. It shows where and why it found it.

1Source location 2Detection method 3Confidence
app/inference.py

Illustrative example. Detector identifiers and field names shown here are examples; see the documentation for the current output schema.

04 · AIBOM output

From discovery to an AI Bill of Materials.

Findings become machine-readable output that other tools can consume, with evidence attached to each component.

$airom scan . --format cyclonedx

      
OUTPUT FORMATS
05 · Developer workflow

One command to see what's in your AI stack.

Run AIROM against any project directory. Add a format flag when you need an AIBOM file instead of terminal output.

~/my-ai-application

    
06 · Security & CI/CD

Put AI visibility into your existing security workflow.

Run AIROM as a step in your CI pipeline. Keep the AIBOM as a build artifact, and send SARIF results to any code scanning tool that accepts SARIF.

01
Git pushcommit / PR
02
CIpipeline job
03
AIROMairom scan .
04
AI discoverycomponents + evidence
05
AIBOM / SARIFbuild artifacts
06
Security workflowreview / triage
CI/CD Pull requests Security scanning Compliance Inventory
07 · Scan targets

Scan more than source code.

Repositories
Git repository
AIROM
AI component inventory
Containers
Container image
AIROM
AI dependencies
Kubernetes
Kubernetes manifests
AIROM
AI infrastructure
One AI component inventory CycloneDX · SARIF · JSON · YAML
08 · Open source

Built in the open.

AIROM is open source. Inspect it, run it locally, integrate it into your workflow, and contribute to its detection ecosystem.

github.com/airomhq/airom
Stars
15
Contributors
4
Latest
v0.4.7
License
Apache-2.0
Counts are from the last site build; the repository is the live source.
09 · Technical foundations

Built for engineers who need evidence.

Open source

The scanner and its detectors are public. Read the code that produces every finding.

Evidence-backed findings

Each component links to a file, line, detection method, detector and confidence level.

Machine-readable output

Structured JSON and YAML for scripts, pipelines and downstream tooling.

CycloneDX support

Generate an AIBOM in the CycloneDX format alongside your existing SBOM process.

SARIF support

Emit findings as SARIF for tools that read static analysis results.

CI/CD integration

Runs as a command-line step, so it fits into any pipeline that can run a static binary.

Deterministic scanning

Rule-based detectors produce the same findings for the same input.

Local-first workflow

Run it on your machine or your own CI runner, next to the code you scan.

10 · Use cases

One inventory, four teams.

Developers

Understand the AI components inside your application.

Security teams

Discover AI dependencies and integrate findings into security workflows.

Platform teams

Standardize AI component visibility across repositories and environments.

Compliance teams

Generate structured AI inventory information with traceable evidence.

11 · Get started

Start scanning in minutes.

Install from PyPI and run your first scan from the project root.

Read the documentation
01 $ pip install airom
02 $ airom scan .

Make your AI supply chain visible.

Discover the models, data, prompts, frameworks, and infrastructure behind your AI applications.