Models
Discover models referenced directly or indirectly by applications.
AIROM discovers AI components across your software supply chain and generates an evidence-backed AI Bill of Materials.
Scan code, containers, and AI infrastructure. Discover models, datasets, prompts, RAG components, frameworks, and more — with evidence for every finding.
$ pip install airom $ airom scan .
Select a finding to see the evidence behind it.
Traditional software inventories list packages and versions. A modern AI application also depends on models, the providers that serve them, the datasets behind them, prompt templates, embedding models, and vector stores.
Many of these are referenced in code and configuration rather than declared as dependencies, so they don't show up in a package list.
AIROM turns this hidden AI dependency graph into a structured inventory.
AIROM organizes its detections into eight AI asset categories, represented by thirteen component kinds, found across source, configuration and manifests.
Discover models referenced directly or indirectly by applications.
Identify datasets and training/data dependencies.
Find prompts and prompt-related assets.
Identify embedding models and embedding dependencies.
Discover vector stores used by AI applications.
Identify retrieval-augmented generation components.
Detect AI frameworks, libraries, and providers.
Identify AI-related infrastructure and configuration.
AIROM doesn't just tell you what it found. It shows where and why it found it.
Illustrative example. Detector identifiers and field names shown here are examples; see the documentation for the current output schema.
Findings become machine-readable output that other tools can consume, with evidence attached to each component.
Run AIROM against any project directory. Add a format flag when you need an AIBOM file instead of terminal output.
Run AIROM as a step in your CI pipeline. Keep the AIBOM as a build artifact, and send SARIF results to any code scanning tool that accepts SARIF.
AIROM is open source. Inspect it, run it locally, integrate it into your workflow, and contribute to its detection ecosystem.
The scanner and its detectors are public. Read the code that produces every finding.
Each component links to a file, line, detection method, detector and confidence level.
Structured JSON and YAML for scripts, pipelines and downstream tooling.
Generate an AIBOM in the CycloneDX format alongside your existing SBOM process.
Emit findings as SARIF for tools that read static analysis results.
Runs as a command-line step, so it fits into any pipeline that can run a static binary.
Rule-based detectors produce the same findings for the same input.
Run it on your machine or your own CI runner, next to the code you scan.
Understand the AI components inside your application.
Discover AI dependencies and integrate findings into security workflows.
Standardize AI component visibility across repositories and environments.
Generate structured AI inventory information with traceable evidence.
Install from PyPI and run your first scan from the project root.
Read the documentation$ pip install airom
$ airom scan .
Discover the models, data, prompts, frameworks, and infrastructure behind your AI applications.