← Back to agents
🔗

Supply Chain Agent

Verifies and monitors in production the supply chain of your AI systems: third-party models, datasets and dependencies. Every check is traced.

What the agent does

📦 Model verification

Analysis of third-party models (Hugging Face, hubs) to spot malicious code and backdoors.

📊 Dataset audit

Provenance, bias and poisoning checked before use.

🔍 ML dependencies

Vulnerabilities and licenses of your pipeline components.

🔒 Model signing

Integrity verified across the whole lifecycle.

📋 AI SBOM

AI-specific software bill of materials: models, data, pipelines.

⚠️ Alerts

Notification if a dependency in your chain becomes compromised.

How it works

1

Inventory

Inventory of your AI components

2

Verification

Analysis of each component

3

Scoring

Assessment of supply-chain risk

4

Monitoring

Monitoring of updates

Technical approach

Artifact analysis

Static inspection of model formats (pickle, safetensors, ONNX).

Behavioral analysis

Sandboxed execution to spot suspicious behavior.

Poisoning detection

Statistical analysis of datasets.

Signatures

Cryptographic verification (Cosign / Sigstore).

Dependency graph

Alerts on CVEs affecting your components.

Sovereign audit trail

Every check reports to the sovereign controller, traced in SHA-256, with no cloud dependency.

Use cases

PRODUCTION

Third-party model validation

Verifying an external model before integrating it into the production pipeline.

COMPLIANCE

SBOM for the AI Act

Building the AI bill of materials expected for high-risk systems.

SECURITY

Backdoor detection

Spotting a backdoor in a pre-trained model before deployment.

Secure your AI supply chain

Submit your system, we return an exposure report covering its supply chain.