Every agent, model, MCP server, prompt, and credential in your estate: named, versioned, and pinned in one signed AI-BOM. No asset off the board.
answered in section 02 →A security grade per asset: credential scope, egress, injection surface, supply-chain posture, folded in from the tooling you already trust.
answered in section 03 →Performance and cost with a denominator: benchmarked against your workloads, metered per task, graded $ to $$$$ against the value delivered.
answered in section 03 →Signed evidence mapped to NIST AI RMF, ISO 42001, the EU AI Act, and OWASP — decisions your stack enforces natively, not a PDF.
answered in section 04 →The prompts, configs, and data every asset runs on, versioned and pinned.
What's deployed, where it runs, and which skills it carries.
Which tools each asset can call, what it can reach, and which calls actually leave the building.
Servers, scopes, and prompt configs: not just process lists.
Which foundation model each asset calls, and under what account.
vettd-cli walks your estate and writes one signed AI-BOM. Nothing leaves the host until you decide.
Credential scope, egress, injection surface, and supply-chain posture: findings from the security tooling you already trust fold into one grade per asset.
Does the agent actually do the job? Benchmarked against your workloads, not a public leaderboard, so the grade means something in your estate.
Token burn with a denominator: metered per asset and per task, graded $ to $$$$ against the value delivered.
One inventory answers all four questions: what's running · is it safe · is it worth it · can you prove it.
how grading works →A grade that can't reach the token, the socket, or the pull request is a PDF. A Vettd credential is enforced natively by your stack.
Purpose matches and the evidence is current: the call proceeds untouched, logged end to end. ALLOW is the default state of a governed estate.
Scans become a living inventory your security team can defend: private by default.
The scanner is free forever. Book a briefing to talk through cloud rollout, timelines, and what fits your estate.
Book a 30-min briefing →