SBOMs have been mandated for software since 2021. AI agents have nothing, and they change faster. Vettd extends the bill-of-materials discipline to every layer of the agentic stack, and keeps it current.
vettd-cli walks your estate: agents, models, MCP servers, prompts, skills, credentials, egress, and writes a signed, machine-readable AI-BOM. Zero egress: nothing leaves the host until you decide.
What's deployed, where it runs, and which skills it carries.
Which foundation models each asset calls, and under what account.
Tools, scopes, and prompt configs: not just process lists.
What each asset can reach, and which calls actually leave the building.
Substrate, not another silo. The scanners and eval harnesses you already run write their findings into the same record, and every asset gets graded on two axes, against your workloads.
Credential scope, egress, injection surface, supply-chain posture. Findings from the security tooling you already trust fold into one grade per asset.
Does the agent actually do the job? Benchmarked against your workloads, not a public leaderboard, so the grade means something in your estate.
Contract declared: what it covers, how it collects, where data goes, on the published schema.
Output tested against a Vettd corpus; findings normalize cleanly into the record.
Enforcement round-trip proven: decision out, signed receipt back.
Methodology reviewed by a third party.
A scan is just a findings list. Vettd turns it into remediation work, and the re-scan into proof the fix landed: the loop closes, on the record.
Inventory the estate: local, signed, complete.
Security and performance, one open schema.
Findings become tickets with owners and diffs.
The re-scan proves the fix. Evidence, signed and dated.
The scanner is open source and free forever. Book a briefing to talk through the cloud dashboard: grading, coverage, and evidence across your whole estate.