498 days until EU AI Act high-risk obligations apply · Dec 02 2027vettd-cli is live today →
The product

The AI bill of materials.

SBOMs have been mandated for software since 2021. AI agents have nothing, and they change faster. Vettd extends the bill-of-materials discipline to every layer of the agentic stack, and keeps it current.

The agentic stackrate of change
Prompts & datacontinuous
Workflows & skillsdaily
Toolsmonthly
MCP serversmonthly+
Modelquarterly
A moving target no point-in-time review can hold. — ISO 42001
01 · Inventory

Every agentic asset you run. Fully local.

vettd-cli walks your estate: agents, models, MCP servers, prompts, skills, credentials, egress, and writes a signed, machine-readable AI-BOM. Zero egress: nothing leaves the host until you decide.

agents & workflows

What's deployed, where it runs, and which skills it carries.

models & providers

Which foundation models each asset calls, and under what account.

mcp servers & tools

Tools, scopes, and prompt configs: not just process lists.

credentials & egress

What each asset can reach, and which calls actually leave the building.

Live todayMIT licenseZero egressAgent-native
02 · Evaluate

One open schema. Every tool becomes an input.

Substrate, not another silo. The scanners and eval harnesses you already run write their findings into the same record, and every asset gets graded on two axes, against your workloads.

A
Security
Live

Credential scope, egress, injection surface, supply-chain posture. Findings from the security tooling you already trust fold into one grade per asset.

reads from: vettd scan · SAST & supply-chain scanners · red-team probes · policy checks
B
Performance
Next

Does the agent actually do the job? Benchmarked against your workloads, not a public leaderboard, so the grade means something in your estate.

reads from: eval harnesses · benchmark suites · task-level evals you define
Vettd Verified: "connected" is a contract, not a status
Tier 1
Connected

Contract declared: what it covers, how it collects, where data goes, on the published schema.

Tier 2
Evidence verified

Output tested against a Vettd corpus; findings normalize cleanly into the record.

Tier 3
Control verified

Enforcement round-trip proven: decision out, signed receipt back.

Tier 4
Independently assessed

Methodology reviewed by a third party.

03 · Control

Evidence an auditor signs. Fixes an engineer ships.

A scan is just a findings list. Vettd turns it into remediation work, and the re-scan into proof the fix landed: the loop closes, on the record.

1 · SCAN

Inventory the estate: local, signed, complete.

2 · GRADE

Security and performance, one open schema.

3 · FIX

Findings become tickets with owners and diffs.

NIST AI RMFISO 42001EU AI ActOWASP
what the auditor signs
Where the verdict lands: eight control points
a decision that can't reach these is a PDF
01
Pull request
hold the merge
02
CI / CD
fail the build
03
Agent registration
gate the catalog
04
Tool invocation
allow / deny the call
05
Model req / resp
redact inline
06
Identity grant
scope the token
07
Container / process
terminate at the kernel
08
Network
close the socket
Start now

Scan today. Grade next. Prove always.

The scanner is open source and free forever. Book a briefing to talk through the cloud dashboard: grading, coverage, and evidence across your whole estate.

Book a 30-min briefing