Loading…
Loading…
Patent-pending scanning across pickle, .pth, .safetensors, ONNX, PyTorch and TensorFlow checkpoints — supply-chain integrity evidence aligned to ISO 42001 and EU AI Act. Compromised artifacts blocked at the deployment gate.
ML Formats Scanned
AI GRC Frameworks
Deployment Modes
Release Gate
Models from public hubs, partner-provided checkpoints, and even internally trained artifacts moving between environments carry latent supply-chain risk. Generic software scanners do not understand ML formats. Runtime LLM firewalls cannot detect a backdoor that was already baked into the weights.
Most enterprises deploy imported models, fine-tuned checkpoints, and third-party weights without scanning. The first signal of a compromised artifact is typically a production incident.
Conventional software composition analysis tooling scans for known CVEs in software dependencies. Pickle payloads, malicious hooks in weights, and ML loader injections are opaque to that class of scanner.
LLM-firewall tools moderate prompts at runtime. They cannot detect a backdoor already baked into the model — the compromise occurred before the firewall saw the first prompt.
Scan pickle, .pth, .safetensors, ONNX, serialized PyTorch and TensorFlow checkpoints, Keras .h5, joblib dumps, and accompanying deployment code.
Identify backdoor payloads in deserialization paths, malicious hooks (exec, subprocess, network call-out, encoded binaries), and dependency injections in loader scripts.
Block compromised artifacts at the deployment gate. Quarantine workflow with provenance trace produces full forensic context for the security team.
Generate PrismMLScanner reports, provenance traces, and gate decision logs pre-mapped to ISO 42001 supply-chain controls and EU AI Act Art. 15.
Pickle, PyTorch (.pth, .pt), .safetensors, ONNX, TensorFlow SavedModel and HDF5, Keras .h5, scikit-learn joblib, plus loader scripts, requirements files, Dockerfiles.
Identifies hidden payloads in pickle deserialization paths, exec/subprocess/network call-out hooks, encoded binary payloads, and malicious dependency injections in deployment code.
Integrates into MLOps pipelines as a deployment gate. Compromised artifacts blocked before production with full quarantine and provenance trace.
Built on SISA's patent-pending AI model scanning solution. Detection rules are forensics-informed by SISA's Global PFI breach intelligence.
Deploy independently as a release gate, or as a release gate before PrismSecure within the full PRISM lifecycle. Artifact integrity feeds PrismGovern.
PrismMLScanner reports, provenance traces, quarantine records, and gate decision logs pre-mapped to ISO 42001, EU AI Act Art. 15, NIST AI RMF MAP/MANAGE, HITRUST AI Security Certification.
Close the pickle-file and serialized-model attack vector at the gate — not during a forensic investigation.
Imported third-party models become trustable. Internal artifacts moving between environments pass the same gate.
Pipeline-integrated release gate with quarantine workflow — supply-chain risk reduced and evidenced at the artifact level.
Audit-ready evidence aligned to ISO 42001 supply-chain controls, EU AI Act Art. 15, NIST AI RMF, HITRUST AI Security Certification.
