Products

Three records, one method

Each answers the same question about software you did not write: what is in it, who says so, and how do you know.

Live registry

Global AI Registry

Provenance for the agents you are about to adopt

Every agent carries a passport recording what its build actually discloses (model, framework, tools, data sources, hosting, residency and permission scope) and who said so.

  • Verified, Disclosed and Unknown are recorded separately
  • Where a source is silent, the value reads Unknown
  • Filter, compare and share a result set by link
Read more →
Self-hostableHelm or ComposeRuns locally

CodeRoot Open Source

Component intelligence, from an SBOM

Upload a bill of materials and every component resolves to its real source repository, enriched with maintenance, contributor, release, dependency and advisory signals, then assessed for where in the world it is actually maintained.

  • Citeable dossiers, versioned and time-stamped
  • Verified facts kept separate from assessed judgments
  • Contributor geography and concentration risk per component
Read more →
Bring your own modelAir-gap capableRead-only MCP

CodeRoot Vulnerability Intelligence

The MITRE chain, self-updating, in your cluster

D3FEND to ATT&CK to CAPEC to CWE to CVE, with the CISA KEV catalog, EPSS scores, the NVD CPE dictionary and both tiers of GitHub Security Advisories. It comes up empty, populates itself and stays current with no operator intervention.

  • Nine ingest sources, unattended
  • A read-only MCP server your own model can query
  • Answers carry citations; no free-form SQL, no model credentials
Read more →