Upcoming Webinar Closing the Risk Gap: Power and Proof with Checkmarx Fusion Register Today
Press Release Checkmarx Fusion: Hybrid Scanning Delivers the Most Complete Vulnerability Detection Available Read Now
Gartner® Checkmarx Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security Get the Report
Outlook Report The Future of Application Security in the Era of AI Download Now
Latest Innovations
Checkmarx for Developers
Partners
Blog
Research
Checkmarx One – AI Supply Chain Security

LLM Scanner

Close the AI supply chain blind spot. Checkmarx’s LLM Scanner exposes hidden code and security risks
inside your AI model packages before they ever run in production.

AI Model Security Scanning

See the Hidden Code inside AI Model Packages

AI engineers pull models faster than security teams can review them. LLM Scanner closes that gap, scanning bundled source and binaries into actionable findings and a deterministic AI-BOM.

ML-aware static analysis

Scan Model Packages

LLM Scanner connects to Hugging Face repos, Git repos, local directories, and internal registries, extracting and cataloguing every source code file and binary artifact bundled inside AI model packages, so nothing enters your environment without review, including the pickle opcode gadget chains that no SAST or SCA tool was ever built to find.

See it in Action
Screenshot of a dark-themed software interface displaying AI asset scan results and a detailed view of a GPT-4o configuration with a highlighted code snippet.
Pre-Runtime Findings

Detect Unsafe Model Code Before It Runs

Surface insecure deserialization, trust_remote_code, command execution, dynamic eval, and other risks before models load in any environment. The model is never executed during the scan, so there is no risk of triggering the code you are trying to inspect.

See It in Action
A dark-themed UI showing 'Project Sol (Scan Results)' with a list of AI assets and their states, alongside an 'AI SUPPLY CHAIN' panel detailing 'GPT-4o' risks, including 'Unsafe Deserialization in Code' with code snippet.
Deterministic AI-BOM

Generate AI-BOM Evidence

View findings in Checkmarx One and generate deterministic AI-BOM output that records model provenance, findings, and risk posture for governance, audit, and AI adoption decisions.

See It in Action
A dark-themed dashboard showing an 'AI Supply Chain Global Inventory' table with asset details and an 'Export AI-BOM report' modal window open, offering options for standard and format.
Platform Native

Built-in to Checkmarx One

LLM findings surface in the same console, workflows, and ticketing integrations your team already uses, with broader coverage across SAST, SCA, DAST, and now, LLM risk.

See It in Action
llm_feature_built_in_to_checkmarx_one
AI Model Security

AI Model Security Scanning
for Hidden Code Risks

AI models are more than weights and data. They often ship with bundled Python source and serialized artifacts that execute at load time, outside normal AppSec review and invisible to standard scanners. 

Problem

AI models ship with source code
Your AppSec team never sees

Solution

Make hidden model code visible

LLM Scanner extracts and scans bundled source from every model package before runtime, so AppSec teams can see, triage, and stop risks that never reached SAST review.

Problem

Model artifacts are a blind spot your scanners can’t see

Solution

Coverage your existing tools can't reach

ML-aware analysis scans Python, notebooks, and binary model files, catching unsafe deserialization, command execution, and pickle gadget chains that SAST and SCA miss.

Problem

Regulators are asking for AI model evidence you can’t produce.

Solution

Regulators are asking for AI model evidence you can't produce.

Deterministic AI-BOM output documents model provenance, findings, and risk posture, giving teams audit-ready evidence for NIST AI RMF, EU AI Act, and ISO 42001 obligations.

See it in Action

Shadow AI in the SDLC: A Practitioner Panel on Visibility, Risk, and the Road to Governed AI

See how Checkmarx can help you regain visibility before AI governance gaps become an operational risk

A Gartner® Magic Quadrant Leader™
A Forrester Wave Leader™
SOC 2 Type II Certified
Customer Stories

Why the World’s Top Teams Choose Checkmarx

AI Supply Chain Security

Frequently Asked Questions

Secure AI Model Packages Before Runtime

See how LLM Scanner uncovers unsafe code inside AI model packages before it reaches production, catching critical AI risks early and generating AI-BOM evidence in Checkmarx One.

Thank You!

Your Custom Demo Request is successfully sent. A member of Checkmarx Team would contact you shortly to set up your custom demo.

thank you page decoration

Personalized LLM Scanner Demo

Find Hidden Risk Inside Your AI Models

Scan Hidden AI Model Code

Inspect bundled Python files and model artifacts before any model runs in production.

Fit Your ML pipelines

Add CI/CD-native scanning with SARIF, JSON, YAML, or text output.

Binary-Level Coverage

Detect pickle opcode gadget chains and Torch rebuild helpers no SAST or SCA tool can reach.

Built-In AI Governance

Add scan findings to a deterministic AI-BOM to support NIST AI RMF, EU AI Act, and ISO 42001 requirements.

One Platform

Findings appear in Checkmarx One alongside SAST, SCA, and DAST, for unified risk intelligence

Catch High-Risk Patterns Early

Surface unsafe deserialization, command execution, and trust_remote_code risks early.

See It in Action

Scan Model Packages
Before They Run

AI models ship with hidden code most AppSec tools have never reviewed. LLM Scanner brings that blind spot into full view.

A Gartner® Magic Quadrant Leader™
A Forrester Wave Leader™
SOC 2 Type II Certified