compliance-gap
policy-drift
ungoverned-agent
audit-flag
vendor-risk
unvetted-mcp
config-drift
data-residency
token-exposure
shadow-agent
api-misuse
auth-gap
exfil-risk
policy-violation
10,000+ agent repositories scanned and classified

Own your
AI Risk
Ship with confidence

You cannot govern what you cannot see. Unseen AI is an unmanaged risk: exposed data, broken controls, and liability nobody signed off on. Agntz reads, analyzes, and shows you every AI capability your teams built, so approval stops being a bottleneck.

One repository. Full visibility.

This is what happens in the two minutes after you connect a single repository.

agntz — governance pipeline
live

Initializing governance pipeline...

What we find in an average repository

Across 10,000+ repositories scanned
0+
Findings Per Repo
0
Shadow AI Per Repo
0
Shadow Vendors Per Repo
0
CVEs Per Repo

Before you connect a repo, estimate what those numbers look like across your whole codebase.

Estimate Your Exposure
Platform

One scan to
secure, govern, and ship AI

Your SCA tool sees a dependency. Agntz sees the model inside it, the tools it binds, and everything it can reach.

Security

Agent Discovery

Find the agents nobody registered, in repos nobody flagged. Shadow AI averages two components per repository, and neither one is on your inventory.

Capability Mapping

Every tool the agent binds, every permission it holds, every place it can send your data. This is the blast radius, mapped before anything runs.

Shadow Vendor Detection

Five vendors per repo reached through transitive dependencies. Your SCA tool sees the package. It does not see the model inside it.

Vulnerability Intelligence

CVEs matched across the full chain and mapped to MITRE ATLAS, so findings arrive in language your SOC already reads.

Compliance

AI Bill of Materials

Every model, framework, plugin and MCP server your agents depend on. The inventory your auditor asks for and nobody currently has.

Control-Level Mapping

Findings tied to specific controls in ISO 42001, NIST AI RMF, ISO 27001, SOC 2, CMMC and HIPAA. Naming frameworks is easy. Naming controls is the evidence.

Your Industry's Rules

Model risk under SR 11-7. Controlled data under ITAR. ePHI paths under HIPAA. Your agents inherit obligations you already carry.

Evidence, Not Claims

Every finding carries the file, the line, and the call path that produced it. Export it and hand it over without translating anything.

Enablement

Zero Touch

Connect a repo and scan. No install, no SDK, no code changes, no architecture review, no ticket.

Every Commit

Re-scanned as the code changes, so your evidence is a diff instead of a snapshot and drift is something you see rather than discover.

Agent Marketplace

10,000+ open-source agent repositories already scanned and classified. Start from something that arrives with its evidence attached.

Free First Repo

Scan your first repository free. No card, no call. Security answers in minutes instead of next sprint.

Shipping Next
In development

Runtime Flight Recorder

The scan already worked out how far every capability can reach. The recorder logs what the agent actually does and measures each event against that blast radius. An anomaly is not something new. It is something that reached further than it should have.

  • A shell call is not an alert. A shell call that lands on your AWS keys is.
  • Every event scored against the impact graph built during the scan.
  • MITRE technique and business impact attached before anyone opens the ticket.

Policy Enforcement follows, turning the reach you have already mapped into guardrails per agent.

payments-agent

Agent activity

Live
Prompt from
dave@company.com
00:00
Model
claude-opus-4.61,847 tokens
00:23
Read File
./src/config.ts
00:41
Run Shellenv | grep AWS01:12
Reach exceeded
Capability

Run Shell

Direct

Filesystem

Reach

.env Files

Credentials

AWS Keys

Maximum reach72%
MITRE T1059Secret Theft10 assets in reach
How it works

Know the agent before you adopt it

Every agent your teams want to bring in, read line by line before it reaches your codebase.

1

Pick Any Agent

Paste a public repository URL. Nothing to install, no access to grant, no ticket to open.

1b

Or Browse the Marketplace

10,000+ open-source agent repositories already scanned and classified, from first-tier to fifth-generation.

2

Agntz Reads Every Line

Tool bindings, permissions, data paths, MCP connections and autonomy loops, resolved into a capability map.

1 agent → 9 repos · Full supply chain
3

See the Blast Radius

Every capability scored for reach. What it touches, what it can compromise, what that costs the business.

4

Get the Evidence

AIBOM, CVEs, MITRE ATLAS coverage, and control references across ISO 42001, NIST AI RMF, CMMC and HIPAA.

5

Decide Before You Adopt

Approve it, restrict it, or walk away. With the reasoning on record either way.

See exactly what your agents touch

Every data source, every API, every credential. Mapped by capability, scored for reach, cross-checked against MITRE ATLAS.

AIDER
AGENT INTERNALDATA ACCESSEXTERNAL SERVICESOPERATING SYSTEMCLOUD APIS
Compliance

Your AI agents inherit every rule you already follow

An agent that touches patient records lands on your HIPAA inventory. One that shapes a credit decision is a model under SR 11-7. One that reads controlled technical data and calls an external model is an export. Nothing changed about the rules. What changed is that nobody read the code.

Findings tied to named controls, not just named frameworks
Every claim backed by a file, a line, and a call path
The evidence your auditor asks for, before they ask for it
Calculate my AI governance risk

Free report. No signup. ~60 seconds.

One scan produces
Capability MapAI Bill of MaterialsBlast RadiusFlight Recordersoon
AI Bill of MaterialsCapability MapBlast RadiusFlight Recordersoon
hiring-screener
Static analysis
Read File./candidates.csvintake.ts:88
Model callclaude-opus-4.6screen.ts:31
Outbound POSTvendor.eu-west-1notify.ts:204
Reach exceeded
Capability

Network Access

Direct

Outbound HTTP

Reach

Candidate Records

Data

Personal Data

Maximum reach68%
Art. 15Annex IIIBoundary Exit

Own your AI Risk
Ship with confidence

Full visibility in minutes. No install. No card. No access to grant.