AIRIAM · MANAGED

AI Application Vulnerability Detection

Reads code, never data · consequence-led findings for the tenants you manage
Tenant: Northside Clinic Group 1 of 80 in fleet SIMULATION
01Choose input
02Recover the flow
03Declare data
04Detect & trace

1 · Input source

Either door builds the same flow model. Requirements is the original platform capability; code is the new one this feature adds.

Requirements original
Natural-language description of the application.
Source code new
Recover the flows directly from the application's source.

3 · Data declaration

Declare what category of data this tenant handles (Airiam holds this from onboarding). It selects which controls are required — it does not tag edges, and the analyzer never sees the data.

PHI · health PCI · payment PII · personal
Recovered flow · data movement & decisions awaiting input
Choose an input source and recover the flow to begin.
your environment external patient data untrusted payment svc write API leaves env → leaves env → Patient recordsdatastore Inbound emailuntrusted source Payment servicedatastore Web UIstate-mutating entry Support agentkind: agent · makes decisions Delete-records toolcap: admin·delete External LLMmodel_endpoint Send-email toolcap: external·write
Trace
Trace the transaction to watch data move and decisions get made.
Press Start. At each decision point you'll see the decision made — or the missing one that is the vulnerability.
risk path recovered flow control in place environment boundary

4 · What bites this tenant

Findings led by business consequence, ranked by severity. Each shows our confidence and whether it was decided from code or needs confirming.

No detection yet. Recover the flow, declare the data, then run detection.