Vannus / Catalog / Bandit

Bandit

This entry runs no foundation model. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Python-focused security linter using heuristic AST parsing — detects hardcoded secrets, weak cryptography, dangerous built-in functions (eval/exec), and insecure imports

security, static-analysis, open-source
Model provenance

No foundation model. Bandit does not run one, so this criterion does not apply and is excluded from the grade rather than counted against it. Bandit is a static analysis tool that scans Python source for common security issues by building an AST per file and running rule-based plugins against the AST nodes. Established from the product’s own public documentation and what it does. If that is out of date, tell us at right of reply.

Who controls it

Not yet assessed. We publish a sovereignty position only where the vendor documents one — we do not infer it from a domain or a company name.

Compliance the vendor states
OWASP

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Bandit ↗ Grade your whole stack →