This entry runs no foundation model. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.
Audits Python environments for packages with known vulnerabilities — the conscious architect's first line of defence against building blindly with unvetted dependencies
No foundation model. pip-audit does not run one, so this criterion does not apply and is excluded from the grade rather than counted against it. pip-audit is a PyPA command-line scanner that checks installed Python packages against the Python Packaging Advisory Database and OSV to report known vulnerabilities. It invokes no foundation model. Established from the product’s own public documentation and what it does. If that is out of date, tell us at right of reply.
Not yet assessed. We publish a sovereignty position only where the vendor documents one — we do not infer it from a domain or a company name.
Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →