Vannus records that this vendor has not disclosed which model it runs. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.
Python dependency vulnerability scanner checking installed packages against the Safety DB — prevents unconscious smuggling of known-vulnerable libraries into production
Uses AI; provider not disclosed. Safety's own site describes LLM-powered analysis in its Data Engine, but no provider is nameable from any Safety-controlled page. We checked and found no first-party page naming it, so the criterion is excluded from the grade rather than counted against Safety. safetycli.com ↗
Not yet assessed. We publish a sovereignty position only where the vendor documents one — we do not infer it from a domain or a company name.
Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →