HomeCyber BalkansInsignary Launches Clarity AIR for Detecting Open-Source and AI Code

Insignary Launches Clarity AIR for Detecting Open-Source and AI Code

Published on

spot_img

Toronto, Canada, October 8th, 2026, CyberNewswire

Insignary Unveils Clarity AIR: Bridging the Gap Between Developer Declarations and Actual Code

In a significant advancement for software security and compliance, Insignary Inc. has launched Clarity AIR, a revolutionary source-code scanning product designed to address a critical issue many security teams face—the uncertainty surrounding what code is genuinely operating within their software, beyond what developers have reported. The introduction of this tool aims to remedy what has been acknowledged as a persistent blind spot in the software development and compliance processes.

In the dynamic landscape of software development, manifests and Software Bill of Materials (SBOMs) constructed from declared dependencies only reflect what developers have explicitly chosen to report. However, with an estimated 70-90% of modern applications heavily reliant on open-source code, there remains a substantial portion of code that slips through the cracks. This includes snippets lifted from various online resources, functions copied from other projects, and blocks generated by AI coding assistants—elements that are often overlooked in conventional reporting mechanisms.

The gaps in reporting leave security leaders, such as Chief Information Security Officers (CISOs), facing unmanaged risks when signing off on software manifests. These risks are exacerbated when legal teams are called upon to certify license compliance, as the incomplete nature of the reports could lead to potential vulnerabilities, leaving organizations exposed to unforeseen liabilities.

"Clarity AIR was engineered to address these inherent gaps at the source code level," stated Taek Wan Kim, President & CEO of Insignary. The tool identifies open-source components that may not be declared in existing manifests, utilizing Insignary’s proprietary fingerprint database to assess the existence of open-source code—even when that code has undergone modifications, adaptations, or regenerations due to AI interactions.

Moreover, Clarity AIR offers insights into the extent of AI contributions within a codebase. By classifying code lines with associated confidence scores, organizations can better categorize AI-generated code as a specific risk element rather than treating it as an ambiguous entity. This differentiation facilitates more informed decision-making for engineering, security, and legal teams.

The scanning tool further provides a comprehensive inventory of the various AI models, APIs, and frameworks incorporated into the software, generating an AI Bill of Materials alongside the standard open-source inventory. This feature is particularly valuable for organizations seeking transparency in their software components, ensuring that all dependencies are accounted for.

Each identified match within Clarity AIR is meticulously reviewed and verified by human experts before being included in reports, thereby enhancing the reliability of results, which can be exported as audit-ready SBOMs. This level of scrutiny ensures that organizations can confidently attest to their software compliance.

As the regulatory landscape evolves, compliance requirements for organizations across North America have intensified. The U.S. Office of Management and Budget (OMB) recently underscored the urgency for federal agencies to independently verify vendor SBOMs instead of relying solely on a singular attestation form. Additionally, FDA mandates necessitate rigorous compliance for cyber devices, marking further complexities in an already intricate regulatory framework.

In Canada, the enactment of Bill C-8, which established the Critical Cyber Systems Protection Act in June 2026, introduces progressive supply chain obligations that are now in the phased rollout stage. These regulatory advancements underscore the fragility of inventory systems that depend solely on developer declarations, as they may falter under scrutiny from both regulatory bodies and security audits.

To address these multifaceted challenges, Clarity AIR complements Insignary’s existing offerings, which include Clarity, a binary-level software composition analysis platform, and Clarity SC, a governance platform for SBOMs. Collectively, these tools equip security and compliance teams with robust coverage throughout the lifecycle of software development, from source code to compiled binaries.

At present, Clarity AIR is available for direct purchase from Insignary and through its partner channels, with implementation on customer-owned infrastructure. Organizations interested in exploring this innovative tool can request trial licenses via Insignary’s official website. Additionally, a user-friendly demo showcasing the AI code detection capabilities is available for public access, allowing potential clients to experience the tool before committing to a purchase.

About Insignary
Founded in Toronto, Insignary Inc. is a notable player in the realm of software supply chain security. Their patented binary fingerprint technology empowers enterprises, governmental institutions, and software vendors to authenticate the contents of their software products directly from compiled binaries, alleviating the need for source code access. Recognized by several Gartner research reports, Insignary continues to expand its influence within the cybersecurity landscape with strategic partnerships across various regions, reinforcing its commitment to safeguarding the integrity and compliance of software development processes.

Source link

Latest articles

Breach Roundup: Fortibleed Continues to Leak Credentials

Cybersecurity Incidents and Breaches: Weekly Roundup In a continuing effort to inform the public and...

Attackers Compromise Three ccTLDs to Acquire Google Certificates

Cybersecurity Breach: ccTLD Registries Compromised, Unauthorized Certificates Obtained In a significant cybersecurity incident, attackers have...

FBI Warns: FortiBleed Attackers Can Lock Organizations Out of Firewalls

Cybersecurity Threats: Evolving Tactics and FBI Guidance In an alarming update for businesses and organizations...

Ransomware Response Firm CEO Charged with Data Recovery Fraud

MonsterCloud CEO Disguised Ransom Payments as Proprietary Tool, Say Prosecutors In a startling turn of...

More like this

Breach Roundup: Fortibleed Continues to Leak Credentials

Cybersecurity Incidents and Breaches: Weekly Roundup In a continuing effort to inform the public and...

Attackers Compromise Three ccTLDs to Acquire Google Certificates

Cybersecurity Breach: ccTLD Registries Compromised, Unauthorized Certificates Obtained In a significant cybersecurity incident, attackers have...

FBI Warns: FortiBleed Attackers Can Lock Organizations Out of Firewalls

Cybersecurity Threats: Evolving Tactics and FBI Guidance In an alarming update for businesses and organizations...