Primary Goal
Detect and reduce security risk continuously from code authoring through deployment and operations.
Embed security into every stage with AI-enhanced detection, remediation workflows, and supply chain transparency.
Detect and reduce security risk continuously from code authoring through deployment and operations.
Provide real-time secure coding guidance, automate vulnerability detection and triage, and improve response precision with threat analysis.
Continuous vulnerability posture, remediation backlog, ATO evidence, and model/package inventory with governance tracking.
Get AI-powered security recommendations while coding, catching vulnerabilities before they enter repositories.
Real-time static application security testing with AI-guided remediation during development.
Capabilities: Real-time code analysis, vulnerability classification, remediation templates, secure coding suggestions.
Owner: Checkmarx (IDA approved)
Platform/Environment: IL5, GCC High compatible
AI coding assistant with embedded security best practices and compliance guidance.
Capabilities: Detect insecure patterns, suggest secure alternatives, enforce DoD secure coding standards, OWASP guidance.
Owner: US Department of Defense (CDAO)
Platform/Environment: IL5, DoD cloud
Scan code, dependencies, and containers automatically; AI prioritizes findings by business risk and suggests remediation.
Comprehensive vulnerability detection across code, dependencies, containers, and IaC with AI-driven prioritization.
Capabilities: Dependency scanning, container scanning, IaC analysis, remediation guidance, risk scoring.
Owner: Snyk (FedRAMP authorized)
Platform/Environment: IL4-IL5, GCC High
AI-powered software composition analysis for open-source and third-party component risk assessment.
Capabilities: License compliance, vulnerability correlation, threat intelligence integration, remediation paths.
Owner: Sonatype
Platform/Environment: IL5, on-prem and cloud options
Pre-approved container and image vulnerability scanners for Army cloud deployments.
Capabilities: Container image scanning, runtime security monitoring, policy enforcement, compliance validation.
Owner: Platform One, DISA
Platform/Environment: IL4-IL5, Iron Bank environments
Maintain visibility into AI models and software dependencies through automated Bill-of-Materials generation aligned with Project Linchpin governance.
Automated AI model and component inventory aligned to DoD AI governance and traceability requirements.
Capabilities: Model provenance tracking, supply chain risk assessment, versioning and configuration control, audit trail maintenance.
Owner: Project Linchpin PMO
POC: linchpin@ai.mil
Automated Software Bill-of-Materials and AI Bill-of-Materials creation for compliance and risk management.
Capabilities: Component inventory, version tracking, dependency mapping, export to SPDX/CycloneDX formats, governance alignment.
Owner: CDAO, JAIC
Platform/Environment: IL5, integrated with pipeline tools
Deploy AI agents to review pull requests for security policy violations and auto-suggest fixes before human review.
Automated code review agents that validate security policies and compliance requirements before merge approval.
Capabilities: Policy violation detection, auto-remediation suggestions, compliance evidence collection, audit logging.
Owner: Army AI Task Force
Platform/Environment: IL5, GitHub/GitLab integrated
Declarative security policies with automated remediation actions aligned to Army standards and DoD guidance.
Capabilities: Policy definition DSL, automated fix generation, rollback capabilities, compliance reporting.
Owner: CDAO, Army Software Factory
Platform/Environment: IL5, policy-as-code