Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire

Insignary Launches Clarity AIR: Closing the Blind Spot Between What Your Developers Declare and What’s Actually in Your Code

New snippet-level scanning shows security and compliance leaders which open-source code and which AI-written code never made it into a manifest.

Insignary Inc. today announced the general availability of Insignary Clarity AIR, a source-code scanning product built to answer a question most security teams can’t currently answer with confidence: what is actually running in their software, beyond what developers reported.

Manifests and SBOMs built from declared dependencies are only as complete as what developers chose to report. An estimated 70–90% of applications today are built substantially on open-source code, and a meaningful share of it arrives through channels no manifest captures — a function copied from another project, a snippet pulled from a forum, a block an AI coding assistant generated and nobody reviewed line by line. For a CISO signing off on an SBOM, or a legal team certifying license compliance, that gap is unmanaged risk sitting inside a document meant to prove the opposite.

Clarity AIR is built to close it, at the source-code level rather than the manifest level:

It finds open source your manifest doesn’t know about, matching source code against Insignary’s fingerprint database of the open-source ecosystem — even when the code has been modified, adapted, or regenerated, which is exactly what happens when AI assistants touch it.

It tells organizations how much of their codebase an AI actually wrote, classifying code line by line with a confidence score, so engineering, security, and legal can see AI-assistant output as a distinct risk category instead of an invisible one.

It inventories the AI your software depends on — the models, APIs, and frameworks built into the product itself — producing an AI Bill of Materials alongside the standard open-source one.

Every match is reviewed and confirmed by a human before it’s counted, and results export as audit-ready SBOMs and full reports.

“You cannot verify an SBOM by reading the manifest that created it. AI-written code is the same problem. If a developer does not declare it, nothing records it. You have to look at the code itself,” said Taek Wan Kim, President & CEO of Insignary.

Current Compliance Context

For CISOs, the compliance calendar just accelerated across North America — unevenly, which is its own risk. In the U.S., OMB’s January 2026 update (Memorandum M-26-05) pushes federal agencies toward independently verifying vendor SBOMs rather than relying on a single attestation form, and FDA Section 524B remains a separate, binding requirement for every cyber device submission. In Canada, Bill C-8 made the Critical Cyber Systems Protection Act law in June 2026, with supply-chain obligations now phasing in. None of this converges into one clean rule — which is exactly why an inventory built only on what developers chose to declare is so fragile to defend, whichever side of the border you’re on.

Clarity AIR joins Insignary Clarity, the company’s binary-level software composition analysis platform, and Clarity SC, its SBOM governance platform, in the Insignary Clarity suite — giving security and compliance teams coverage from source code through compiled binaries to SBOM lifecycle management.

Availability

Clarity AIR is available now directly from Insignary and through its partner channel, deployed on customer-owned infrastructure. Trial licenses are available on request at insignary.com. A free, easy-to-use demo of the AI code detection capability is also available at insignary.com for anyone to try.

About Insignary

Insignary Inc. is a Toronto-based software supply chain security company. Its patented binary fingerprint technology lets enterprises, government agencies, and software vendors verify what’s actually inside the software they build, ship, and deploy — directly from compiled binaries, without needing source code. Insignary has been cited in four Gartner research reports and named a Sample Vendor for Reachability Analysis in the Gartner Hype Cycle for Secure Software Engineering, 2026. The company is supported by strategic partners including BearingPoint in Europe; Cybertrust Japan and TechMatrix in Japan; and TMA Solutions.

Comments are closed.