Press Release

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire

Insignary Launches Clarity AIR: Closing the Blind Spot Between What Your Developers Declare and What’s Actually in Your Code

New snippet-level scanning shows security and compliance leaders which open-source code and which AI-written code never made it into a manifest.

Insignary Inc. today announced the general availability of Insignary Clarity AIR, a source-code scanning product built to answer a question most security teams can’t currently answer with confidence: what is actually running in their software, beyond what developers reported.

Manifests and SBOMs built from declared dependencies are only as complete as what developers chose to report.

An estimated 70–90% of applications today are built substantially on open-source code, and a meaningful share of it arrives through channels no manifest captures a function copied from another project, a snippet pulled from a forum, a block an AI coding assistant generated and nobody reviewed line by line.

For a CISO signing off on an SBOM, or a legal team certifying license compliance, that gap is unmanaged risk sitting inside a document meant to prove the opposite.

Clarity AIR is built to close it, at the source-code level rather than the manifest level:

It finds open source your manifest doesn’t know about, matching source code against Insignary’s fingerprint database of the open-source ecosystem even when the code has been modified, adapted, or regenerated, which is exactly what happens when AI assistants touch it.

It tells organizations how much of their codebase an AI actually wrote, classifying code line by line with a confidence score, so engineering, security, and legal can see AI-assistant output as a distinct risk category instead of an invisible one.

It inventories the AI your software depends on the models, APIs, and frameworks built into the product itself producing an AI Bill of Materials alongside the standard open-source one.

Every match is reviewed and confirmed by a human before it’s counted, and results export as audit-ready SBOMs and full reports.

“You cannot verify an SBOM by reading the manifest that created it. AI-written code is the same problem.

If a developer does not declare it, nothing records it. You have to look at the code itself,” said Taek Wan Kim, President & CEO of Insignary.

Current Compliance Context

For CISOs, the compliance calendar just accelerated across North America unevenly, which is its own risk. In the U.S., OMB’s January 2026 update (Memorandum M-26-05) pushes federal agencies toward independently verifying vendor SBOMs rather than relying on a single attestation form, and FDA Section 524B remains a separate, binding requirement for every cyber device submission.

In Canada, Bill C-8 made the Critical Cyber Systems Protection Act law in June 2026, with supply-chain obligations now phasing in.

None of this converges into one clean rule which is exactly why an inventory built only on what developers chose to declare is so fragile to defend, whichever side of the border you’re on.

Clarity AIR joins Insignary Clarity, the company’s binary-level software composition analysis platform, and Clarity SC, its SBOM governance platform, in the Insignary Clarity suite giving security and compliance teams coverage from source code through compiled binaries to SBOM lifecycle management.

Availability

Clarity AIR is available now directly from Insignary and through its partner channel, deployed on customer-owned infrastructure.

Trial licenses are available on request at insignary.com. A free, easy-to-use demo of the AI code detection capability is also available at insignary.com for anyone to try.

About Insignary

Insignary Inc. is a Toronto-based software supply chain security company. Its patented binary fingerprint technology lets enterprises, government agencies, and software vendors verify what’s actually inside the software they build, ship, and deploy directly from compiled binaries, without needing source code.

Insignary has been cited in four Gartner research reports and named a Sample Vendor for Reachability Analysis in the Gartner Hype Cycle for Secure Software Engineering, 2026.

The company is supported by strategic partners including BearingPoint in Europe; Cybertrust Japan and TechMatrix in Japan; and TMA Solutions.

Contact

Principal Solutions Architect

Jessica DY Lee

Insignary Inc.

jessicalee@insignary.com

CyberNewswire

A PR Newswire Syndication Platform for Cybersecurity Companies

Recent Posts

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

3 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

3 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

4 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

5 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…

5 hours ago