
What it finds
| Type | Examples |
|---|---|
| LLM Provider | Direct imports or API calls to OpenAI, Anthropic, Google, Mistral, etc. |
| AI Service | External AI services (moderation APIs, speech-to-text, image gen). |
| SDK Dependency | AI-related packages in package.json, requirements.txt, etc. |
| MCP Tool | Registered MCP servers and tools. |
| Gateway Config | Guardway or other AI-gateway configuration files. |
How it works
Connect GitHub
In Settings → Integrations, add a GitHub Personal Access Token with
repo and read:org scopes. See Integrations.Scan a repository
Guardway analyzes the repo’s manifests and code, detects AI dependencies, and stores the result as a set of findings.
Review the findings
Drill into any repo to see tabs for LLM Providers, AI Services, SDKs, MCPs, and Gateways; check the MCP security score; review SCA vulnerabilities.
Where to next
Organizations
Sync orgs, scan repos, filter by status.
Findings
Drill into a repository, see the findings tabs, security scans, and AIBOM export.