Mend AI
(24-August-2026) commercialMend AI is a software composition analysis tool that identifies and manages security vulnerabilities and open source compliance issues in code dependencies.
Summary
Mend AI is a commercial ai-security platform that provides unified security for application and AI risk. It is offered under a paid license and runs as a service. This tool is intended for developers integrating AI into applications, and its documentation positions it alongside tools addressing application security gaps. It has seen two releases in the tracked window, with the most recent one occurring 13 days ago.
Mend AI is a software composition analysis tool that identifies and manages security vulnerabilities and open source compliance issues in code dependencies.
What Mend AI answers
What types of security risks does it assess?
it provides unified security for application and AI risk
What security gaps does it cover?
it addresses the gap between traditional application security and standalone AI security tools
Can it work with existing codebases?
it is intended for developers integrating AI into applications
Does it provide security testing for LLMs?
it provides security for AI risk, including llm-security
What is its licensing model?
it is offered under a paid license
Where does its functionality lie?
it runs as a service
Release history
- docs update
- ›Introduces the AI Bill of Materials (
AI-BOM) report, available through the Mend Platform reporting interface and API, generating a full inventory of detected AI entities — models, system prompts, agent configurations, tools, and agents — scoped to organization, application, or project level. - ›Exports AI-BOM data in industry-standard
CycloneDX 1.7andSPDX 3.0.1formats, with metadata-only exports to preserve data privacy.
- ›Introduces the AI Bill of Materials (
- docs update
Mend AI 26.8.1 adds account-level global workflows with API support and a redesigned Administration sidebar.
- ›Introduces Account-Level (Global) Workflows, letting administrators define workflows centrally and propagate them to selected organizations, with controls over whether org-level admins can enable or disable them locally.
- ›Adds comprehensive API support for managing global workflows.
- ›Updates the Administration page sidebar with a categorized, collapsible navigation structure, adding a dedicated 'AI Usage' tab under a new AI category and sub-headers for AI, Code, and Dependencies in Engine Settings.
└──▷ BREAKING ON UPGRADE- !AI Usage settings have been moved from the General tab to a dedicated 'AI Usage' tab under the new AI category in the Administration page sidebar.
- docs update
Mend Renovate 44.41.x adds cursor pagination for GitHub HTTP and a new
overrideDescriptionconfig option.- ›Adds
overrideDescriptionoption to Renovate config (v44.41.0). - ›Adds cursor pagination support for GitHub HTTP requests (v44.41.1).
- ›Adds
- docs update
Mend Container 26.8.1 adds Chainguard support to hardened image detection, including VEX status and branding in the UI.
- ›Adds Chainguard as a supported vendor in Mend Container's hardened image detection, incorporating Chainguard-specific vulnerability data, VEX information, and detection of Chainguard image layers and base images.
- ›Surfaces Chainguard VEX status and branding directly in the risk factors columns across the UI for Chainguard-based images and findings.
- (24-August-2026)
Mend AI adds an AI Bill of Materials (AI-BOM) report in CycloneDX 1.7 and SPDX 3.0.1 formats via UI and API.
└──▷ HOW TO FIND ITGenerate an AI-BOM report for your organization's AI footprint via the Mend Platform reporting UI.📍In the Mend Platform, go to Reports › AI Bill of Materials (AI-BOM), select the desired scope (organization, application, or project), choose output format (CycloneDX 1.7 or SPDX 3.0.1), and export.- ›New AI Bill of Materials (AI-BOM) report available via the Mend Platform reporting interface and API, generating a metadata-only inventory of detected AI entities — models, system prompts, agent configurations, tools, and agents — scoped to organization, application, and project levels.
- ›AI-BOM exports support industry-standard CycloneDX 1.7 and SPDX 3.0.1 formats.
- (09-August-2026)
Mend AI adds framework-based agent discovery with a new dashboard, plus entity-level suppression with audit trail for AI inventory triage.
└──▷ HOW TO FIND ITAfter upgrading, navigate to the new agent dashboard to review discovered AI agents, their connected MCPs, and referenced system prompts across your projects.📍In the Mend AI platform, go to the AI Inventory section and select the new 'Agents' dashboard (beta) to view discovered agents, their connected tools and MCPs, and the models and system prompts they reference.- ›Adds framework-based agent discovery that detects AI agents and their connected tools and Model Context Protocols (MCPs) within projects, surfacing referenced models and system prompts.
- ›Introduces a dedicated agent dashboard and detailed agent views (currently in beta) for managing and securing the AI agent ecosystem.
- ›Adds entity-level suppression and review for AI entities — Models, System Prompts, Agent Configs, and Agents — with a status column tracking triage states (unreviewed, manually reviewed, or suppressed), bulk actions, and an audit trail that persists across scans.