AI TRANSPARENCY
AI augments — it does not replace — security expertise.
ScanexAI uses AI to translate technical findings into clear, actionable language. Vulnerability detection itself is entirely rule-based and deterministic.
ScanexAI uses artificial intelligence to make security findings easier to understand and act on. After the rule-based scanner finishes analysing a target, the AI receives a structured summary of what was found and produces a plain-English breach narrative. This narrative explains how the detected vulnerabilities could be chained together by a real attacker, and which issues should be addressed first.
It is important to understand what the AI does and does not do. The AI does not discover vulnerabilities. It does not send requests to your website or make any judgements about your code. Its only job is to take the structured output from the deterministic scanner and present it in a way that is readable by developers, managers, and auditors who may not have a deep security background.
We have chosen to be transparent about how AI is used in this platform because we believe users deserve to know when they are reading AI-generated content. Every AI-produced narrative is clearly labelled as such within the dashboard and in exported PDF reports. We encourage all users to treat AI output as a starting point for conversation, not a final authority.
ScanexAI uses Llama 3 (via Groq) for generating executive breach narratives and remediation priorities
Vulnerability detection is rule-based - AI is not used to identify vulnerabilities; it only narrates and prioritises findings
No proprietary or fine-tuned models are used; all AI calls go to Groq's hosted inference API
Model selection may be updated to newer or more capable models as they become available
After the rule-based scanner completes, AI receives a structured JSON summary of findings
AI generates a plain-English breach narrative explaining how an attacker could chain vulnerabilities
AI produces ranked remediation recommendations ordered by exploitability and impact
The AI narrative is clearly labelled in reports and is supplementary - not the primary security assessment
Only structured scan metadata is sent: vulnerability types, CVSS scores, attack chain nodes, and the target URL
No raw page content, user data, credentials, or personal information is transmitted to the AI provider
Prompts are constructed server-side and are not editable by end users to prevent prompt injection
AI provider data retention policies apply - refer to Groq's privacy policy for details
AI-generated narratives may contain inaccuracies or hallucinations - always verify findings with manual testing
The breach narrative does not constitute legal or professional security advice
AI outputs should be reviewed by a qualified security professional before being acted upon in production
ScanexAI's AI features are intended to assist communication of risk, not replace expert judgement
All AI outputs are clearly marked as AI-generated within the platform and PDF reports
Users retain full responsibility for decisions made based on AI-generated content
ScanexAI reviews AI feature behaviour periodically and may update prompts to improve accuracy
If you encounter a materially incorrect AI narrative, please report it via our support channel
Effective date: 1 June 2025