Detection over declaration. AI SDKs, model files and API keys, found, matched against known models, documented in an AI-BOM with provenance and licence. Like a model checkpoint in the repo.
Every cryptographic algorithm in your estate, inventoried, with flags on what won't survive the post-quantum transition. Like RSA-2048 in a signing path. Earnie keeps the inventory standing.
Components, licences, obligations, down to the snippet someone pasted. Attribution and notice files generated, SBOMs versioned and retrievable. Like the GPL snippet in a proprietary module.
Known vulnerabilities in what you actually ship, found where they live, tied to remediation at AI speed. Like a vulnerable parser three levels deep. The fix arrives with the finding.
Earnie's findings are deterministic, built on hard, reliable data, not probabilistic guesswork. The same code produces the same result, every time. That's what makes the record defensible.
What Earnie is, what it checks, and how the record holds up when someone asks for it. Bring your hardest question about agent-written code.