Toronto, Canada, October 8th, 2026, CyberNewswire
Insignary Introduces Clarity AIR: Eliminating the Blind Spot Between Developer Declarations and Actual Code Contents
A fresh approach to snippet-level scanning provides compliance and security leadership with visibility into undeclared open-source elements and AI-generated code missing from standard manifests.
Insignary Inc. has rolled out the general availability of Insignary Clarity AIR, a source-code analysis tool designed to address a persistent challenge for security teams: identifying what is genuinely executing within their software beyond developer-reported details.
Standard Software Bill of Materials (SBOMs) and manifests relying on declared dependencies are limited by what developers actively choose to submit. Because roughly 70 to 90 percent of modern applications incorporate open-source code, a substantial portion enters through unmonitored channels—such as functions copied across projects, snippets taken from forums, or AI-assisted blocks integrated without line-by-line review. For legal departments validating license terms or CISOs approving an SBOM, these omissions represent unmonitored vulnerabilities hidden inside compliance documentation.
Clarity AIR operates at the source-code level rather than relying on standard manifests to address this exposure:
It uncovers unlisted open source, cross-referencing source code against the extensive fingerprint database maintained by Insignary. This system identifies dependencies even when they have been modified, restructured, or re-created by AI tools.
It quantifies AI-authored contributions within the codebase, evaluating code line by line and assigning confidence metrics so legal, security, and engineering teams can treat AI outputs as a distinct risk category rather than an unmonitored variable.
It maps the integrated AI ecosystem, tracking frameworks, models, and APIs embedded directly within the application to generate an AI Bill of Materials alongside traditional open-source records.
Every potential match undergoes manual review and confirmation prior to final tabulation, and outputs can be exported as complete audit files and formatted SBOMs.
“You cannot verify an SBOM by reading the manifest that created it. AI-written code is the same problem. If a developer does not declare it, nothing records it. You have to look at the code itself,” stated Taek Wan Kim, President & CEO of Insignary.
Current Compliance Context
Regulatory timelines across North America have recently tightened for CISOs, introducing complexity through divergent regional rules. In the United States, updated OMB guidelines from January 2026 (Memorandum M-26-05) guide federal agencies toward independent verification of vendor SBOM submissions rather than relying solely on standard attestation forms, while FDA Section 524B maintains mandatory compliance for medical cyber device entries. Meanwhile, Canadian legislation brought the Critical Cyber Systems Protection Act into effect via Bill C-8 in June 2026, initiating supply-chain mandates. Because these frameworks do not unify into a single standard, inventories based strictly on developer declarations remain vulnerable on either side of the border.
Clarity AIR integrates into the broader Insignary Clarity portfolio, joining the company’s binary software composition analysis solution (Insignary Clarity) and its SBOM governance platform (Clarity SC). Together, these tools provide teams with end-to-end visibility stretching from source code to compiled binaries and ongoing SBOM lifecycle oversight.
Availability
Clarity AIR is currently distributed directly through Insignary and its partner network, with deployment supported on customer-managed infrastructure. Trial licenses are accessible via request at insignary.com, where a complimentary online demonstration of the AI code detection features is also hosted for public evaluation.
About Insignary
Insignary Inc. operates as a software supply chain security provider headquartered in Toronto. Utilizing patented binary fingerprinting methodologies, the enterprise assists businesses, software vendors, and government bodies in auditing the internal components of deployed and distributed software directly through compiled binaries without requiring source code access. Recognized in four Gartner research publications, Insignary was designated a Sample Vendor for Reachability Analysis in the 2026 Gartner Hype Cycle for Secure Software Engineering. The firm collaborates with key strategic partners including TechMatrix and Cybertrust Japan in Japan, BearingPoint throughout Europe, and TMA Solutions.
Contact
Principal Solutions Architect
Jessica DY Lee
Insignary Inc.
jessicalee@insignary.com




