AIROM is an open-source AI Bill of Materials scanner, licensed Apache-2.0. That is a claim about verifiability, not just about price: an AIBOM is only worth as much as your ability to check it, and checking it means reading the thing that produced it.

What you can actually inspect

The scanner

The whole pipeline — sources, detectors, the assembler, every writer.

The rule packs

Detection for the fast-moving surface is YAML data, not Go. Read a rule, or write one.

The benchmark

A labelled corpus with published precision and recall, so detection quality is measured rather than asserted.

The honest ledger

What works, and what it deliberately does not do yet.

Why it matters for an inventory

Every component AIROM reports carries the detector that produced it. Because that detector is public, a finding you doubt is a finding you can trace:
The id you get back — rules/openai/model-literal, say — names a rule you can open and read. A scanner that cannot be inspected asks you to take its inventory on trust; this one does not.

Running it entirely offline

A scan never reaches the network. Two features do, and both are optional and explicit: the CVE overlay queries OSV.dev, and airom rules update fetches a signed rule bundle. Use --offline to refuse both.
The rule-update channel is signed with ed25519 and verified against a key compiled into the binary. See Rule updates.