Securing the agentic AI software supply chain

Gain foresight into introduced artifacts at generate-time.

Your favorite AI agents suggest artifacts for use. Aephix Sift provides cross-ecosystem intelligence on whether they are malicious or hallucinated, before any damage is done.

0%
of technologists now use coding agents at work
Stack Overflow
0%
of packages AI coding models suggest do not exist
USENIX Security
0%
of breaches now involve a third party
Verizon
Agents install faster than anyone reviews.
01
Your assistant picks the dependencies now

Much of the code shipping today was written by an assistant, and the import lines came with it. Nearly half of the dependency edits a coding agent makes introduce a package that was not there before.

02
It invents package names that do not exist

Close to one in five package names suggested across sixteen models did not exist at all. Two in five of those invented names came back on every rerun, which is what makes registering one worth an attacker's time.

03
Trusted packages are where compromise lands

A self-spreading npm compromise reached 25,000 GitHub repositories in December 2025. The packages a team already depends on are the ones worth poisoning, so one release of a good package can be the problem.

04
The download is the point of no return

By the time something is installed, the decision has already been made for you. Agents pick a known-vulnerable version more often than people do, so the moment that matters is the one before the download.

Three ways a package goes wrong.

Sift names which one before anything is downloaded.

Already known malicious

Caught the moment it is proposed, so it never reaches your machine.

  • Stopped before anything downloads
  • Every answer comes with its evidence
  • The same answer across every ecosystem you use
A package that was never real

Assistants invent names that sound right. Attackers register them and wait.

  • Invented names caught on the spot
  • No time lost chasing a package that does not exist
  • The trap is closed before anyone falls in
A near-copy of one you trust

A name a character away from something your team already relies on.

  • Look-alikes of the packages you actually use
  • Names borrowed from another ecosystem
  • Put in front of you while it still matters
It just works.

Sift integrates wherever your team installs, imports and builds, fitting right into your daily workflows.

Coding agents

The answer arrives while your agent can still change its mind.

Editors

Works with the AI coding tools your team already has open.

Command line

One command for a package you are adding yourself.

Continuous integration

The same answer on the machine that builds.

Plans.

Three tiers. Looking one package up by hand stays free at Aephix Vantage.

Individual
One developer
Team
Five seats and up
Organization
Procurement-led buyers
Known malicious, invented and look-alike names
Every surface your team works in
Answers you can act on
A record of what was proposed
Shared policy
One report across the team
Yesterday rechecked against today
Signed, timestamped evidence
Feeds your AI bill of materials
Single sign-on
Support
Community
Email
Shared channel, response target
Payment
Card
Card or invoice
Invoicing
Questions.
Pricing and billing
Is there a free option?

Yes. Looking a package up by hand stays free at Aephix Vantage. Sift is the automation of that, and every paid tier opens with a free trial.

Do I need a card to try it?

No. The trial runs without one, and it is time-limited rather than feature-limited, so you evaluate the real thing.

Is there a minimum term?

Individual and Team are monthly and cancel any time. Organization is an annual agreement.

What you get
What does it catch?

Packages already known malicious, names your assistant invented that were never real, and near-copies of packages your team already trusts.

Will it get in my way?

No. The packages you rely on keep working, and you hear from Sift when something is worth hearing about.

Does it slow my assistant down?

No. The answer is there before you would have noticed waiting for it.

Do I have to change how I work?

No. Sift meets your team in the tools already open, so the workflow you have today is the workflow you keep.

Privacy
Does my source code leave my machine?

No. Your code is yours. Sift never reads it, uploads it or indexes it.

Is what my team is building private?

Yes. Anything internal to your organisation stays internal, and your own record of what was checked stays on your machines.

Comprehensive intel on artifacts your AI agent introduces at generate-time.

Join the list. Tell us which coding assistant your team uses.