docs: name the editions Shannon, Pro, Enterprise and Community Program

Drop "Shannon Open Source" and "the Keygraph platform" as product names.
The open-source project is Shannon (Shannon OSS where a contrast helps),
and the commercial editions are Keygraph Pro and Keygraph Enterprise, plus
the Community Program. The one retired-names line now maps Shannon Lite to
Shannon and Shannon Pro to Keygraph Pro. Also covers the npm README, the
coverage and safety docs, llms.txt and the regenerated llms-full.txt.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
george-keygraphandClaude Opus 5.5 committed 2026-10-07 10:32:40 -07:00
1 parent f5054dc885
commit 5d961820b3
7 files changed
+86 -86

No files matched your search

+15 -15
View File
@@ -15,7 +15,7 @@
It analyzes your source code, identifies attack paths, and executes real exploits to prove vulnerabilities before they reach production. **No exploit, no report.**
**This repository is Shannon Open Source: the full agent, run locally from your command line.**
**This repository is Shannon: the full open-source agent, run locally from your command line.**
<p><strong>Launch Shannon</strong></p>
@@ -76,7 +76,7 @@ Shannon is an autonomous AI pentester developed by [Keygraph](https://keygraph.i
Shannon analyzes your web application's source code to identify potential attack vectors, then uses browser automation and command-line tools to execute real exploits against the running application and its APIs. Only vulnerabilities with a working proof-of-concept are included in the final report.
Shannon is the agent. This repository is Shannon Open Source, the standalone pentester you run yourself. The same Shannon also powers the [Keygraph platform](https://keygraph.io), Keygraph's commercial pentesting product. See [Editions](#editions) for how Shannon Open Source compares with the platform's Community Program, Pro, and Enterprise editions.
Shannon is the agent. This repository is Shannon, the open-source pentester you run yourself. The same Shannon also powers Keygraph's commercial editions, [Pro and Enterprise](https://keygraph.io/pricing). See [Editions](#editions) for how Shannon compares with Pro, Enterprise, and the Community Program.
<a id="why-shannon-exists"></a>
<details>
@@ -114,7 +114,7 @@ Shannon shifts pentesting left into the software development lifecycle (SDLC). U
![Shannon running an autonomous pentest](assets/Shannon3GIF.gif)
These reports are from Shannon Open Source scans of Photoview 2.4.0, one of the applications in Doyensec's comparison of Aikido and XBOW. We ran Shannon against the same application version and evaluated its results separately. Read the [Doyensec study](https://doyensec.com/resources/ComparingAIApplicationSecurityTestingPlatforms_Doyensec.pdf) and our [Shannon follow-up comparison](docs/shannon-xbow-aikido-benchmark.md) for the methodology, limitations, costs, and results.
These reports are from Shannon OSS scans of Photoview 2.4.0, one of the applications in Doyensec's comparison of Aikido and XBOW. We ran Shannon against the same application version and evaluated its results separately. Read the [Doyensec study](https://doyensec.com/resources/ComparingAIApplicationSecurityTestingPlatforms_Doyensec.pdf) and our [Shannon follow-up comparison](docs/shannon-xbow-aikido-benchmark.md) for the methodology, limitations, costs, and results.
| Model | Report | SARIF |
@@ -235,18 +235,18 @@ See the [Shannon GitHub Action documentation](https://github.com/KeygraphHQ/shan
## Editions
Shannon Lite is now Shannon Open Source. Shannon Pro is now the Keygraph platform.
Shannon Lite is now just Shannon. Shannon Pro is now Keygraph Pro.
| Edition | What it is | Price |
| --- | --- | --- |
| **Shannon Open Source** (Shannon OSS) | This repository. A complete autonomous pentester you run yourself, locally or in CI/CD, against an application whose source code you have. Well suited to individual developers and small teams. | Open source under AGPL-3.0. You pay only your own model costs. |
| **Community Program** | The full Keygraph platform, cloud-hosted, for U.S.-based 501(c)(3) nonprofits and for seed or pre-Series-A startups with 20 or fewer active developers. | $0 in cloud service fees while you qualify. |
| **Pro** | The full Keygraph platform, cloud-hosted and managed by Keygraph, with every module included. | $50 per active developer per month. |
| **Shannon** (open source) | This repository. A complete autonomous pentester you run yourself, locally or in CI/CD, against an application whose source code you have. Well suited to individual developers and small teams. | Open source under AGPL-3.0. You pay only your own model costs. |
| **Community Program** | Keygraph Pro at no cost, for U.S.-based 501(c)(3) nonprofits and for seed or pre-Series-A startups with 20 or fewer active developers. | $0 in cloud service fees while you qualify. |
| **Pro** | Keygraph's cloud-hosted edition, managed by Keygraph, with every module included. | $50 per active developer per month. |
| **Enterprise** | Everything in Pro, self-hosted in your own environment or fully air-gapped. | Custom. |
See [keygraph.io/pricing](https://keygraph.io/pricing) for current prices and the full feature table.
The **Keygraph platform** runs an enterprise-hardened fork of Shannon. The Community Program, Pro, and Enterprise all add:
**Pro**, **Enterprise**, and the **Community Program** run an enterprise-hardened fork of Shannon, and all three add:
- **Black-box pentesting**: tests the running application from the outside, with no source code needed.
- **Dependency (SCA) and secret checks**: SCA with reachability, and secrets scanning that includes repository history.
@@ -256,7 +256,7 @@ The **Keygraph platform** runs an enterprise-hardened fork of Shannon. The Commu
No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbox-pentester).
[Learn about the Keygraph platform and compare editions →](docs/keygraph-platform.md)
[Compare Shannon, Pro, and Enterprise in detail →](docs/keygraph-platform.md)
## Architecture
@@ -308,7 +308,7 @@ Use these guides for operational detail:
| [Workspaces and resuming](docs/workspaces.md) | Naming workspaces, resuming interrupted scans, and workspace storage. |
| [Safety and limitations](docs/safety.md) | Authorized-use requirements, non-production guidance, mutative effects, cost, and model caveats. |
| [Coverage and roadmap](docs/coverage-roadmap.md) | Current vulnerability coverage and planned work. |
| [Keygraph platform](docs/keygraph-platform.md) | Shannon Open Source compared with the Community Program, Pro, and Enterprise editions: black-box pentesting, SCA and secrets, findings management, fix pull requests, retests, Jira, and deployment. |
| [Pro and Enterprise](docs/keygraph-platform.md) | Shannon compared with Pro, Enterprise, and the Community Program: black-box pentesting, SCA and secrets, findings management, fix pull requests, retests, Jira, and deployment. |
@@ -321,7 +321,7 @@ You are responsible for using Shannon legally and ethically. Do not point Shanno
Important limitations:
- Shannon Open Source is tuned for fast, code-informed pentesting in everyday development and CI/CD. Exhaustive agentic SAST, broader scanner coverage, centralized governance, and full-lifecycle vulnerability management are delivered through the Keygraph platform, in its Community Program, Pro, and Enterprise editions.
- Shannon is tuned for fast, code-informed pentesting in everyday development and CI/CD. Exhaustive agentic SAST, broader scanner coverage, centralized governance, and full-lifecycle vulnerability management are delivered through Pro, Enterprise, and the Community Program.
- Findings still require human review. LLM-generated reports can contain weakly supported or incorrect details.
- Anthropic, OpenAI, xAI, and AWS Bedrock are built-in providers, and any other provider in the harness catalogue works too — each reachable through a custom base URL that points it at a proxy or LLM gateway. Model capability varies, and a model that does not follow Shannon's instructions or tool-use constraints reliably will produce weaker results.
- A full run can take roughly 1 to 1.5 hours and may incur LLM API costs depending on model pricing and application complexity.
@@ -331,9 +331,9 @@ Read the full [Safety and limitations](docs/safety.md) guide before running Shan
## License
Shannon Open Source is licensed under the [GNU Affero General Public License v3.0](LICENSE).
Shannon is licensed under the [GNU Affero General Public License v3.0](LICENSE).
Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including the Keygraph platform.
Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including Keygraph Pro and Enterprise.
For commercial licensing, contact [shannon@keygraph.io](mailto:shannon@keygraph.io).
@@ -347,7 +347,7 @@ See [THIRD_PARTY_NOTICES.md](./THIRD_PARTY_NOTICES.md) for licensing and attribu
## About Keygraph
**Keygraph** is the company behind Shannon. It also builds the **Keygraph platform**, the commercial agentic pentesting product that closes the full AppSec lifecycle and runs an enhanced build of Shannon as its pentesting engine.
**Keygraph** is the company behind Shannon. It also builds **Keygraph Pro** and **Keygraph Enterprise**, the commercial editions that close the full AppSec lifecycle and run an enhanced build of Shannon as their pentesting engine.
## Community and Support
@@ -378,7 +378,7 @@ Stay connected:
### Can I self-host Shannon?
Yes. Shannon Open Source runs inside your infrastructure in an ephemeral worker container. It mounts the repository read-only and writes results to a local workspace.
Yes. Shannon runs inside your infrastructure in an ephemeral worker container. It mounts the repository read-only and writes results to a local workspace.
Keygraph never receives your source code and never proxies your model traffic. Your model requests go straight to the provider or endpoint you configure, and they carry source and application context with them. Point Shannon at a locally hosted endpoint and that traffic stays inside your environment too.
+4 -4
View File
@@ -6,7 +6,7 @@
It analyzes your source code, identifies attack paths, and executes real exploits to prove vulnerabilities before they reach production.
**This package is Shannon Open Source: the full agent, run locally from your command line.**
**This package is Shannon: the full open-source agent, run locally from your command line.**
---
@@ -41,7 +41,7 @@ Shannon pulls the worker image from Docker Hub, starts the required local infras
## Editions
Shannon ships in two ways. **Shannon Open Source** is this package: the standalone pentester you run yourself, on demand, and complete in that lane. The **Keygraph platform** is the commercial product that runs an enhanced build of Shannon continuously and closes the full AppSec lifecycle around it - code analysis, finding management, automated remediation, verification, and enterprise deployment.
**Shannon** is this package: the open-source pentester you run yourself, on demand, and complete in that lane. **Keygraph Pro** and **Keygraph Enterprise** are the commercial editions. They run an enhanced build of Shannon continuously and close the full AppSec lifecycle around it: code analysis, finding management, automated remediation, verification, and enterprise deployment. The **Community Program** offers Pro at no cost to organizations that qualify. See [keygraph.io/pricing](https://keygraph.io/pricing).
## Documentation
@@ -49,9 +49,9 @@ Shannon ships in two ways. **Shannon Open Source** is this package: the standalo
## License
Shannon Open Source is licensed under the [GNU Affero General Public License v3.0](https://github.com/KeygraphHQ/shannon/blob/main/LICENSE).
Shannon is licensed under the [GNU Affero General Public License v3.0](https://github.com/KeygraphHQ/shannon/blob/main/LICENSE).
Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including the Keygraph platform.
Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including Keygraph Pro and Enterprise.
For commercial licensing, contact [shannon@keygraph.io](mailto:shannon@keygraph.io).
+1 -1
View File
@@ -20,4 +20,4 @@ This reduces speculative noise, but it also means Shannon does not aim to report
Planned coverage areas should continue to live in the repository's canonical roadmap document if one exists. The README should link to that document rather than carrying detailed roadmap history inline.
For organizations that need broader static and organizational coverage now, see [the Keygraph platform](keygraph-platform.md).
For organizations that need broader static and organizational coverage now, see [Keygraph Pro and Enterprise](keygraph-platform.md).
+22 -22
View File
@@ -1,26 +1,26 @@
# Keygraph Platform
# Keygraph Pro and Enterprise
Shannon Lite is now Shannon Open Source. Shannon Pro is now the Keygraph platform.
Shannon Lite is now just Shannon. Shannon Pro is now Keygraph Pro.
Shannon 3.0 is an open-source pentester. It reads your source, maps routes and data flows, runs real attacks against a live target, and writes PDF and SARIF reports. It runs locally, in CI, or air-gapped with your own model. Shannon Open Source is a complete pentester, not a trial edition.
Shannon 3.0 is an open-source pentester. It reads your source, maps routes and data flows, runs real attacks against a live target, and writes PDF and SARIF reports. It runs locally, in CI, or air-gapped with your own model. Shannon is a complete pentester, not a trial edition.
The Keygraph platform is Keygraph's commercial product. It runs an enterprise-hardened fork of Shannon continuously across hundreds of repositories and adds what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. It is for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify.
Pro and Enterprise are Keygraph's commercial editions. They run an enterprise-hardened fork of Shannon continuously across hundreds of repositories and add what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. They are for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify.
The Keygraph platform comes in three editions: the Community Program, Pro, and Enterprise. Every module is included in all three. They differ in price, eligibility, hosting, and support. Current prices and the full feature table are at [keygraph.io/pricing](https://keygraph.io/pricing).
The Community Program is Pro at no cost for organizations that qualify. Every module is included in Pro, Enterprise, and the Community Program. They differ in price, eligibility, hosting, and support. Current prices and the full feature table are at [keygraph.io/pricing](https://keygraph.io/pricing).
Every edition is BYOK: you bring your own model key and pay your provider directly. Shannon Open Source runs from your machine or CI runner, and Keygraph never receives your source or proxies your model traffic. The Community Program and Pro are cloud-hosted and managed by Keygraph. Enterprise deploys inside your cloud or data center, including fully air-gapped.
Every edition is BYOK: you bring your own model key and pay your provider directly. Shannon runs from your machine or CI runner, and Keygraph never receives your source or proxies your model traffic. The Community Program and Pro are cloud-hosted and managed by Keygraph. Enterprise deploys inside your cloud or data center, including fully air-gapped.
No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbox-pentester).
## Compare editions
| | Shannon Open Source | Community Program | Pro | Enterprise |
| | Shannon (open source) | Community Program | Pro | Enterprise |
| --- | --- | --- | --- | --- |
| Price | Open source under AGPL-3.0. You pay only your own model costs | $0 in cloud service fees while you qualify. You pay only your own AI provider usage | $50 per active developer per month, every module included, no add-ons | Custom |
| Best for | Developers and teams running repository-level pentests locally or in CI | U.S.-based 501(c)(3) nonprofits, and seed or pre-Series-A startups with 20 or fewer active developers | Teams that want the full Keygraph platform, cloud-hosted and managed by Keygraph | Security organizations running continuous AppSec across many teams and repositories that need the platform inside their own environment |
| Best for | Developers and teams running repository-level pentests locally or in CI | U.S.-based 501(c)(3) nonprofits, and seed or pre-Series-A startups with 20 or fewer active developers | Teams that want every module, cloud-hosted and managed by Keygraph | Security organizations running continuous AppSec across many teams and repositories that need it inside their own environment |
| Code analysis | Agent pass over architecture, entry points, and data flows to seed the pentest, plus optional multi-stage security code analysis, sized to finish inside a CI run | Same as Pro | Persistent code property graph plus a long-running analysis harness with interprocedural taint, sanitizer modeling, cross-repo context, exploit chains, and multi-pass review | Same as Pro |
| White-box pentesting | On-demand, source-aware white-box pentesting with optional authenticated testing, focused on injection, XSS, SSRF, broken authentication, and broken authorization, with proof by exploitation | Same as Pro | Enterprise-hardened Shannon fork run continuously against white-box and grey-box targets, with proof by exploitation | Same as Pro |
| Black-box pentesting (no source code) | Not included. Shannon Open Source needs the target's source code | Same as Pro | Agents attack the running application from the outside with no source access, with up to 4 login credentials for multi-role testing. Findings are validated with working exploits | Same as Pro |
| Black-box pentesting (no source code) | Not included. Shannon needs the target's source code | Same as Pro | Agents attack the running application from the outside with no source access, with up to 4 login credentials for multi-role testing. Findings are validated with working exploits | Same as Pro |
| SCA and secrets | Not included | Same as Pro | SCA with reachability and secrets scanning, including repository history | Same as Pro |
| Findings management | Per-run PDF, Markdown, JSON, and SARIF 2.1.0, with SARIF upload to GitHub code scanning | Same as Pro | One record per vulnerability per repository across scans and scanners, with status history, auto-reopen, ownership, SLAs, dashboards, and audit evidence | Same as Pro |
| Fix pull requests and retests | Fix manually from the report, then re-run the scan to verify | Same as Pro | Fix pull requests for a developer to review and apply, verified by re-analysis and exploit replay without a full rescan | Same as Pro |
@@ -32,11 +32,11 @@ No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbo
### What Pro includes
Pro is the full Keygraph platform, cloud-hosted and managed by Keygraph, at $50 per active developer per month. Every module is included, with unlimited repositories and scans under BYOK. That covers white-box and black-box pentesting, agentic SAST, SCA, secrets scanning, findings management with status history, retests (fix verification by re-analysis and exploit replay), fix pull requests, two-way Jira sync, and SSO, RBAC, and audit logs.
Pro is cloud-hosted and managed by Keygraph, at $50 per active developer per month. Every module is included, with unlimited repositories and scans under BYOK. That covers white-box and black-box pentesting, agentic SAST, SCA, secrets scanning, findings management with status history, retests (fix verification by re-analysis and exploit replay), fix pull requests, two-way Jira sync, and SSO, RBAC, and audit logs.
None of these require Enterprise. Enterprise adds self-hosted or fully air-gapped deployment, a dedicated engineer and white-glove onboarding, and a custom SLA and security patch SLA.
The Community Program is the same managed Pro platform, with every module included, at $0 in cloud service fees for organizations that qualify. It is cloud-hosted only. See the [Community Program](https://keygraph.io/community-program) for eligibility and how to apply.
The Community Program is Pro, with every module included, at $0 in cloud service fees for organizations that qualify. It is cloud-hosted only. See the [Community Program](https://keygraph.io/community-program) for eligibility and how to apply.
## How it fits your pipeline
@@ -50,9 +50,9 @@ The Community Program is the same managed Pro platform, with every module includ
### Static analysis on a code property graph
Shannon Open Source's code analysis is sized to finish inside a CI run: agents read the repository, map the attack surface, and hand candidates to the pentester. The Keygraph platform is built for depth instead. It first parses each repository into a persistent code property graph, then runs an analysis harness derived from one built for long-running vulnerability audits, heavily adapted to query the graph rather than read files. The harness decomposes the application into risk, taint-flow, framework, and specialist tasks and supports longer-running audit workflows beyond typical CI job windows.
Shannon's code analysis is sized to finish inside a CI run: agents read the repository, map the attack surface, and hand candidates to the pentester. Pro and Enterprise are built for depth instead. They first parse each repository into a persistent code property graph, then run an analysis harness derived from one built for long-running vulnerability audits, heavily adapted to query the graph rather than read files. The harness decomposes the application into risk, taint-flow, framework, and specialist tasks and supports longer-running audit workflows beyond typical CI job windows.
On the graph, it performs:
On the graph, they perform:
- Interprocedural taint tracking across functions, files, fields, containers, and framework request lifecycles.
- Source, sink, and sanitizer modeling that records where validation, encoding, or authorization changes a path.
@@ -62,30 +62,30 @@ On the graph, it performs:
### Business-logic invariants
Shannon Open Source focuses on injection, XSS, SSRF, and broken authentication and authorization. The Keygraph platform adds testing for the bugs that do not fit a vulnerability class: it derives invariants the application is supposed to hold (tenant isolation, workflow ordering, approval limits, balance conservation, state transitions) and tests them against the running application. This is where application-specific vulnerabilities live and where pattern-based SAST often provides little or no signal.
Shannon focuses on injection, XSS, SSRF, and broken authentication and authorization. Pro and Enterprise add testing for the bugs that do not fit a vulnerability class: they derive invariants the application is supposed to hold (tenant isolation, workflow ordering, approval limits, balance conservation, state transitions) and test them against the running application. This is where application-specific vulnerabilities live and where pattern-based SAST often provides little or no signal.
### Proof by exploitation
The pentesting engine is a hardened fork of Shannon with the same rule: a pentest finding requires a working exploit. No exploit, no finding. The platform stores the exploit and replays it later to verify the fix.
The pentesting engine is a hardened fork of Shannon with the same rule: a pentest finding requires a working exploit. No exploit, no finding. Pro and Enterprise store the exploit and replay it later to verify the fix.
The Blackbox Pentester applies the same rule without source access. It attacks the running application from the outside with a real browser and terminal, and it can take up to 4 login credentials (Google OAuth, GitHub, or custom auth) to test privilege escalation and IDOR across roles.
SCA prioritizes vulnerable dependencies that application code actually reaches. Secrets scanning covers current source and repository history.
<p align="center">
<img src="../assets/keygraph-platform/agentic-sast-results.png" alt="Keygraph platform findings grouped into business-logic issues, point issues, and secrets" width="100%">
<img src="../assets/keygraph-platform/agentic-sast-results.png" alt="Keygraph Pro findings grouped into business-logic issues, point issues, and secrets" width="100%">
</p>
## Findings
Shannon Open Source hands you a report per scan. The Keygraph platform dedupes across runs and across scanners, deterministically and semantically, into one record per vulnerability per repository. Each record carries evidence, source location, severity, scan history, status, owner, resolution, and last-verified state. This is included in the Community Program, Pro, and Enterprise.
Shannon hands you a report per scan. Pro and Enterprise dedupe across runs and across scanners, deterministically and semantically, into one record per vulnerability per repository. Each record carries evidence, source location, severity, scan history, status, owner, resolution, and last-verified state. This is included in the Community Program, Pro, and Enterprise.
Workflows cover assignment, triage, false-positive and risk-acceptance decisions, and SLA policies with escalation and aging. A resolved finding that reappears in a later scan reopens automatically. Dashboards report open risk, coverage, new versus resolved, SLA compliance, and MTTR, exportable as evidence for customers and auditors. Findings sync both ways with Jira.
Findings still require human review. The platform's extra review passes reduce weakly supported findings, but they do not eliminate them.
Findings still require human review. The extra review passes in Pro and Enterprise reduce weakly supported findings, but they do not eliminate them.
<p align="center">
<img src="../assets/keygraph-platform/canonical-findings.png" alt="Keygraph platform findings inventory with severity, status, source, and verification filters" width="100%">
<img src="../assets/keygraph-platform/canonical-findings.png" alt="Keygraph Pro findings inventory with severity, status, source, and verification filters" width="100%">
</p>
### Fix and verify
@@ -93,13 +93,13 @@ Findings still require human review. The platform's extra review passes reduce w
From a finding, Keygraph generates a patch scoped to that finding and opens a pull request for a developer to review and apply. It never commits to a protected branch.
<p align="center">
<img src="../assets/keygraph-platform/automated-remediation.png" alt="Keygraph platform remediation workflow for generating a fix and opening a pull request" width="100%">
<img src="../assets/keygraph-platform/automated-remediation.png" alt="Keygraph Pro remediation workflow for generating a fix and opening a pull request" width="100%">
</p>
Verification re-analyzes the changed code and, for pentest findings, replays the original exploit against the patched target. The verdict comes from deterministic checks plus a review pass, without rerunning the full scan.
<p align="center">
<img src="../assets/keygraph-platform/targeted-verification.png" alt="Keygraph platform finding-verification workflow" width="100%">
<img src="../assets/keygraph-platform/targeted-verification.png" alt="Keygraph Pro finding-verification workflow" width="100%">
</p>
## Deployment and access control
@@ -113,7 +113,7 @@ Model access is BYOK and BYOM in every edition. Route workloads to Anthropic, Op
Access control, in the Community Program, Pro, and Enterprise: SAML/OIDC SSO, SCIM, roles with repository-scoped visibility (RBAC, plus attribute and relationship rules where needed), full audit log, scoped API keys.
<p align="center">
<img src="../assets/keygraph-platform/enterprise-access-control.png" alt="Keygraph platform roles and repository visibility controls" width="100%">
<img src="../assets/keygraph-platform/enterprise-access-control.png" alt="Keygraph Pro roles and repository visibility controls" width="100%">
</p>
Keygraph maintains a SOC 2 Type II audit. The report is available to customers under NDA.
+1 -1
View File
@@ -43,7 +43,7 @@ Shannon currently targets exploitable vulnerabilities in these classes:
Shannon's proof-by-exploitation model means it does not report issues it cannot actively exploit, such as many vulnerable dependency, insecure configuration, or broad policy findings.
For broader coverage, the Keygraph platform adds black-box and white-box agentic pentesting, graph-based static analysis, SCA reachability, secrets detection, business logic testing, remediation workflows, SLA tracking, and reporting dashboards.
For broader coverage, Keygraph Pro and Enterprise add black-box and white-box agentic pentesting, graph-based static analysis, SCA reachability, secrets detection, business logic testing, remediation workflows, SLA tracking, and reporting dashboards.
## Cost and Performance
+39 -39
View File
@@ -23,7 +23,7 @@
It analyzes your source code, identifies attack paths, and executes real exploits to prove vulnerabilities before they reach production. **No exploit, no report.**
**This repository is Shannon Open Source: the full agent, run locally from your command line.**
**This repository is Shannon: the full open-source agent, run locally from your command line.**
<p><strong>Launch Shannon</strong></p>
@@ -84,7 +84,7 @@ Shannon is an autonomous AI pentester developed by [Keygraph](https://keygraph.i
Shannon analyzes your web application's source code to identify potential attack vectors, then uses browser automation and command-line tools to execute real exploits against the running application and its APIs. Only vulnerabilities with a working proof-of-concept are included in the final report.
Shannon is the agent. This repository is Shannon Open Source, the standalone pentester you run yourself. The same Shannon also powers the [Keygraph platform](https://keygraph.io), Keygraph's commercial pentesting product. See [Editions](#editions) for how Shannon Open Source compares with the platform's Community Program, Pro, and Enterprise editions.
Shannon is the agent. This repository is Shannon, the open-source pentester you run yourself. The same Shannon also powers Keygraph's commercial editions, [Pro and Enterprise](https://keygraph.io/pricing). See [Editions](#editions) for how Shannon compares with Pro, Enterprise, and the Community Program.
<a id="why-shannon-exists"></a>
<details>
@@ -122,7 +122,7 @@ Shannon shifts pentesting left into the software development lifecycle (SDLC). U
![Shannon running an autonomous pentest](assets/Shannon3GIF.gif)
These reports are from Shannon Open Source scans of Photoview 2.4.0, one of the applications in Doyensec's comparison of Aikido and XBOW. We ran Shannon against the same application version and evaluated its results separately. Read the [Doyensec study](https://doyensec.com/resources/ComparingAIApplicationSecurityTestingPlatforms_Doyensec.pdf) and our [Shannon follow-up comparison](docs/shannon-xbow-aikido-benchmark.md) for the methodology, limitations, costs, and results.
These reports are from Shannon OSS scans of Photoview 2.4.0, one of the applications in Doyensec's comparison of Aikido and XBOW. We ran Shannon against the same application version and evaluated its results separately. Read the [Doyensec study](https://doyensec.com/resources/ComparingAIApplicationSecurityTestingPlatforms_Doyensec.pdf) and our [Shannon follow-up comparison](docs/shannon-xbow-aikido-benchmark.md) for the methodology, limitations, costs, and results.
| Model | Report | SARIF |
@@ -243,18 +243,18 @@ See the [Shannon GitHub Action documentation](https://github.com/KeygraphHQ/shan
## Editions
Shannon Lite is now Shannon Open Source. Shannon Pro is now the Keygraph platform.
Shannon Lite is now just Shannon. Shannon Pro is now Keygraph Pro.
| Edition | What it is | Price |
| --- | --- | --- |
| **Shannon Open Source** (Shannon OSS) | This repository. A complete autonomous pentester you run yourself, locally or in CI/CD, against an application whose source code you have. Well suited to individual developers and small teams. | Open source under AGPL-3.0. You pay only your own model costs. |
| **Community Program** | The full Keygraph platform, cloud-hosted, for U.S.-based 501(c)(3) nonprofits and for seed or pre-Series-A startups with 20 or fewer active developers. | $0 in cloud service fees while you qualify. |
| **Pro** | The full Keygraph platform, cloud-hosted and managed by Keygraph, with every module included. | $50 per active developer per month. |
| **Shannon** (open source) | This repository. A complete autonomous pentester you run yourself, locally or in CI/CD, against an application whose source code you have. Well suited to individual developers and small teams. | Open source under AGPL-3.0. You pay only your own model costs. |
| **Community Program** | Keygraph Pro at no cost, for U.S.-based 501(c)(3) nonprofits and for seed or pre-Series-A startups with 20 or fewer active developers. | $0 in cloud service fees while you qualify. |
| **Pro** | Keygraph's cloud-hosted edition, managed by Keygraph, with every module included. | $50 per active developer per month. |
| **Enterprise** | Everything in Pro, self-hosted in your own environment or fully air-gapped. | Custom. |
See [keygraph.io/pricing](https://keygraph.io/pricing) for current prices and the full feature table.
The **Keygraph platform** runs an enterprise-hardened fork of Shannon. The Community Program, Pro, and Enterprise all add:
**Pro**, **Enterprise**, and the **Community Program** run an enterprise-hardened fork of Shannon, and all three add:
- **Black-box pentesting**: tests the running application from the outside, with no source code needed.
- **Dependency (SCA) and secret checks**: SCA with reachability, and secrets scanning that includes repository history.
@@ -264,7 +264,7 @@ The **Keygraph platform** runs an enterprise-hardened fork of Shannon. The Commu
No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbox-pentester).
[Learn about the Keygraph platform and compare editions →](docs/keygraph-platform.md)
[Compare Shannon, Pro, and Enterprise in detail →](docs/keygraph-platform.md)
## Architecture
@@ -316,7 +316,7 @@ Use these guides for operational detail:
| [Workspaces and resuming](docs/workspaces.md) | Naming workspaces, resuming interrupted scans, and workspace storage. |
| [Safety and limitations](docs/safety.md) | Authorized-use requirements, non-production guidance, mutative effects, cost, and model caveats. |
| [Coverage and roadmap](docs/coverage-roadmap.md) | Current vulnerability coverage and planned work. |
| [Keygraph platform](docs/keygraph-platform.md) | Shannon Open Source compared with the Community Program, Pro, and Enterprise editions: black-box pentesting, SCA and secrets, findings management, fix pull requests, retests, Jira, and deployment. |
| [Pro and Enterprise](docs/keygraph-platform.md) | Shannon compared with Pro, Enterprise, and the Community Program: black-box pentesting, SCA and secrets, findings management, fix pull requests, retests, Jira, and deployment. |
@@ -329,7 +329,7 @@ You are responsible for using Shannon legally and ethically. Do not point Shanno
Important limitations:
- Shannon Open Source is tuned for fast, code-informed pentesting in everyday development and CI/CD. Exhaustive agentic SAST, broader scanner coverage, centralized governance, and full-lifecycle vulnerability management are delivered through the Keygraph platform, in its Community Program, Pro, and Enterprise editions.
- Shannon is tuned for fast, code-informed pentesting in everyday development and CI/CD. Exhaustive agentic SAST, broader scanner coverage, centralized governance, and full-lifecycle vulnerability management are delivered through Pro, Enterprise, and the Community Program.
- Findings still require human review. LLM-generated reports can contain weakly supported or incorrect details.
- Anthropic, OpenAI, xAI, and AWS Bedrock are built-in providers, and any other provider in the harness catalogue works too — each reachable through a custom base URL that points it at a proxy or LLM gateway. Model capability varies, and a model that does not follow Shannon's instructions or tool-use constraints reliably will produce weaker results.
- A full run can take roughly 1 to 1.5 hours and may incur LLM API costs depending on model pricing and application complexity.
@@ -339,9 +339,9 @@ Read the full [Safety and limitations](docs/safety.md) guide before running Shan
## License
Shannon Open Source is licensed under the [GNU Affero General Public License v3.0](LICENSE).
Shannon is licensed under the [GNU Affero General Public License v3.0](LICENSE).
Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including the Keygraph platform.
Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including Keygraph Pro and Enterprise.
For commercial licensing, contact [shannon@keygraph.io](mailto:shannon@keygraph.io).
@@ -355,7 +355,7 @@ See [THIRD_PARTY_NOTICES.md](./THIRD_PARTY_NOTICES.md) for licensing and attribu
## About Keygraph
**Keygraph** is the company behind Shannon. It also builds the **Keygraph platform**, the commercial agentic pentesting product that closes the full AppSec lifecycle and runs an enhanced build of Shannon as its pentesting engine.
**Keygraph** is the company behind Shannon. It also builds **Keygraph Pro** and **Keygraph Enterprise**, the commercial editions that close the full AppSec lifecycle and run an enhanced build of Shannon as their pentesting engine.
## Community and Support
@@ -386,7 +386,7 @@ Stay connected:
### Can I self-host Shannon?
Yes. Shannon Open Source runs inside your infrastructure in an ephemeral worker container. It mounts the repository read-only and writes results to a local workspace.
Yes. Shannon runs inside your infrastructure in an ephemeral worker container. It mounts the repository read-only and writes results to a local workspace.
Keygraph never receives your source code and never proxies your model traffic. Your model requests go straight to the provider or endpoint you configure, and they carry source and application context with them. Point Shannon at a locally hosted endpoint and that traffic stays inside your environment too.
@@ -1335,7 +1335,7 @@ Shannon currently targets exploitable vulnerabilities in these classes:
Shannon's proof-by-exploitation model means it does not report issues it cannot actively exploit, such as many vulnerable dependency, insecure configuration, or broad policy findings.
For broader coverage, the Keygraph platform adds black-box and white-box agentic pentesting, graph-based static analysis, SCA reachability, secrets detection, business logic testing, remediation workflows, SLA tracking, and reporting dashboards.
For broader coverage, Keygraph Pro and Enterprise add black-box and white-box agentic pentesting, graph-based static analysis, SCA reachability, secrets detection, business logic testing, remediation workflows, SLA tracking, and reporting dashboards.
## Cost and Performance
@@ -1367,35 +1367,35 @@ This reduces speculative noise, but it also means Shannon does not aim to report
Planned coverage areas should continue to live in the repository's canonical roadmap document if one exists. The README should link to that document rather than carrying detailed roadmap history inline.
For organizations that need broader static and organizational coverage now, see [the Keygraph platform](keygraph-platform.md).
For organizations that need broader static and organizational coverage now, see [Keygraph Pro and Enterprise](keygraph-platform.md).
---
# File: docs/keygraph-platform.md
# Keygraph Platform
# Keygraph Pro and Enterprise
Shannon Lite is now Shannon Open Source. Shannon Pro is now the Keygraph platform.
Shannon Lite is now just Shannon. Shannon Pro is now Keygraph Pro.
Shannon 3.0 is an open-source pentester. It reads your source, maps routes and data flows, runs real attacks against a live target, and writes PDF and SARIF reports. It runs locally, in CI, or air-gapped with your own model. Shannon Open Source is a complete pentester, not a trial edition.
Shannon 3.0 is an open-source pentester. It reads your source, maps routes and data flows, runs real attacks against a live target, and writes PDF and SARIF reports. It runs locally, in CI, or air-gapped with your own model. Shannon is a complete pentester, not a trial edition.
The Keygraph platform is Keygraph's commercial product. It runs an enterprise-hardened fork of Shannon continuously across hundreds of repositories and adds what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. It is for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify.
Pro and Enterprise are Keygraph's commercial editions. They run an enterprise-hardened fork of Shannon continuously across hundreds of repositories and add what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. They are for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify.
The Keygraph platform comes in three editions: the Community Program, Pro, and Enterprise. Every module is included in all three. They differ in price, eligibility, hosting, and support. Current prices and the full feature table are at [keygraph.io/pricing](https://keygraph.io/pricing).
The Community Program is Pro at no cost for organizations that qualify. Every module is included in Pro, Enterprise, and the Community Program. They differ in price, eligibility, hosting, and support. Current prices and the full feature table are at [keygraph.io/pricing](https://keygraph.io/pricing).
Every edition is BYOK: you bring your own model key and pay your provider directly. Shannon Open Source runs from your machine or CI runner, and Keygraph never receives your source or proxies your model traffic. The Community Program and Pro are cloud-hosted and managed by Keygraph. Enterprise deploys inside your cloud or data center, including fully air-gapped.
Every edition is BYOK: you bring your own model key and pay your provider directly. Shannon runs from your machine or CI runner, and Keygraph never receives your source or proxies your model traffic. The Community Program and Pro are cloud-hosted and managed by Keygraph. Enterprise deploys inside your cloud or data center, including fully air-gapped.
No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbox-pentester).
## Compare editions
| | Shannon Open Source | Community Program | Pro | Enterprise |
| | Shannon (open source) | Community Program | Pro | Enterprise |
| --- | --- | --- | --- | --- |
| Price | Open source under AGPL-3.0. You pay only your own model costs | $0 in cloud service fees while you qualify. You pay only your own AI provider usage | $50 per active developer per month, every module included, no add-ons | Custom |
| Best for | Developers and teams running repository-level pentests locally or in CI | U.S.-based 501(c)(3) nonprofits, and seed or pre-Series-A startups with 20 or fewer active developers | Teams that want the full Keygraph platform, cloud-hosted and managed by Keygraph | Security organizations running continuous AppSec across many teams and repositories that need the platform inside their own environment |
| Best for | Developers and teams running repository-level pentests locally or in CI | U.S.-based 501(c)(3) nonprofits, and seed or pre-Series-A startups with 20 or fewer active developers | Teams that want every module, cloud-hosted and managed by Keygraph | Security organizations running continuous AppSec across many teams and repositories that need it inside their own environment |
| Code analysis | Agent pass over architecture, entry points, and data flows to seed the pentest, plus optional multi-stage security code analysis, sized to finish inside a CI run | Same as Pro | Persistent code property graph plus a long-running analysis harness with interprocedural taint, sanitizer modeling, cross-repo context, exploit chains, and multi-pass review | Same as Pro |
| White-box pentesting | On-demand, source-aware white-box pentesting with optional authenticated testing, focused on injection, XSS, SSRF, broken authentication, and broken authorization, with proof by exploitation | Same as Pro | Enterprise-hardened Shannon fork run continuously against white-box and grey-box targets, with proof by exploitation | Same as Pro |
| Black-box pentesting (no source code) | Not included. Shannon Open Source needs the target's source code | Same as Pro | Agents attack the running application from the outside with no source access, with up to 4 login credentials for multi-role testing. Findings are validated with working exploits | Same as Pro |
| Black-box pentesting (no source code) | Not included. Shannon needs the target's source code | Same as Pro | Agents attack the running application from the outside with no source access, with up to 4 login credentials for multi-role testing. Findings are validated with working exploits | Same as Pro |
| SCA and secrets | Not included | Same as Pro | SCA with reachability and secrets scanning, including repository history | Same as Pro |
| Findings management | Per-run PDF, Markdown, JSON, and SARIF 2.1.0, with SARIF upload to GitHub code scanning | Same as Pro | One record per vulnerability per repository across scans and scanners, with status history, auto-reopen, ownership, SLAs, dashboards, and audit evidence | Same as Pro |
| Fix pull requests and retests | Fix manually from the report, then re-run the scan to verify | Same as Pro | Fix pull requests for a developer to review and apply, verified by re-analysis and exploit replay without a full rescan | Same as Pro |
@@ -1407,11 +1407,11 @@ No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbo
### What Pro includes
Pro is the full Keygraph platform, cloud-hosted and managed by Keygraph, at $50 per active developer per month. Every module is included, with unlimited repositories and scans under BYOK. That covers white-box and black-box pentesting, agentic SAST, SCA, secrets scanning, findings management with status history, retests (fix verification by re-analysis and exploit replay), fix pull requests, two-way Jira sync, and SSO, RBAC, and audit logs.
Pro is cloud-hosted and managed by Keygraph, at $50 per active developer per month. Every module is included, with unlimited repositories and scans under BYOK. That covers white-box and black-box pentesting, agentic SAST, SCA, secrets scanning, findings management with status history, retests (fix verification by re-analysis and exploit replay), fix pull requests, two-way Jira sync, and SSO, RBAC, and audit logs.
None of these require Enterprise. Enterprise adds self-hosted or fully air-gapped deployment, a dedicated engineer and white-glove onboarding, and a custom SLA and security patch SLA.
The Community Program is the same managed Pro platform, with every module included, at $0 in cloud service fees for organizations that qualify. It is cloud-hosted only. See the [Community Program](https://keygraph.io/community-program) for eligibility and how to apply.
The Community Program is Pro, with every module included, at $0 in cloud service fees for organizations that qualify. It is cloud-hosted only. See the [Community Program](https://keygraph.io/community-program) for eligibility and how to apply.
## How it fits your pipeline
@@ -1425,9 +1425,9 @@ The Community Program is the same managed Pro platform, with every module includ
### Static analysis on a code property graph
Shannon Open Source's code analysis is sized to finish inside a CI run: agents read the repository, map the attack surface, and hand candidates to the pentester. The Keygraph platform is built for depth instead. It first parses each repository into a persistent code property graph, then runs an analysis harness derived from one built for long-running vulnerability audits, heavily adapted to query the graph rather than read files. The harness decomposes the application into risk, taint-flow, framework, and specialist tasks and supports longer-running audit workflows beyond typical CI job windows.
Shannon's code analysis is sized to finish inside a CI run: agents read the repository, map the attack surface, and hand candidates to the pentester. Pro and Enterprise are built for depth instead. They first parse each repository into a persistent code property graph, then run an analysis harness derived from one built for long-running vulnerability audits, heavily adapted to query the graph rather than read files. The harness decomposes the application into risk, taint-flow, framework, and specialist tasks and supports longer-running audit workflows beyond typical CI job windows.
On the graph, it performs:
On the graph, they perform:
- Interprocedural taint tracking across functions, files, fields, containers, and framework request lifecycles.
- Source, sink, and sanitizer modeling that records where validation, encoding, or authorization changes a path.
@@ -1437,30 +1437,30 @@ On the graph, it performs:
### Business-logic invariants
Shannon Open Source focuses on injection, XSS, SSRF, and broken authentication and authorization. The Keygraph platform adds testing for the bugs that do not fit a vulnerability class: it derives invariants the application is supposed to hold (tenant isolation, workflow ordering, approval limits, balance conservation, state transitions) and tests them against the running application. This is where application-specific vulnerabilities live and where pattern-based SAST often provides little or no signal.
Shannon focuses on injection, XSS, SSRF, and broken authentication and authorization. Pro and Enterprise add testing for the bugs that do not fit a vulnerability class: they derive invariants the application is supposed to hold (tenant isolation, workflow ordering, approval limits, balance conservation, state transitions) and test them against the running application. This is where application-specific vulnerabilities live and where pattern-based SAST often provides little or no signal.
### Proof by exploitation
The pentesting engine is a hardened fork of Shannon with the same rule: a pentest finding requires a working exploit. No exploit, no finding. The platform stores the exploit and replays it later to verify the fix.
The pentesting engine is a hardened fork of Shannon with the same rule: a pentest finding requires a working exploit. No exploit, no finding. Pro and Enterprise store the exploit and replay it later to verify the fix.
The Blackbox Pentester applies the same rule without source access. It attacks the running application from the outside with a real browser and terminal, and it can take up to 4 login credentials (Google OAuth, GitHub, or custom auth) to test privilege escalation and IDOR across roles.
SCA prioritizes vulnerable dependencies that application code actually reaches. Secrets scanning covers current source and repository history.
<p align="center">
<img src="../assets/keygraph-platform/agentic-sast-results.png" alt="Keygraph platform findings grouped into business-logic issues, point issues, and secrets" width="100%">
<img src="../assets/keygraph-platform/agentic-sast-results.png" alt="Keygraph Pro findings grouped into business-logic issues, point issues, and secrets" width="100%">
</p>
## Findings
Shannon Open Source hands you a report per scan. The Keygraph platform dedupes across runs and across scanners, deterministically and semantically, into one record per vulnerability per repository. Each record carries evidence, source location, severity, scan history, status, owner, resolution, and last-verified state. This is included in the Community Program, Pro, and Enterprise.
Shannon hands you a report per scan. Pro and Enterprise dedupe across runs and across scanners, deterministically and semantically, into one record per vulnerability per repository. Each record carries evidence, source location, severity, scan history, status, owner, resolution, and last-verified state. This is included in the Community Program, Pro, and Enterprise.
Workflows cover assignment, triage, false-positive and risk-acceptance decisions, and SLA policies with escalation and aging. A resolved finding that reappears in a later scan reopens automatically. Dashboards report open risk, coverage, new versus resolved, SLA compliance, and MTTR, exportable as evidence for customers and auditors. Findings sync both ways with Jira.
Findings still require human review. The platform's extra review passes reduce weakly supported findings, but they do not eliminate them.
Findings still require human review. The extra review passes in Pro and Enterprise reduce weakly supported findings, but they do not eliminate them.
<p align="center">
<img src="../assets/keygraph-platform/canonical-findings.png" alt="Keygraph platform findings inventory with severity, status, source, and verification filters" width="100%">
<img src="../assets/keygraph-platform/canonical-findings.png" alt="Keygraph Pro findings inventory with severity, status, source, and verification filters" width="100%">
</p>
### Fix and verify
@@ -1468,13 +1468,13 @@ Findings still require human review. The platform's extra review passes reduce w
From a finding, Keygraph generates a patch scoped to that finding and opens a pull request for a developer to review and apply. It never commits to a protected branch.
<p align="center">
<img src="../assets/keygraph-platform/automated-remediation.png" alt="Keygraph platform remediation workflow for generating a fix and opening a pull request" width="100%">
<img src="../assets/keygraph-platform/automated-remediation.png" alt="Keygraph Pro remediation workflow for generating a fix and opening a pull request" width="100%">
</p>
Verification re-analyzes the changed code and, for pentest findings, replays the original exploit against the patched target. The verdict comes from deterministic checks plus a review pass, without rerunning the full scan.
<p align="center">
<img src="../assets/keygraph-platform/targeted-verification.png" alt="Keygraph platform finding-verification workflow" width="100%">
<img src="../assets/keygraph-platform/targeted-verification.png" alt="Keygraph Pro finding-verification workflow" width="100%">
</p>
## Deployment and access control
@@ -1488,7 +1488,7 @@ Model access is BYOK and BYOM in every edition. Route workloads to Anthropic, Op
Access control, in the Community Program, Pro, and Enterprise: SAML/OIDC SSO, SCIM, roles with repository-scoped visibility (RBAC, plus attribute and relationship rules where needed), full audit log, scoped API keys.
<p align="center">
<img src="../assets/keygraph-platform/enterprise-access-control.png" alt="Keygraph platform roles and repository visibility controls" width="100%">
<img src="../assets/keygraph-platform/enterprise-access-control.png" alt="Keygraph Pro roles and repository visibility controls" width="100%">
</p>
Keygraph maintains a SOC 2 Type II audit. The report is available to customers under NDA.
+4 -4
View File
@@ -1,6 +1,6 @@
# Shannon
> Shannon is an autonomous AI pentesting project by Keygraph. This repository contains Shannon, the AGPL-3.0 open-source white-box pentesting CLI. The Keygraph platform is Keygraph's commercial continuous pentesting and AppSec platform.
> Shannon is an autonomous AI pentesting project by Keygraph. This repository contains Shannon, the AGPL-3.0 open-source white-box pentesting CLI. Keygraph Pro and Keygraph Enterprise are Keygraph's commercial continuous pentesting and AppSec editions.
Use this file as the concise entry point for AI agents and LLMs reading this repository. For a single combined context file, use [llms-full.txt](llms-full.txt).
@@ -18,13 +18,13 @@ Use this file as the concise entry point for AI agents and LLMs reading this rep
- [Safety and Limitations](docs/safety.md): Authorized-use requirements, non-production guidance, mutative effects, model caveats, scope limits, cost, and performance.
- [Coverage and Roadmap](docs/coverage-roadmap.md): Current Shannon coverage and roadmap direction.
## Keygraph Platform
## Keygraph Pro and Enterprise
- [Keygraph platform](docs/keygraph-platform.md): Commercial continuous pentesting and AppSec platform, compared edition by edition with Shannon Open Source. The Community Program, Pro, and Enterprise editions all include black-box and white-box pentesting, parsed-code SAST, SCA and secrets scanning, findings management, fix pull requests and retests, Jira sync, and SSO, RBAC, and audit logs. Pro and the Community Program are cloud-hosted; Enterprise is self-hosted or air-gapped. Shannon Lite is now Shannon Open Source. Shannon Pro is now the Keygraph platform.
- [Pro and Enterprise](docs/keygraph-platform.md): Keygraph's commercial continuous pentesting and AppSec editions, compared edition by edition with Shannon. The Community Program, Pro, and Enterprise all include black-box and white-box pentesting, parsed-code SAST, SCA and secrets scanning, findings management, fix pull requests and retests, Jira sync, and SSO, RBAC, and audit logs. Pro and the Community Program are cloud-hosted; Enterprise is self-hosted or air-gapped. Shannon Lite is now just Shannon. Shannon Pro is now Keygraph Pro.
## External Links
- [Keygraph website](https://keygraph.io): Company and commercial product information.
- [Keygraph pricing](https://keygraph.io/pricing): Prices and the feature table for Shannon Open Source, the Community Program, Pro, and Enterprise.
- [Keygraph pricing](https://keygraph.io/pricing): Prices and the feature table for Shannon, the Community Program, Pro, and Enterprise.
- [Keygraph demo](https://cal.com/team/keygraph/keygraph-technical-demo): Technical demo booking.
- [Community Discord](https://discord.gg/cmctpMBXwE): Community support and discussion.