September 2026

Tooling · platform intelligence & risk telemetry

Find the AI and SaaS nobody approved.

Shadow Scanner runs a zero-knowledge assessment of an environment and returns what is actually in use: which applications, which AI models, which people. Then what it costs you in risk and in licences paid twice.

Used across every engagement we run

Why it exists

the inventory nobody has

Almost every organisation we work with can name its sanctioned stack. Very few can name what runs alongside it: the consumer AI logins, the personal-tier developer tools, the file shares set to “anyone with the link”, the workspace that never went behind SSO.

That is not a discipline problem. It is a visibility problem. You can't govern, consolidate or budget for what you can't see. Shadow Scanner closes the gap before the strategy work starts.

What it reports

summary, then detail

Every scan opens with one screen an executive can read. Behind it sits row-level detail an engineer can act on.

01

Overall AI posture

One graded score for the environment. The starting position is measurable, and so is progress after remediation.

02

Application sprawl

Distinct applications accessed by users, checked against a registry of 12,482. The count usually runs several times higher than expected.

03

Critical egress vectors

Each route by which data leaves around corporate network controls, named individually rather than rolled into a summary.

04

Live vulnerabilities

Active CVEs and architectural flaws on detected platforms, including structural ones like missing SSO enforcement.

05

Consolidation ROI

Estimated annual saving from moving shadow tools onto licences you already pay for. Itemised, so procurement can check it.

06

Exportable QBR

The assessment exports to PDF, formatted to drop straight into a quarterly business review.

What it detects

two telemetry passes

AI & model telemetry

For each shadow platform, Shadow Scanner names the model being called, the threat vector it opens, and the sanctioned alternative that does the same job inside your controls.

Typical findings: consumer logins to frontier models with no enterprise data protection. Internal material pasted into public chat. Unmanaged GPU environments pulling open-weight models for local fine-tuning. Personal-tier developer tools sending code back to a vendor's shared models. AI assistants joining meetings and recording off-network.

Security posture & commercial intelligence

The second pass pairs each detected application with its live vulnerabilities, its commercial impact and a specific fix.

The findings are usually structural, not exotic. Workspaces without SSO, so former staff keep live access. Open-link shares that sit outside eDiscovery. Pre-release assets in personal accounts. Individual subscriptions that skip procurement and lose the bulk price.

Who is using what

the part that changes decisions

An application count describes a problem. Attribution lets you act on it. Shadow Scanner maps usage to users and teams. That means a conversation with one team instead of a blanket policy, training aimed where adoption already happened, and a licence count based on who needs a seat.

It also changes how the findings read. Unsanctioned use is usually an unmet need, not defiance. People reach for a tool because the approved one is missing, slower or harder to get. Who reached for what tells you which gap to close first.

The trade-off. Attribution means handling who-uses-what data with care. Route findings to the people who can close the gap, not into performance reviews.

Where the findings go

one scan · six cuts

Shadow Scanner is a starting point, not a deliverable on its own. Each capability reads a different cut of the same scan.

AI strategy & roadmapping →

The live footprint, so the roadmap starts from what is running rather than the licence list.

Vendor & tool evaluation →

Overlap and duplicate spend, so an evaluation begins with the stack you already pay for.

Governance, risk & compliance →

Unsanctioned inventory, egress vectors, and access that outlived the employee.

Implementation & integration →

Each finding paired with the sanctioned platform it should migrate into.

Agentic AI engineering →

Where AI is already acting outside managed boundaries, before you add more.

Team enablement & training →

Per-team usage, so training targets behaviour that is already happening.

Findings are specific to the environment scanned. Figures in any sample or demonstration report are illustrative. They are not benchmarks, and not results from a named client.

See what's actually running.

A person replies within one business day.

Talk to us