Orbyx AI SPM
An open-source dashboard that shows a company every AI model and AI agent running inside it, including the unofficial ones nobody signed off on, and flags which of them are a security risk.
🔗 Visit Orbyx AI SPMDescription
Most companies now have employees quietly plugging AI tools into their work — a chatbot wired to internal data here, an automated agent there — often without security teams ever finding out. That's "shadow AI," and it's the same problem shadow IT was a decade ago, except these systems can read files and take actions on their own. Orbyx AI SPM is like a building manager doing rounds with a clipboard, except instead of checking fire exits, it walks through a company's AI systems and writes down what it finds: which AI models are deployed, what data they can touch, and whether any of them are doing something they shouldn't.
Technically, it's an AI Security Posture Management (AI-SPM) platform: it discovers AI models, agents, and their associated resources across an organization, evaluates risk across the AI supply chain and inference pipelines, and enforces governance policies via an OPA (Open Policy Agent) engine, with Prometheus/Grafana dashboards for real-time monitoring and runtime detection of anomalous agent behavior. It's Apache 2.0 licensed and self-hosted — you deploy it to a Kubernetes cluster (a bootstrap script targets a local Kind cluster in about 20 minutes for evaluation) rather than sending data to a third-party SaaS.
💬 Our review
The short version: if your security team suspects — but can't prove — that engineers are wiring internal data into random AI agents, this is a free, self-hosted way to actually see it, at the cost of running and maintaining a Kubernetes deployment yourself.
The honest comparison here isn't really other AI-SPM vendors (most, like Wiz or Netskope's AI modules, are closed-source enterprise sales-led products); it's Suprbox, a similarly-scoped project in this catalog that takes the opposite approach — a managed, policy-gated vault rather than a self-hosted discovery/monitoring layer. Orbyx wins on cost (free, Apache 2.0, no vendor lock-in) and on giving you visibility into AI usage you don't already control, which a vault-style product can't do since it only governs data that's already routed through it. It loses on maturity: 13 stars, one fork, and no evidence yet of production deployments outside its own repo, which for a security tool is a real signal to weigh — you're trusting policy enforcement to a young project. Worth a pilot on a Kind cluster before anyone signs off on it for anything regulated.
📊 Global score
🤖 AI-enriched data
Apache 2.0, entièrement gratuit et self-hosted. Aucune offre payante — coûts limités à l'infrastructure Kubernetes que vous faites tourner vous-même. Lien de don Ko-fi optionnel pour les mainteneurs.
Pros
Gratuit, open source, self-hosted
Découverte + scoring de risque + policy enforcement intégrés
Moteur OPA + Prometheus/Grafana
Détection runtime des comportements suspects d'agents IA
Cons
Projet très jeune (13 stars, 1 fork)
Nécessite un cluster Kubernetes et des compétences ops
Pas d'option hébergée/managée
10 issues ouvertes
