Orbyx AI SPM

Orbyx AI SPM

An open-source dashboard that shows a company every AI model and AI agent running inside it, including the unofficial ones nobody signed off on, and flags which of them are a security risk.

🔗 Visit Orbyx AI SPM
📁 Security & Privacy🗣️ English📅 July 26, 2026

Description

Most companies now have employees quietly plugging AI tools into their work — a chatbot wired to internal data here, an automated agent there — often without security teams ever finding out. That's "shadow AI," and it's the same problem shadow IT was a decade ago, except these systems can read files and take actions on their own. Orbyx AI SPM is like a building manager doing rounds with a clipboard, except instead of checking fire exits, it walks through a company's AI systems and writes down what it finds: which AI models are deployed, what data they can touch, and whether any of them are doing something they shouldn't.

Technically, it's an AI Security Posture Management (AI-SPM) platform: it discovers AI models, agents, and their associated resources across an organization, evaluates risk across the AI supply chain and inference pipelines, and enforces governance policies via an OPA (Open Policy Agent) engine, with Prometheus/Grafana dashboards for real-time monitoring and runtime detection of anomalous agent behavior. It's Apache 2.0 licensed and self-hosted — you deploy it to a Kubernetes cluster (a bootstrap script targets a local Kind cluster in about 20 minutes for evaluation) rather than sending data to a third-party SaaS.

💬 Our review

The short version: if your security team suspects — but can't prove — that engineers are wiring internal data into random AI agents, this is a free, self-hosted way to actually see it, at the cost of running and maintaining a Kubernetes deployment yourself.

The honest comparison here isn't really other AI-SPM vendors (most, like Wiz or Netskope's AI modules, are closed-source enterprise sales-led products); it's Suprbox, a similarly-scoped project in this catalog that takes the opposite approach — a managed, policy-gated vault rather than a self-hosted discovery/monitoring layer. Orbyx wins on cost (free, Apache 2.0, no vendor lock-in) and on giving you visibility into AI usage you don't already control, which a vault-style product can't do since it only governs data that's already routed through it. It loses on maturity: 13 stars, one fork, and no evidence yet of production deployments outside its own repo, which for a security tool is a real signal to weigh — you're trusting policy enforcement to a young project. Worth a pilot on a Kind cluster before anyone signs off on it for anything regulated.

📊 Global score

53Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile90/100Excellent

Profile completeness

🤖 AI-enriched data

💰 Pricing model
🆓 Gratuit / open source

Apache 2.0, entièrement gratuit et self-hosted. Aucune offre payante — coûts limités à l'infrastructure Kubernetes que vous faites tourner vous-même. Lien de don Ko-fi optionnel pour les mainteneurs.

👥 Target audienceÉquipes sécurité/plateforme dans des organisations qui déploient des modèles et agents IA et veulent une visibilité sur le "shadow AI" et la conformité de leurs pipelines IA.
🗣️ Languagesen
🌍 Target countriesWorldwide
👍

Pros

Gratuit, open source, self-hosted

Découverte + scoring de risque + policy enforcement intégrés

Moteur OPA + Prometheus/Grafana

Détection runtime des comportements suspects d'agents IA

👎

Cons

Projet très jeune (13 stars, 1 fork)

Nécessite un cluster Kubernetes et des compétences ops

Pas d'option hébergée/managée

10 issues ouvertes

❓ Frequently asked questions

What is Orbyx AI SPM?
Is it free?
Do I need Kubernetes to use it?
What does it actually detect?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?