AI TRANSPARENCY
AI augments — it does not replace — security expertise.
ScanexAI uses AI to translate technical findings into clear, actionable language. Vulnerability detection itself is entirely rule-based and deterministic.
ScanexAI uses artificial intelligence to make security findings easier to understand and act on. After the rule-based scanner finishes analysing a target, the AI receives a structured summary of what was found and produces a plain-English breach narrative. This narrative explains how the detected vulnerabilities could be chained together by a real attacker, and which issues should be addressed first.
It is important to understand what the AI does and does not do. The AI does not discover vulnerabilities. It does not send requests to your website or make any judgements about your code. Its only job is to take the structured output from the deterministic scanner and present it in a way that is readable by developers, managers, and auditors who may not have a deep security background.
We have chosen to be transparent about how AI is used in this platform because we believe users deserve to know when they are reading AI-generated content. Every AI-produced narrative is clearly labelled as such within the dashboard and in exported PDF reports. We encourage all users to treat AI output as a starting point for conversation, not a final authority.
ScanexAI uses Llama 3, a large language model developed by Meta and accessed via Groq's hosted inference API. Llama 3 was selected for its strong natural-language reasoning capabilities, its suitability for technical content, and the speed of Groq's inference infrastructure — which allows narratives to be generated in seconds rather than minutes.
Vulnerability detection is entirely rule-based and deterministic. The AI model is not involved in identifying security weaknesses — it only receives the output of the scanner and produces the plain-English narrative and remediation priorities. No proprietary or fine-tuned models are used. All AI calls are made to Groq's hosted API and are subject to Groq's standard data handling policies.
Model selection may change over time as newer and more capable models become available. Any change to the underlying model will be reflected in an update to this page.
After the rule-based scanner completes its analysis, the AI layer receives a structured summary of the findings — vulnerability types, severity scores, CVSS values, and the assembled attack chains. Using this structured input, the model generates a breach narrative: a plain-English description of how an attacker could realistically exploit the discovered weaknesses, which combinations of findings create the most serious risk, and what the likely outcome of a successful attack would be.
The AI also produces a ranked set of remediation recommendations. These are ordered by a combination of exploitability, potential impact, and how central the finding is to the identified attack chains — so the most important fixes are always surfaced first.
The AI narrative is clearly labelled within the dashboard and in exported PDF reports. It is supplementary to — not a replacement for — the underlying rule-based assessment. Users are encouraged to treat the narrative as a communication tool, not as a definitive technical finding.
ScanexAI sends only structured scan metadata to the AI provider — specifically: the list of vulnerability types detected, their CVSS scores, the attack chain nodes and relationships, and the target domain. No raw page content is sent. No user account data, credentials, personal information, or sensitive content from the scanned website is included in the AI prompt.
All prompts are constructed server-side by ScanexAI's backend. Users cannot directly modify the prompt sent to the model, which prevents prompt injection attacks against the AI layer itself.
Groq's data retention and privacy policies apply to all data transmitted to their API. We recommend reviewing Groq's privacy policy if you have specific requirements around data handling. ScanexAI does not use AI provider features that would cause your scan data to be used for model training.
Large language models can produce inaccurate output. AI-generated breach narratives may contain errors, mischaracterise the severity of a finding, or describe exploit scenarios that are not applicable to your specific application. This is sometimes called hallucination — the model generating plausible-sounding but incorrect content.
The breach narrative does not constitute legal or professional security advice. It should not be used as the sole basis for making security decisions in production systems. We strongly recommend that any significant findings surfaced by ScanexAI be reviewed and verified by a qualified security professional before remediation steps are taken in sensitive environments.
ScanexAI's AI features are intended to assist in communicating and prioritising risk — not to replace expert security judgement. The value of the AI layer is in making technical findings accessible to a broader audience, not in providing a higher level of technical certainty than the underlying scanner.
All AI outputs within ScanexAI are clearly marked as AI-generated, both within the dashboard interface and in exported PDF reports. This labelling is intentional — we believe users deserve to know when they are reading content produced by a model rather than a human security analyst.
Users retain full responsibility for any decisions they make based on AI-generated content. ScanexAI periodically reviews AI feature behaviour and updates the prompts and parameters used to generate narratives as we identify opportunities to improve accuracy or reduce the risk of misleading output.
If you encounter an AI-generated narrative that appears materially incorrect — particularly one that significantly mischaracterises the risk of a finding — please report it via our support channel at support@scanexai.com. Feedback from users directly improves the quality of AI output across the platform.
Effective date: 1 June 2025