Reference implementation · What we build, running

NINELINE.
Your 9-line for software and AI.

NINELINE is Optimal’s working reference implementation of AI-native application and supply-chain security. Real scanners, real repositories, and frontier-model reasoning compress thousands of raw findings down to the handful that are actually reachable and actively exploited — the targets that matter. Named for the close air support brief: strip everything down to the target.

SBOM / Reachability / EPSS + CISA KEV / AI-BOM / Auto-remediation

syft + grype Frontier-model reachability Runs in your environment

From raw scanner output to the targets that matter

874 Raw findings
deprioritized unreachable / transitive / no known exploit
18 Require action
−97.9% noise eliminated

Of 874 raw findings, 18 survive to the action queue. Of 8 findings on the CISA Known Exploited Vulnerabilities list, only 2 of 8 are reachable in this deployment — so the model deprioritizes the rest. Reachable-and-exploited is the real target; everything else is noise you can’t afford to chase.

The mechanism

Five frontier-model capabilities, not a bolt-on.

Everything on screen comes from real analysis of real repositories — nothing is hardcoded. The model does the reading, the tracing, and the judgment an analyst would.

01

Agentic reachability analysis

The flagship capability. For each high-signal finding, a frontier model reads the actual codebase — grepping, opening files, tracing call chains — to decide whether the vulnerable path is truly reachable from an entry point. It reads the code the way an analyst would, and shows its work.

02

Mission-context triage

EPSS exploitation probability, CISA KEV status, dependency position, and the reachability verdict fuse into a single mission priority — written for a program manager, not a pentester.

03

Reachability-gated remediation

For the findings that survive triage, the model drafts the exact fix — an appliable pull request with the version bump or transitive override, breaking-change risk, and test focus. Automation fires only for what's proven reachable, not the whole backlog.

04

Drift narration & AI-BOM risk

Every change to the software bill of materials is narrated in mission terms, and every discovered ML model gets an AI-written risk assessment — license suitability for government use, provenance confidence, training-data lineage.

05

Grounded natural-language query

Ask in plain English — “which critical findings are actually reachable,” “do any of our AI models have license problems.” Answers are grounded in the real scan data through query tools and cited to actual records. Never a hallucination.

Where the risk lives

Most of your risk is in software you didn’t write
— and don’t know you’re running.

Defense industrial base

Built for the mandates the DIB is already under.

Reachability and mission context match how the department actually triages — mission assurance, not raw CVSS. And it runs air-gapped: reachability reads source, so nothing has to leave the enclave.

CMMC & secure-development attestation

Asset inventory and vulnerability management are gating controls for keeping DoD business. NINELINE is the evidence engine — an authoritative SBOM plus the risk analysis on top of it.

SBOM mandates

Federal software-supply-chain direction (EO 14028, OMB memoranda, NIST SSDF) expects a bill of materials and secure-development attestation. This produces the SBOM and the reachability-ranked findings against it.

Continuous ATO

DoD is moving from point-in-time authorization to continuous monitoring. The drift → reachability → gated-remediation loop is exactly that posture, running on your own infrastructure.

AI bill of materials

Model provenance, license, and lineage tooling barely exists while the DIB adopts AI fast. The AI-BOM view surfaces the license conflicts that stop a model from reaching production.

Regulatory timelines move quickly — we’ll scope current enforcement to your specific contracts and environment.

“NINELINE is how we show what governed, AI-native security looks like when we build it — a working reference implementation you can run in your own environment, not a SaaS subscription.”

See the targets
that matter.

Click into the live demonstrator, or book a walkthrough and we’ll show it against your stack — then scope standing it up in your environment.