- Linting & Type Checking
- AI-Specific Custom Rules (Semgrep) — Demographic Feature Flagging
- AI-Specific Custom Rules — Hardcoded Threshold Detection
- AI-Specific Custom Rules — Missing Logging Detection (Art. 12)
- AI-Specific Custom Rules — Model Registry Bypass Detection
- Dependency Scanning (Snyk, Dependabot, pip-audit, OWASP)
- Licence Compliance Scanning (FOSSA, Black Duck, pip-licenses)
- Secret Detection (Pre-Commit Hooks & CI Steps)