
“The scan was fast, easy to work with, and gave us useful security signals we could immediately investigate. We were impressed by what the model was able to identify.”
Fluton
Kann AI / Model Alpha extracts Solidity call graphs and returns function-level security signals for expert validation. It is an early analysis tool, not an audit certificate.
How it works
Kann AI builds an understanding of your codebase, analyzes contract behavior and security-sensitive logic, and returns findings you can review and validate.
Provide the smart contract codebase you want to analyze.
Kann AI maps contracts, dependencies, inheritance, permissions, and protocol interactions.
The model investigates code paths, assumptions, state changes, and security-sensitive behavior.
Potential vulnerabilities and suspicious behaviors are identified in context.
Receive structured findings with explanations engineers and security researchers can validate.
Local workflow
Read the full README before installation and confirm code-handling requirements before analyzing confidential source.
git clone https://github.com/Kann-Audits/model-alpha.git /tmp/model-alphaThen follow the agent-specific dependency and installation instructions in the repository.
Hosted workflow
Scan your repository through the Kann Audits interface without setting up Model Alpha locally.
github.com/example/protocolTrusted in production
Teams building real protocols use Kann AI as another layer in their security workflow.

“The scan was fast, easy to work with, and gave us useful security signals we could immediately investigate. We were impressed by what the model was able to identify.”
Fluton

“Kann AI did an excellent job on our codebase. We ran a full scan across 3,000+ lines of code, and it uncovered over 80 security findings. The results were impressive and gave us a lot of value throughout the audit scan.”
castr.fun

“Kann AI demonstrated how useful AI can become when it is built specifically for smart contract security. The output gave us meaningful additional context during our security review.”
Manifest Finance
Benchmarks
See how Model Alpha performs against the DODO smart contract security benchmark.
Model Alpha Security Benchmark
DODO Cross-Chain DEX · 17 findings (5 High and 12 Medium)
Model Alpha detected every High-severity finding in the benchmark and nine of twelve Medium-severity findings.
FAQ
No. It produces early function-level signals. Business logic, economic attacks, cross-contract behavior, and system assumptions still require expert review.
The current public Model Alpha repository documents Solidity contract analysis.
The public documentation says function context is sent to a hosted endpoint but does not publish a retention policy. Confirm handling requirements before submitting confidential code.
The call-graph extraction and CLI run locally, while the documented analysis step calls a hosted Model Alpha endpoint.
Inspect the complete call path, reproduce the behavior, test system assumptions, and have a qualified reviewer assess real impact before making a security decision.
Start with the scope
Share your scope, target date, and architecture. The security team will review the details and respond with the next steps.