The scanner is not
- a full security audit
- a compliance review
- a guaranteed vulnerability scanner
- a guaranteed modernization planner
- an autonomous production rewrite engine
- a substitute for developer review
- a substitute for legal, compliance, or security review
Current private scan limitations
- static indicators only unless AI deep scan is explicitly enabled
- no guarantee that all risks are detected
- no guarantee that all secrets are found
- no guarantee that code is safe to deploy
- no guarantee that a modernization path is complete
Memory-Safe Modernization Roadmap
Modernize Agent AI currently focuses on static legacy-code risk scanning, evidence-backed reports, callback/domain review, archive/package intake, and modernization readiness planning.
Future roadmap areas may include:
- C/C++ to Rust readiness assessment
- memory-safety risk identification
- behavior-preservation planning
- test/readiness gap detection
- containment-first recommendations
- security profile and sandboxing considerations
- migration planning for high-risk legacy components
Limitations:
- Modernize Agent AI does not currently perform automatic C-to-Rust conversion.
- Modernize Agent AI does not currently prove behavior equivalence.
- Modernize Agent AI does not currently perform AppArmor profile generation or enforcement.
- Modernize Agent AI does not currently certify generated code as safe.
- Any generated or transformed code must be treated as untrusted until validated.
Evidence doctrine
Safe usage