# Shannon Lite vs Shannon Pro: Complete Feature and Architecture Comparison

> Compare Shannon Lite AGPL with Shannon Pro commercial. Discover key differences in features and architecture including source-sink analysis, data-flow analysis, CVSS scoring, CI CD integration, and RBAC.

- Repository: [KeygraphHQ/shannon](https://github.com/keygraphhq/shannon)
- Tags: comparison
- Published: 2026-02-16

---

**Shannon Lite is a free, AGPL‑licensed CLI tool that performs context‑window limited source‑sink analysis, while Shannon Pro is a commercial platform offering cross‑codebase data‑flow analysis, CVSS scoring, CI/CD integration, and enterprise RBAC.**

The **KeygraphHQ/shannon** repository hosts both editions of this AI‑powered security scanner. While Shannon Lite provides foundational vulnerability detection for individual developers, Shannon Pro extends the architecture with multi‑agent orchestration and enterprise controls. Understanding the differences between Shannon Lite and Shannon Pro helps teams choose the right deployment model for their security workflows.

## Core Feature Comparison

### Scanning Engine and Analysis Depth

**Shannon Lite** implements a simple source‑sink analysis constrained to the LLM context window. It runs a single Claude Agent that examines code within token budget limits, making it suitable for focused scans of individual modules.

**Shannon Pro** deploys an LLM‑powered data‑flow analysis engine inspired by *LLM‑Driven Data‑Flow Analysis* research. According to the source code in [`src/session-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/session-manager.ts), Pro coordinates a fleet of specialized Claude Agents that contribute to a **graph‑based data‑flow engine**. This tracks input → sink relationships across the entire codebase, enabling detection of multi‑module vulnerability chains that exceed context window limitations.

### Enterprise Features and Compliance

Shannon Pro adds enterprise controls absent from the open‑source edition:

- **CVSS Scoring**: Automatic CVSS v3.1 calculation for each finding
- **Remediation Guidance**: Line‑by‑line code fixes generated by the LLM, versus basic descriptions in Lite
- **RBAC and SSO**: Multi‑user support with role‑based access control and SAML/SSO integration
- **Audit Logging**: Immutable checkpoints and compliance reports (OWASP, PCI‑DSS, SOC 2) stored in `audit-logs/*` via `src/audit/`
- **Support**: Dedicated support with SLA versus community‑driven Discord and GitHub issues

## Architecture Comparison: AGPL vs Commercial

### Analysis Engine Implementation

The architectural divergence begins in the agent orchestration layer. In [`src/session-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/session-manager.ts), Shannon Lite initializes a single agent queue with linear execution. Shannon Pro extends this to manage **parallel groups** of agents that simultaneously query a global data‑flow graph.

Shannon Lite’s analysis is limited by the context window of the underlying LLM. Shannon Pro’s graph‑based engine in [`src/session-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/session-manager.ts) aggregates input‑output relationships across files, enabling detection of vulnerabilities that span multiple modules.

### Workflow Orchestration

Both editions use Temporal workflows defined in [`src/temporal/workflows.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/temporal/workflows.ts), but with different concurrency models:

**Shannon Lite** runs four linear phases: Reconnaissance → Vulnerability Analysis → Exploitation → Reporting. Each phase completes before the next begins.

**Shannon Pro** enlarges the parallel groups within the same Temporal backbone. The *Vulnerability Analysis* stage runs **five simultaneous agents** that each query the global data‑flow graph, dramatically increasing coverage while maintaining the workflow structure.

### Scalability and Deployment Options

Shannon Lite is designed for single‑container deployment via [`docker-compose.docker.yml`](https://github.com/KeygraphHQ/shannon/blob/main/docker-compose.docker.yml), running on a single Docker container with no built‑in authentication beyond LLM API keys.

Shannon Pro supports **cloud‑scale** deployment as a stateless service behind a load balancer, with horizontal scaling of Temporal workers. Deployment options include:
- **Cloud‑hosted SaaS**: Fully managed by Keygraph
- **Self‑hosted**: Docker or Kubernetes with enterprise configuration via [`configs/example-config.yaml`](https://github.com/KeygraphHQ/shannon/blob/main/configs/example-config.yaml)

The self‑hosted Pro configuration in [`configs/example-config.yaml`](https://github.com/KeygraphHQ/shannon/blob/main/configs/example-config.yaml) exposes settings for SSO, audit storage (S3 or local), and compliance reporting that are absent from the Lite edition.

## Practical Usage Examples

### Running Shannon Lite Locally

Shannon Lite requires only Docker and an Anthropic API key:

```bash

# Clone the repository

git clone https://github.com/KeygraphHQ/shannon.git
cd shannon

# Provide an Anthropic API key

export ANTHROPIC_API_KEY="your-key"

# Run a pentest against a local app

./shannon start URL=http://host.docker.internal:3000 REPO=sample-app

```

This executes the single‑agent scan defined in [`src/session-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/session-manager.ts) with context‑window limited analysis.

### Integrating Shannon Pro into CI/CD

Shannon Pro provides native GitHub Actions support and API access for automated pipelines:

```yaml
name: Security Scan
on: [push, pull_request]

jobs:
  shannon-pro:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - name: Run Shannon Pro
        env:
          SHANNON_API_KEY: ${{ secrets.SHANNON_API_KEY }}
        run: |
          curl -X POST https://api.keygraph.io/shannon/run \
            -H "Authorization: Bearer $SHANNON_API_KEY" \
            -d '{"repo":"${{ github.repository }}","ref":"${{ github.sha }}"}'

```

This triggers the multi‑agent workflow in [`src/temporal/workflows.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/temporal/workflows.ts) with parallel vulnerability analysis.

### Accessing Pro Features via API

Fetch detailed findings with CVSS scores using the Shannon Pro REST API:

```python
import requests, os

api_key = os.getenv("SHANNON_API_KEY")
headers = {"Authorization": f"Bearer {api_key}"}
resp = requests.get("https://api.keygraph.io/shannon/findings", headers=headers)
for finding in resp.json()["findings"]:
    print(f"{finding['id']}: {finding['title']} (CVSS {finding['cvss']})")

```

The API exposes the graph‑based analysis results stored in the Pro audit system.

### Configuring Enterprise Audit Logs

For self‑hosted Shannon Pro deployments, enable compliance logging via [`configs/example-config.yaml`](https://github.com/KeygraphHQ/shannon/blob/main/configs/example-config.yaml):

```yaml
audit:
  enabled: true
  storage: s3   # or local

  s3:
    bucket: shannon-audits
auth:
  sso:
    enabled: true
    provider: saml
    metadata_url: https://sso.example.com/metadata.xml

```

This activates the enterprise controls implemented in `src/audit/` and [`src/queue-validation.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/queue-validation.ts).

## Key Files and Implementation Details

Understanding the codebase structure clarifies the technical boundaries between editions:

- **[`src/session-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/session-manager.ts)**: Defines the agent queue and orchestration logic. Lite uses a single agent; Pro implements parallel groups and graph‑based data‑flow tracking.
- **[`src/temporal/workflows.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/temporal/workflows.ts)**: Contains the workflow definitions. Lite runs linear phases; Pro extends this with concurrent agent execution during vulnerability analysis.
- **[`src/tool-checker.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/tool-checker.ts)**: Validates external security tools. Pro exposes this as a plugin API for custom scanners.
- **[`src/queue-validation.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/queue-validation.ts)**: Enforces enterprise standards for deliverables, including RBAC and compliance checks available only in Pro.
- **[`configs/example-config.yaml`](https://github.com/KeygraphHQ/shannon/blob/main/configs/example-config.yaml)**: Demonstrates configuration options. Pro‑specific fields include SSO, audit storage backends, and compliance reporting.
- **[`docker-compose.docker.yml`](https://github.com/KeygraphHQ/shannon/blob/main/docker-compose.docker.yml)**: Supports single‑container deployment suitable for Lite; Pro can use this for self‑hosting but typically deploys to cloud‑scale infrastructure.

## Summary

- **Shannon Lite** is an open‑source, AGPL‑3.0 licensed CLI tool providing context‑window limited source‑sink analysis via a single Claude Agent, suitable for individual developers and small projects.
- **Shannon Pro** is a commercial platform adding cross‑codebase data‑flow analysis through a multi‑agent graph engine, automatic CVSS scoring, detailed remediation guidance, and native CI/CD integration.
- **Architecture**: Lite runs linear Temporal workflows in a single Docker container; Pro scales horizontally with parallel agent groups, cloud deployment options, and enterprise RBAC/SSO controls.
- **Key differentiators**: Pro exposes plugin APIs in [`src/tool-checker.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/tool-checker.ts) and [`src/queue-validation.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/queue-validation.ts), supports audit logging via `src/audit/`, and offers both SaaS and self‑hosted deployment with SAML configuration in [`configs/example-config.yaml`](https://github.com/KeygraphHQ/shannon/blob/main/configs/example-config.yaml).

## Frequently Asked Questions

### What is the main technical difference between Shannon Lite and Shannon Pro?

The primary technical distinction lies in the analysis engine architecture. Shannon Lite uses a single Claude Agent performing context‑window constrained source‑sink analysis, while Shannon Pro implements a graph‑based data‑flow engine coordinated by [`src/session-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/session-manager.ts) that tracks input → sink relationships across the entire codebase using multiple parallel agents.

### Can I upgrade from Shannon Lite to Shannon Pro without changing my workflow?

Yes, the upgrade path is designed for compatibility. Both editions share the same Temporal workflow backbone defined in [`src/temporal/workflows.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/temporal/workflows.ts), so existing Lite CLI commands work in Pro. However, Pro unlocks parallel execution stages and requires API keys for the commercial service or enterprise configuration in [`configs/example-config.yaml`](https://github.com/KeygraphHQ/shannon/blob/main/configs/example-config.yaml) for self‑hosted deployments.

### Is Shannon Pro available as a self‑hosted option or only SaaS?

Shannon Pro supports both deployment models. You can use the cloud‑hosted SaaS version managed by Keygraph, or self‑host Pro using Docker or Kubernetes with the configuration templates in [`configs/example-config.yaml`](https://github.com/KeygraphHQ/shannon/blob/main/configs/example-config.yaml). The self‑hosted option requires setting up enterprise features like SSO and audit storage backends manually.

### Does Shannon Lite include any commercial features or API access?

No, Shannon Lite is strictly a stand‑alone CLI tool with no built‑in API access or CI/CD integrations. It runs as a single Docker container without authentication mechanisms beyond LLM API keys. Commercial features such as the REST API, webhook connectors, and RBAC controls are exclusive to Shannon Pro.