Legal
Privacy notice
Effective date: 20 September 2026 · Last updated: 22 September 2026
Summary
SBOMFlow is a local, offline-by-default command-line product with a static marketing and documentation website. In plain terms:
- This website has no accounts, no forms, no analytics, no advertising, and no tracking cookies. Its JavaScript handles navigation and progressive enhancement only.
- The SBOMFlow CLI runs on your own machines. By default your source code, firmware, SBOMs, file paths, findings, reviewer notes, and generated reports never leave your environment, and there is no vendor telemetry.
- The only personal data we normally receive is what you choose to send us — for example an email enquiry.
Who we are
SBOMFlow is operated by SBOMFLOW TECHNOLOGIES LTD, a private company limited by shares incorporated in the Federal Republic of Nigeria under the Companies and Allied Matters Act 2020, company registration number 9845783, incorporated at Abuja on 10 September 2026. It is the controller for the personal data described in this notice.
Contact: hello@sbomflow.com. This is the single address for every kind of enquiry, including data-protection requests and security reports; we publish no other alias.
We do not publish a postal address for correspondence. If you need to reach us in writing — for example to exercise a right below, or to serve a notice — email the address above and we will reply with a postal address for that purpose. We would rather tell you that plainly than print an address we do not use.
Scope
This notice covers:
- the public website and documentation at sbomflow.com;
- direct enquiries you send us (for example by email or social media);
- business conversations with prospective design partners and customers;
- the relationship between us as the software vendor and the locally run SBOMFlow CLI.
It does not replace any separate agreement. Where a signed pilot, design-partner, or commercial agreement contains its own data-handling terms, that agreement governs the artifacts exchanged under it.
Information you give us
If you email us or contact us on social media, we receive what you send: typically your name, email address or handle, your organisation, and the content of your message. If we work together on an evaluation or pilot, we also hold the business contact details needed to run that engagement.
The website itself has no contact form, sign-up, waitlist, account, checkout, or newsletter, so it does not collect this information for us.
Website & hosting data
The website is a static site served by Vercel Inc. As with any web host, Vercel's infrastructure processes technical request data — such as your IP address, user-agent string, and the pages requested — to deliver, secure, and load-balance the site. We do not add any analytics, measurement, or tracking on top of this. SBOMFlow does not configure a log drain or independently retain visitor access logs. Vercel states that its platform does not store logs derived from static assets by default; request metadata may still be processed transiently to deliver and protect the site. See Vercel's logging guidance ↗.
Cookies & local storage
This site sets no cookies. There is no consent banner because there is nothing to consent to: no analytics, advertising, or tracking storage is used. One functional preference is stored locally in your browser:
| Name | Type | Purpose | Sent to us? |
|---|---|---|---|
sbomflow-docs-theme |
localStorage | Remembers your documentation theme choice (system, light, dark, or high contrast). | No — it never leaves your browser. |
The documentation search downloads a same-origin static index and runs entirely in your browser; your search queries are never transmitted.
The SBOMFlow CLI and your data
The CLI is software you run in your own environment. By default it
makes zero network requests. Your source code, firmware, SBOMs,
file and directory paths, vulnerability findings, reviewer decisions and
notes, and generated evidence artifacts are read and written locally and
are not transmitted to us or anyone else. There is no vendor telemetry,
and the optional local metrics.json is written only when you
ask for it and is never uploaded by SBOMFlow.
Network access happens only on explicit, individually named actions, and each sends the minimum needed:
| Action | Flag / command | What is sent, and to whom |
|---|---|---|
| OSV advisory lookup | --use-osv |
Component package URLs (purls) to the public OSV API (osv.dev). |
| NVD enrichment | --use-nvd |
CVE identifiers to the public NIST NVD API. |
| KEV / EPSS enrichment | --use-kev / --use-epss |
Vulnerability identifiers to the public CISA KEV and FIRST EPSS feeds. |
| West import resolution | --resolve-west-imports |
Requests for imported Zephyr manifests from their source forge. |
| Vulnerability snapshot update | vulndb update |
Requests for public advisory snapshots you pin locally. |
| Tracker sync / notifications | sync-* / notify with --apply |
The issue plan, SBOM, or gate summary you generated, to systems you choose (e.g. your GitHub, Jira, ServiceNow, Dependency-Track, Slack, Teams, or email), using credentials you supply via environment variables. |
These identifiers go to the third parties named above under their own
terms; SBOMFlow does not receive them. Local snapshot files
(--nvd-file, --kev-file, --epss-file)
keep even enrichment fully offline. Every sync and notify command is
dry-run by default and only transmits with an explicit
--apply.
Purposes & lawful bases
- Responding to enquiries and business conversations — our legitimate interest in running and growing the project, or steps taken at your request before entering a contract.
- Operating and securing the website — our legitimate interest in serving a fast, safe static site (technical hosting data).
- Running an agreed evaluation or pilot — performance of that contract.
Where we rely on legitimate interests, we have weighed them against your interests and rights, and you can object at any time by emailing us — we will stop unless we have a compelling reason not to, and we will tell you what it is. We do not rely on consent for anything on this website, because nothing here asks for it. We never use personal data for automated decision-making or profiling.
Recipients & processors
- Vercel Inc. — website hosting and delivery.
- Google Workspace — email hosting for enquiries sent to hello@sbomflow.com.
No other processors are currently used to operate this static website.
We do not sell personal data and we do not share it with advertisers.
International transfers
Our hosting and email providers are established in the United States and may process data there and in other countries where they operate infrastructure. We have not negotiated bespoke transfer terms with either: we rely on the data-processing and transfer terms each provider publishes for its own customers. We would rather say that than paraphrase a mechanism we have not confirmed — if you need to know exactly which safeguard a provider relies on for your jurisdiction, email us and we will point you at that provider's current published terms.
Retention
We do not operate a database of people. What we hold is correspondence, and we keep it against documented criteria rather than a single fixed clock:
- Enquiries that go nowhere — kept while the conversation is live, then until we no longer need it to recognise a returning correspondent, and deleted after that.
- Evaluation and design-partner conversations — kept for the engagement and for as long as we may need to evidence what was agreed, discussed or delivered.
- Records we are required to keep — kept for the period the applicable company, tax or accounting law sets, which overrides the criteria above.
- Security reports — kept for as long as the issue and its remediation record are relevant.
We review what we hold when a conversation closes, and you can ask us to delete your correspondence at any time. We have not published a single retention figure because one number covering all four cases would be less accurate than the criteria above, not more.
Security
The website is a static site served over TLS with a strict Content-Security-Policy, no third-party scripts, and no server-side application code of ours. The CLI's security posture — offline by default, environment-variable-only credentials, no telemetry — is documented publicly in our security & privacy documentation. No measure guarantees perfect security; we describe our safeguards honestly rather than as promises.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise a right, email hello@sbomflow.com.
You can also complain to a supervisory authority. SBOMFLOW TECHNOLOGIES LTD is established in Nigeria, whose authority is the Nigeria Data Protection Commission, created by the Nigeria Data Protection Act 2023 (ndpc.gov.ng ↗). If you are in the UK, that authority is the Information Commissioner's Office (ico.org.uk ↗); in the EEA it is the authority for your country.
Children
The website and product address a business and professional audience. They are not directed at children, and we do not knowingly collect children's data.
Automated decision-making
We make no automated decisions with legal or similarly significant effects about you. The SBOMFlow engine itself is deliberately designed so that evidence acceptance, VEX status, and release decisions come only from human reviewers.
Third-party links
The site links to third parties — for example official European Commission sources, GitHub, X, and Instagram. Their own privacy notices apply on their sites.
Changes to this notice
We will update this notice when the facts change — for example if a form, account system, or analytics were ever added — and will change the "last updated" date above. Significant changes will be highlighted on this page.
Contact
Questions about this notice, or need it in another format? Email hello@sbomflow.com.