Skip to content
SBOMFlow
The release record Available Embedded & container builds Available Vulnerability review Available Supplier evidence Available Runtime & test evidence Experimental Post-market & PSIRT cases Preview AI evidence In development EU CRA readiness one optional regime Available
Use cases Walkthrough Metrics Trust Docs
Benchmark Accuracy scorecard What's new v0.5.0 release notes About Contact
Design partners
Building in the open

Products

The release record Available Embedded & container builds Available Vulnerability review Available Supplier evidence Available Runtime & test evidence Experimental Post-market & PSIRT cases Preview AI evidence In development EU CRA readiness one optional regime Available

Explore

Use cases Walkthrough Metrics Trust Benchmark Accuracy scorecard Documentation What's new v0.5.0 release notes About Contact Design partners

On this page

Summary Who we are Scope Information you give us Website & hosting data Cookies & local storage The CLI and your data Purposes & lawful bases Recipients & processors International transfers Retention Security Your rights Children Automated decisions Third-party links Changes Contact
In plain English. This website sets no cookies, runs no analytics and has no forms, so it collects nothing about you beyond the technical request data any web host handles. The product is a command-line tool that runs on your own machines and sends nothing anywhere unless you pass a named flag. The only personal data we normally hold is an email you chose to send us.

Legal

Privacy notice

Effective date: 20 September 2026 · Last updated: 22 September 2026

Summary

SBOMFlow is a local, offline-by-default command-line product with a static marketing and documentation website. In plain terms:

  • This website has no accounts, no forms, no analytics, no advertising, and no tracking cookies. Its JavaScript handles navigation and progressive enhancement only.
  • The SBOMFlow CLI runs on your own machines. By default your source code, firmware, SBOMs, file paths, findings, reviewer notes, and generated reports never leave your environment, and there is no vendor telemetry.
  • The only personal data we normally receive is what you choose to send us — for example an email enquiry.

Who we are

SBOMFlow is operated by SBOMFLOW TECHNOLOGIES LTD, a private company limited by shares incorporated in the Federal Republic of Nigeria under the Companies and Allied Matters Act 2020, company registration number 9845783, incorporated at Abuja on 10 September 2026. It is the controller for the personal data described in this notice.

Contact: hello@sbomflow.com. This is the single address for every kind of enquiry, including data-protection requests and security reports; we publish no other alias.

We do not publish a postal address for correspondence. If you need to reach us in writing — for example to exercise a right below, or to serve a notice — email the address above and we will reply with a postal address for that purpose. We would rather tell you that plainly than print an address we do not use.

Scope

This notice covers:

  • the public website and documentation at sbomflow.com;
  • direct enquiries you send us (for example by email or social media);
  • business conversations with prospective design partners and customers;
  • the relationship between us as the software vendor and the locally run SBOMFlow CLI.

It does not replace any separate agreement. Where a signed pilot, design-partner, or commercial agreement contains its own data-handling terms, that agreement governs the artifacts exchanged under it.

Information you give us

If you email us or contact us on social media, we receive what you send: typically your name, email address or handle, your organisation, and the content of your message. If we work together on an evaluation or pilot, we also hold the business contact details needed to run that engagement.

The website itself has no contact form, sign-up, waitlist, account, checkout, or newsletter, so it does not collect this information for us.

Website & hosting data

The website is a static site served by Vercel Inc. As with any web host, Vercel's infrastructure processes technical request data — such as your IP address, user-agent string, and the pages requested — to deliver, secure, and load-balance the site. We do not add any analytics, measurement, or tracking on top of this. SBOMFlow does not configure a log drain or independently retain visitor access logs. Vercel states that its platform does not store logs derived from static assets by default; request metadata may still be processed transiently to deliver and protect the site. See Vercel's logging guidance ↗.

Cookies & local storage

This site sets no cookies. There is no consent banner because there is nothing to consent to: no analytics, advertising, or tracking storage is used. One functional preference is stored locally in your browser:

Browser storage used by sbomflow.com
NameTypePurposeSent to us?
sbomflow-docs-theme localStorage Remembers your documentation theme choice (system, light, dark, or high contrast). No — it never leaves your browser.

The documentation search downloads a same-origin static index and runs entirely in your browser; your search queries are never transmitted.

The SBOMFlow CLI and your data

The CLI is software you run in your own environment. By default it makes zero network requests. Your source code, firmware, SBOMs, file and directory paths, vulnerability findings, reviewer decisions and notes, and generated evidence artifacts are read and written locally and are not transmitted to us or anyone else. There is no vendor telemetry, and the optional local metrics.json is written only when you ask for it and is never uploaded by SBOMFlow.

Network access happens only on explicit, individually named actions, and each sends the minimum needed:

Named opt-in network actions in the SBOMFlow CLI
ActionFlag / commandWhat is sent, and to whom
OSV advisory lookup --use-osv Component package URLs (purls) to the public OSV API (osv.dev).
NVD enrichment --use-nvd CVE identifiers to the public NIST NVD API.
KEV / EPSS enrichment --use-kev / --use-epss Vulnerability identifiers to the public CISA KEV and FIRST EPSS feeds.
West import resolution --resolve-west-imports Requests for imported Zephyr manifests from their source forge.
Vulnerability snapshot update vulndb update Requests for public advisory snapshots you pin locally.
Tracker sync / notifications sync-* / notify with --apply The issue plan, SBOM, or gate summary you generated, to systems you choose (e.g. your GitHub, Jira, ServiceNow, Dependency-Track, Slack, Teams, or email), using credentials you supply via environment variables.

These identifiers go to the third parties named above under their own terms; SBOMFlow does not receive them. Local snapshot files (--nvd-file, --kev-file, --epss-file) keep even enrichment fully offline. Every sync and notify command is dry-run by default and only transmits with an explicit --apply.

Purposes & lawful bases

  • Responding to enquiries and business conversations — our legitimate interest in running and growing the project, or steps taken at your request before entering a contract.
  • Operating and securing the website — our legitimate interest in serving a fast, safe static site (technical hosting data).
  • Running an agreed evaluation or pilot — performance of that contract.

Where we rely on legitimate interests, we have weighed them against your interests and rights, and you can object at any time by emailing us — we will stop unless we have a compelling reason not to, and we will tell you what it is. We do not rely on consent for anything on this website, because nothing here asks for it. We never use personal data for automated decision-making or profiling.

Recipients & processors

  • Vercel Inc. — website hosting and delivery.
  • Google Workspace — email hosting for enquiries sent to hello@sbomflow.com.

No other processors are currently used to operate this static website.

We do not sell personal data and we do not share it with advertisers.

International transfers

Our hosting and email providers are established in the United States and may process data there and in other countries where they operate infrastructure. We have not negotiated bespoke transfer terms with either: we rely on the data-processing and transfer terms each provider publishes for its own customers. We would rather say that than paraphrase a mechanism we have not confirmed — if you need to know exactly which safeguard a provider relies on for your jurisdiction, email us and we will point you at that provider's current published terms.

Retention

We do not operate a database of people. What we hold is correspondence, and we keep it against documented criteria rather than a single fixed clock:

  • Enquiries that go nowhere — kept while the conversation is live, then until we no longer need it to recognise a returning correspondent, and deleted after that.
  • Evaluation and design-partner conversations — kept for the engagement and for as long as we may need to evidence what was agreed, discussed or delivered.
  • Records we are required to keep — kept for the period the applicable company, tax or accounting law sets, which overrides the criteria above.
  • Security reports — kept for as long as the issue and its remediation record are relevant.

We review what we hold when a conversation closes, and you can ask us to delete your correspondence at any time. We have not published a single retention figure because one number covering all four cases would be less accurate than the criteria above, not more.

Security

The website is a static site served over TLS with a strict Content-Security-Policy, no third-party scripts, and no server-side application code of ours. The CLI's security posture — offline by default, environment-variable-only credentials, no telemetry — is documented publicly in our security & privacy documentation. No measure guarantees perfect security; we describe our safeguards honestly rather than as promises.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise a right, email hello@sbomflow.com.

You can also complain to a supervisory authority. SBOMFLOW TECHNOLOGIES LTD is established in Nigeria, whose authority is the Nigeria Data Protection Commission, created by the Nigeria Data Protection Act 2023 (ndpc.gov.ng ↗). If you are in the UK, that authority is the Information Commissioner's Office (ico.org.uk ↗); in the EEA it is the authority for your country.

Children

The website and product address a business and professional audience. They are not directed at children, and we do not knowingly collect children's data.

Automated decision-making

We make no automated decisions with legal or similarly significant effects about you. The SBOMFlow engine itself is deliberately designed so that evidence acceptance, VEX status, and release decisions come only from human reviewers.

Third-party links

The site links to third parties — for example official European Commission sources, GitHub, X, and Instagram. Their own privacy notices apply on their sites.

Changes to this notice

We will update this notice when the facts change — for example if a form, account system, or analytics were ever added — and will change the "last updated" date above. Significant changes will be highlighted on this page.

Contact

Questions about this notice, or need it in another format? Email hello@sbomflow.com.

SBOMFlow is not legal advice and does not claim product conformity or regulatory approval. It never files regulatory reports. Human review remains required.

Home Docs Privacy Terms