Product

One evidence lifecycle, not a wall of features.

SBOMFlow follows a release from identity to post-market: every stage adds evidence to the same record, every consequential decision stays human, and every capability below carries its real status. The machine-checked source of truth is the capability matrix in the docs.

Available today Limited preview · experimental In development Planned
01

Release identity & provenance

Available today

Evidence is only defensible if it names exactly what it describes. Every run pins a product and release identity, hashes every scanned file, and records the provenance of every fact — so each claim traces to the exact bytes it came from, and a result can be reproduced long after the release.

Automatic: stable identifiers, file hashing, provenance on every record, deterministic artifacts. Yours: what counts as a product, a release, and a variant.
02

Composition & SBOMs

Available today

SBOMFlow reads real builds — firmware trees (Buildroot, Yocto, Zephyr), container images, lockfiles across the common and the embedded ecosystems (Conan for C/C++, NuGet, npm, pnpm, yarn, bun, Go, Rust, Python, Ruby, PHP, Swift and more), and the SBOMs your suppliers send — and generates validated, reproducible CycloneDX and SPDX from what it observed. Imported supplier data is kept distinct from locally observed evidence, declared and file-based licences resolve into SPDX expressions, and secure-update artifacts (TUF/Uptane metadata, update manifests) are recorded as evidence. Signature material such as cosign and Sigstore bundles is recorded as present — never silently "verified".

Automatic: composition, dependency edges, licence evidence, SBOM validation. Yours: which inputs are in scope; what a supplier claim is worth.
03

Vulnerabilities & exploitation context

Available today

Components are correlated against advisories — offline by default, with OSV and NVD as explicit network opt-ins — using version-range-aware matching that shows its own confidence on every finding. Cross-source aliases are reconciled so one real vulnerability is never double-counted; withdrawn advisories are excluded and recorded. KEV, EPSS, SSVC suggestions, and conservative reachability arrive as labelled inputs for human triage. VEX statements are authored from reviewer decisions and supplier VEX (OpenVEX, CSAF) is ingested as context — a supplier's "not affected" never silently closes your finding.

Automatic: matching, alias reconciliation, confidence labelling, exploitation-signal enrichment. Yours: triage outcomes, VEX status, what a finding means for your product.
04

Regulatory evidence maps

Available today

Observed evidence maps to a versioned model of the EU Cyber Resilience Act — Annex I, Annex VII, Article 14 — with technical-documentation workspaces, SBOM field-presence checks against NTIA minimum elements and BSI TR-03183-2, and evidence gaps stated plainly. Manual-only areas are labelled, not failed. Every draft is watermarked UNSIGNED, and nothing is ever filed: the output is an engineering gap assessment, never a conformity conclusion. Additional regime views beyond the CRA ship as an experimental preview.

Automatic: coverage mapping, presence checks, gap lists, unsigned drafts. Yours: the conformity judgment — with your assessor, notified body, or counsel.
05

Human review, approvals & explainable gates

Available today

Findings and evidence flow through a review queue into multi-role sign-off with separation of duties and a configurable approval quorum. Release gates are informational until you enforce a policy — then they block with the exact reason recorded, and you can rehearse any gate with a dry run first. Licence risk gates the same way vulnerabilities do. Time-boxed waivers surface before they expire, and everything lands on an append-only, hash-chained audit trail designed to expose later modification.

Automatic: queueing, gate evaluation, audit chaining, waiver expiry surfacing. Yours: every acceptance, every approval, every enforced policy.
06

CI & workflow integrations

Available today

SBOMFlow runs in the CI you already have (GitHub Actions, GitLab, Jenkins), exports SARIF and CSV, and syncs findings to GitHub, Jira, ServiceNow, and Dependency-Track — dry-run by default, apply only on explicit opt-in. Gate verdicts land as native annotations on a pull or merge request, offline and output-only. Sealed results from an external AI-assisted scanner can be imported as clearly-labelled, needs-review observations — SBOMFlow never runs the scanner and never re-derives its findings.

Automatic: exports, annotations, dry-run previews. Yours: every apply, every token (environment-only), every tracker workflow.
07

Release memory & drift

Available today

This is what makes SBOMFlow a system of record rather than a scanner: a local, content-addressed store keeps every release's evidence. Query it across products and versions, roll up a portfolio view, and compare any two releases — new and resolved findings, component and coverage drift, support-period changes. Past releases can be backfilled as clearly-labelled declared records, never presented as observed. Drift is context for your decisions; it never closes a finding by itself.

Automatic: history, drift computation, portfolio rollups. Yours: what a change means, and whether it blocks a release.
Illustrative brand animation · synthetic · not product UI
08

Portable sharing & verification

Available today · passport experimental

Every output is a portable file. A static reviewer console and evidence bundle open in any browser with nothing installed; a no-install auditor package exists for exactly that handoff; a redaction-audited sharing pack covers importers and distributors. Hashes travel with the evidence so a recipient can verify nothing was altered. The assurance passport — a self-contained, hash-attested pack per release with a counts-only decision summary and optional Ed25519 signature, verifiable offline by the recipient — ships today as an experimental preview.

Automatic: bundling, redaction audit, hash attestation, recipient-side verification. Yours: what is shared, with whom, and what stays internal.
09

Post-market & PSIRT cases

Limited preview · experimental

When a new advisory arrives after you ship, the case workflow opens a PSIRT case on an append-only, hash-chained journal: advisory intake with provenance and duplicate detection, correlation against shipped releases into exposure candidates — never automatic "affected" verdicts — human triage, remediation verification against a fixing release, time-boxed risk acceptance, and recorded communications. Advisory exports are watermarked UNSIGNED DRAFTs; SBOMFlow never files, publishes, or sends anything. Interfaces may still change — design partners are shaping this toward production.

Automatic: journaling, correlation into candidates, duplicate detection, chain verification. Yours: every assessment, every disclosure decision, every submission.
10

AI Evidence

In development · design partners

AI-enabled products depend on more than packages: models, datasets, prompts, services, and agents ship too. SBOMFlow is extending the same release record to that evidence. Today the 0.4 release line ships the first foundations — release-grade identification of shipped model artifacts from bytes (hashed, never executed or deserialised) with identification strength recorded per artifact — and the standard scanner already surfaces model files as recognised evidence rather than ignoring them. Operator-facing AI evidence commands and standards-based AI/ML BOM output are in engineering with design partners.

What you get

Outputs you can read, diff, and hand to a reviewer.

A consistent set of evidence you actually own — portable files, not a black box. Each one is observed evidence pending human review, not proof of compliance.

SBOMs
CycloneDX and SPDX (2.3 & 3.0.1) component inventories — validated and reproducible.
Evidence pack
One structured, machine-readable record of components, findings, coverage, and provenance.
Assessment report
A human-readable view that separates observed evidence from reviewed evidence.
CRA coverage
Where evidence maps to the regulation's requirements — and where gaps remain.
Release gate & approvals
A pass/fail decision with the exact policy, reason, and sign-off state — informational unless you enforce it.
Reviewer console & bundles
A single-file static reviewer console you open in a browser, a portable verifiable handoff, a redactable importer/distributor pack, and a no-install auditor package.
Audit trail & drift
A tamper-evident, hash-chained run record and a release-to-release comparison.
SARIF · CSV · VEX · traceability
VEX in OpenVEX, CycloneDX, and CSAF 2.0, plus SARIF, CSV, and a cross-entity index — so evidence drops into the tools and trackers you already run.

With inputs and run context pinned, release artifacts are reproducible; opt-in phase durations are explicitly excluded from determinism checks. Many outputs are optional, and any draft declaration is clearly marked unsigned and incomplete for a person to finish. Full inventory: evidence outputs · artifact schemas.

In engineering now

Planned · not yet available

Accuracy — the remaining tail

  • Maven-native version-range ordering. Today such ranges surface as low-confidence "needs verification" for a human instead of deciding silently.
  • SBOM export conformance and round-trip stability across CycloneDX and SPDX.

AI Evidence & post-market, production-grade

  • Operator-facing AI evidence commands and standards-based AI/ML BOM output, shaped with design partners.
  • Hardening the limited-preview PSIRT case workflow into a production post-market surface.

Sharing & worldwide coverage

  • Supplier-facing VEX authoring for downstream operators, on top of today's redacted sharing packs.
  • Worldwide regime coverage maps, demand-driven — the same evidence pack mapped to what other regimes ask for; observed facts and gaps, never a verdict.

This is our direction, not a commitment. Planned items are not yet available, may change, and imply no delivery date or compliance guarantee.

See it on your own build, not a demo repo.

A first audit runs offline on a laptop and produces a complete evidence pack from your real firmware or software build in minutes.