Use cases

Real jobs, from a real build.

Every job below starts from the build you actually ship and ends with evidence a human can review, hand off, and reproduce. Built for connected and embedded products first: embedded Linux and industrial IoT, firmware-driven appliances, robotics, smart cameras and edge AI, building controls and OT, and network appliances.

Best fit today: small-to-mid-size embedded Linux and industrial IoT manufacturers with firmware CI and product-security ownership, preparing for CRA obligations — not only web apps.

01

Prepare release-backed CRA evidence

Available today

Assemble traceable, build-backed evidence for one product release and see exactly where it maps to the regulation — and where the gaps are — without anyone claiming conformity.

Inputs
your firmware or software build tree, plus any SBOMs and supplier files you already have
Workflow
one offline audit → composition, findings, CRA coverage, gaps → review workspace
Human boundary
reviewers accept evidence and judge gaps; the tool never concludes conformity
Outputs
evidence pack · CRA coverage map · gap list · reviewer bundle
Outcome
a reviewer-ready evidence pack and an honest picture of where you stand
02

Gate a firmware or software release in CI

Available today

Run on every release candidate in the CI you already have. The gate is informational until you choose a policy to enforce — then it blocks on the conditions you set, with the exact reason recorded and a dry-run to rehearse first.

Inputs
the release candidate build, your gate policy, your existing CI (GitHub Actions, GitLab, Jenkins)
Human boundary
you choose what blocks; waivers are recorded, time-boxed, and surfaced before expiry
Outputs
gate decision with reasons · PR/MR annotations · SARIF · audit-trail entry
Outcome
a deterministic, explainable release decision — not a mystery red X
03

Answer an SBOM or security questionnaire

Available today

Produce validated CycloneDX and SPDX SBOMs, VEX statements, and a coverage summary on demand — so a customer or downstream operator request takes minutes, not a sprint.

Inputs
the shipped release (or its stored release record)
Human boundary
you decide what is shared; the redaction contract is audited, not assumed
Outputs
validated SBOMs · VEX (OpenVEX, CycloneDX, CSAF) · redactable sharing pack
Outcome
standards-based artifacts you can send the same day, with verification hashes
04

Triage vulnerabilities with real context

Available today

Correlate components against public advisories and layer in exploitation signals — known-exploited status, exploit probability, conservative reachability — as inputs for human triage, never automatic verdicts. Matching shows its own confidence, and a range it can't order becomes "needs verification", never a silent decision.

Inputs
your release evidence, an offline advisory snapshot (or explicit OSV/NVD opt-in)
Human boundary
triage outcomes and VEX status come only from reviewers, with justifications checked
Outputs
findings with confidence and provenance · exploitation context · VEX from your decisions
Outcome
less false-positive noise, clearer priorities, decisions that hold up later
05

Sign off a release with accountability

Available today

Route findings and evidence through a review queue, require multi-role approval with separation of duties and a configurable quorum, and record time-boxed exceptions in an append-only, hash-chained trail designed to expose later modification.

Inputs
the release evidence, your approval roles and quorum policy
Human boundary
every approval is a named human act; observed status never becomes acceptance
Outputs
approvals record · gate decision · tamper-evident audit trail
Outcome
a defensible record of who decided what, and why
06

Track what changed between releases

Available today

Compare any two releases — new and resolved findings, component and coverage drift, support-period changes — from a local, content-addressed release store, and share a redacted evidence pack downstream when importers or distributors ask.

Inputs
two release records (current and previous, or any pair)
Human boundary
drift is context; it never closes a finding or passes a gate by itself
Outputs
release record · release drift comparison · portfolio rollup
Outcome
release-to-release continuity you can prove, not reconstruct
07

Keep evidence alive after you ship

Limited preview · experimental

When a new advisory lands, open a PSIRT case on an append-only journal: intake with provenance and duplicate detection, correlation against shipped releases into exposure candidates, recorded human triage, remediation verification, time-boxed risk acceptance, and watermarked UNSIGNED DRAFT advisories. SBOMFlow never files or publishes anything.

Inputs
an advisory file, your stored release records
Human boundary
a candidate is never an "affected" verdict; closure requires human-verified remediation or a named override
Outputs
case journal · exposure candidates · triage record · draft advisory (unsigned)
Outcome
post-market work that builds on release evidence instead of restarting it
08

Understand AI-component and service change

In development · design partners

For AI-enabled products: know which model files and declared AI services shipped in a release, and how they changed since the last approved one — under the same review discipline as everything else. Model files are already recognised and hashed today; the full AI evidence workflow is in development with design partners.

Inputs
your release build (model files included), declared AI facts
Human boundary
declared vs observed conflicts stay visible; humans resolve them
Outputs
today: recognised model-artifact evidence · in development: AI inventory and drift
Outcome
an evidence-backed answer to "what intelligence shipped?"

Your job isn't on this page?

Tell us what your release and post-market process actually looks like — we'll give you a straight answer on whether SBOMFlow fits, and where it doesn't yet.