Third parties and supply chain

xBOM

Software and supply-chain bills of materials

A signed inventory of everything you ship, scored against the regulator.

Software bills of materials with cryptography, AI-model, hardware and quantum-exposure inventories on one CycloneDX core. Ingest projects from GitHub, GitLab or CycloneDX uploads, match components against the major vulnerability feeds, triage findings and record VEX verdicts, run signed regulator packs for CERT-In, SEBI, RBI and NPCI, and read one posture score with clause-level citations.

  • SBOM · CBOM · AIBOM · HBOM · QBOMFive BOM types on one core
  • CERT-In · SEBI · RBI · NPCISigned regulator packs
  • Clause-citedOne posture score

How it runs.

  1. 01IngestProjects arrive from GitHub, GitLab or a CycloneDX upload; catalogers build the component graph.
  2. 02MatchComponents meet the vulnerability feeds; KEV and EPSS mark what matters.
  3. 03TriageAnalysts work the queue, record VEX verdicts and trace a CVE's blast radius across projects.
  4. 04EvaluateSigned regulator packs run their rules and keep the evidence.
  5. 05ScoreWeighted parameters roll into one posture score with a 30-day delta and a twelve-month trend.

What xBOM does.

  • Five BOM types
    SBOM catalogers across the major ecosystems, plus CBOM, AIBOM, HBOM and QBOM generators on the same component graph.
  • Vulnerability feeds
    OSV, GHSA, NVD, CISA KEV and FIRST EPSS, delivered as signed blobs or carried in by USB.
  • Triage with reachability
    A tenant-wide queue and workflow; reachability is KEV-listed, on a production path and not blocked by VEX.
  • VEX in every format
    Produce and consume CycloneDX VEX, OpenVEX and CSAF, and download a real advisory from the product.
  • Signed regulator packs
    Packs for CERT-In, SEBI CSCRF, RBI and NPCI, applied by sector and producing signed evidence.
  • One posture score
    Weighted parameters, each anchored to a regulator clause and page you can open inside the product, in English or Hindi.

Deploy on your terms.

  • On-premises
    A single binary on Podman, Helm or systemd, with PostgreSQL and NATS.
  • Air-gapped
    Feed bundles imported from a USB drop zone; the daemon refuses to boot on a tampered pack.
  • Cloud
    India-hosted and multi-tenant, with the same row-level isolation.

Integrations and standards.

Source control
  • GitHub App
  • GitLab
Formats
  • CycloneDX
  • CycloneDX VEX
  • OpenVEX
  • CSAF
  • PURL
  • CPE
  • in-toto
  • DSSE
Regulator packs
  • CERT-In SBOM guidelines
  • SEBI CSCRF
  • RBI IT governance and PSO directions
  • NPCI UPI ISCF

Where teams deploy it.

  • CERT-In SBOM guideline compliance
  • SEBI CSCRF software supply-chain controls
  • RBI and NPCI audit evidence
  • Post-quantum cryptography migration planning
  • Vulnerability triage for critical infrastructure

See xBOM in your environment.

Book a 30-minute walkthrough tailored to your stack, regulators and current security posture. No generic pitch deck, just your questions answered by a senior practitioner.

xBOM - Cybervahak