xBOM
Software and supply-chain bills of materials
A signed inventory of everything you ship, scored against the regulator.
Software bills of materials with cryptography, AI-model, hardware and quantum-exposure inventories on one CycloneDX core. Ingest projects from GitHub, GitLab or CycloneDX uploads, match components against the major vulnerability feeds, triage findings and record VEX verdicts, run signed regulator packs for CERT-In, SEBI, RBI and NPCI, and read one posture score with clause-level citations.
- SBOM · CBOM · AIBOM · HBOM · QBOMFive BOM types on one core
- CERT-In · SEBI · RBI · NPCISigned regulator packs
- Clause-citedOne posture score
How it runs.
- 01IngestProjects arrive from GitHub, GitLab or a CycloneDX upload; catalogers build the component graph.
- 02MatchComponents meet the vulnerability feeds; KEV and EPSS mark what matters.
- 03TriageAnalysts work the queue, record VEX verdicts and trace a CVE's blast radius across projects.
- 04EvaluateSigned regulator packs run their rules and keep the evidence.
- 05ScoreWeighted parameters roll into one posture score with a 30-day delta and a twelve-month trend.
What xBOM does.
- Five BOM typesSBOM catalogers across the major ecosystems, plus CBOM, AIBOM, HBOM and QBOM generators on the same component graph.
- Vulnerability feedsOSV, GHSA, NVD, CISA KEV and FIRST EPSS, delivered as signed blobs or carried in by USB.
- Triage with reachabilityA tenant-wide queue and workflow; reachability is KEV-listed, on a production path and not blocked by VEX.
- VEX in every formatProduce and consume CycloneDX VEX, OpenVEX and CSAF, and download a real advisory from the product.
- Signed regulator packsPacks for CERT-In, SEBI CSCRF, RBI and NPCI, applied by sector and producing signed evidence.
- One posture scoreWeighted parameters, each anchored to a regulator clause and page you can open inside the product, in English or Hindi.
Deploy on your terms.
- On-premisesA single binary on Podman, Helm or systemd, with PostgreSQL and NATS.
- Air-gappedFeed bundles imported from a USB drop zone; the daemon refuses to boot on a tampered pack.
- CloudIndia-hosted and multi-tenant, with the same row-level isolation.
Integrations and standards.
- Source control
- Formats
- Regulator packs
Where teams deploy it.
- CERT-In SBOM guideline compliance
- SEBI CSCRF software supply-chain controls
- RBI and NPCI audit evidence
- Post-quantum cryptography migration planning
- Vulnerability triage for critical infrastructure
Pairs with the other third parties and supply chain products.
See xBOM in your environment.
Book a 30-minute walkthrough tailored to your stack, regulators and current security posture. No generic pitch deck, just your questions answered by a senior practitioner.