Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

OPSWAT Bill of Materials

Identify software packages and known vulnerabilities, assess cryptographic risk, and review AI model provenance and declared licenses.

  • Software Component Visibility
  • Post-Quantum Migration Planning
  • AI Model Provenance

OPSWAT is Trusted by

0
Customers Worldwide
0
Technology Partners
0
Endpoint Cert. Members

Automated SBOM,
CBOM & AIBOM
Generation

CycloneDX & SPDX For SBOM 

8.7M+

Third-Party Open-Source
Software Components

CI/CD Pipeline
Integration

Software & AI License Information

Known Vulnerability & Cryptographic Risk Visibility

Inventory Blind Spots Create Risk

Incomplete inventories leave teams reconstructing evidence for vulnerability response, cryptographic migration, and AI model reviews.

Files Arrive Without Component Details

Supplier software and AI model files can arrive without usable inventories, leaving teams to establish package versions, cryptographic dependencies, model provenance, and declared licenses before review.

Growing Compliance and Documentation Requirements

The EU CRA sets SBOM obligations, EO 14412 directs CBOM guidance, and the EU AI Act requires documentation for covered general-purpose AI models. Separate inventories make supporting evidence harder to assemble.

New CVEs Trigger Manual Component Checks

When a new CVE is disclosed, missing package names and versions delay the initial task: identifying which software artifacts need investigation.

  • Missing Inventories

    Files Arrive Without Component Details

    Supplier software and AI model files can arrive without usable inventories, leaving teams to establish package versions, cryptographic dependencies, model provenance, and declared licenses before review.

  • Compliance Evidence

    Growing Compliance and Documentation Requirements

    The EU CRA sets SBOM obligations, EO 14412 directs CBOM guidance, and the EU AI Act requires documentation for covered general-purpose AI models. Separate inventories make supporting evidence harder to assemble.
  • Response Delays

    New CVEs Trigger Manual Component Checks

    When a new CVE is disclosed, missing package names and versions delay the initial task: identifying which software artifacts need investigation.

Analyze, Inventory, Export

STEP 1

Scan Supported Files and Artifacts

STEP 1

Scan Supported Files and Artifacts

Scan source files, binaries, certificates, container content, and AI model files. Analysis coverage depends on the file type and enabled BOM modules.

STEP 2

Run the Enabled BOM Modules

STEP 2

Run the Enabled BOM Modules

Enabled modules generate up to three inventories within one scan result, depending on the submitted file and supported analysis.

STEP 3

Export Individual or Combined Reports

STEP 3

Export Individual or Combined Reports

Generate separate SBOMs in SPDX or CycloneDX, or together with CBOM and AIBOM in JSON or PDF, giving AppSec, PQC, AI governance, Legal, and GRC teams the formats relevant to their work.

  • STEP 1

    Scan Supported Files and Artifacts

    Scan source files, binaries, certificates, container content, and AI model files. Analysis coverage depends on the file type and enabled BOM modules.

  • STEP 2

    Run the Enabled BOM Modules

    Enabled modules generate up to three inventories within one scan result, depending on the submitted file and supported analysis.

  • STEP 3

    Export Individual or Combined Reports

    Generate separate SBOMs in SPDX or CycloneDX, or together with CBOM and AIBOM in JSON or PDF, giving AppSec, PQC, AI governance, Legal, and GRC teams the formats relevant to their work.

Three Inventories. Broader Risk Visibility.

Identify Packages and
Known Vulnerabilities

List package names, versions, license information, critical software updates and known vulnerabilities from 8.7 million third-party libraries.

Assess Cryptographic Risk

Inspect algorithms, libraries, certificates, protocols, and related cryptographic material. Review classical and quantum risks, with recommended replacements where available, to inform migration decisions. 

Match AI Models to
Published Repositories

Match model files to repositories known to publish the same bytes and report available declared licenses, giving reviewers concrete references for provenance and licensing checks.

Analyze Files in Air-
Gapped Environments

Analyze supported files inside isolated networks. With the required databases installed locally, teams can perform BOM reviews without cloud connectivity during scanning.

Consolidate BOM Analysis

Generate software, cryptographic, and AI inventories through one engine, reducing the need to configure separate scanning workflows for each inventory type.

Configure BOM-Based
Blocking Policies

Set software vulnerability thresholds and package license restrictions. Separately enable blocking for cryptographic risk and selected AI model licenses, according to your workflow requirements.

Explore a Unified BOM Scan Result

Inspect the scan summary, switch between SBOM, CBOM, and AIBOM findings, and export the report you need.

Configure SBOM Policies

Set vulnerability severity thresholds, select package licenses to block, and enable dependency checks for source code.

Configure CBOM and AIBOM Policies

Choose whether to block on cryptographic risk or which AI model licenses to restrict.

Review Unified BOM Summary

Compare software, cryptographic, or AI findings for the scanned file, then open each module for details.

Inspect Software Vulnerabilities

Review package version, reported license, associated CVEs, and severity ratings.

Inspect Cryptographic Risk and Evidence

Review classical and quantum risk classifications alongside source evidence showing where cryptographic assets were found.

Inspect AI Model Provenance

Inspect the model format and architecture, then review repositories known to publish the same file.

  • Configure SBOM Policies

    Set vulnerability severity thresholds, select package licenses to block, and enable dependency checks for source code.

  • Configure CBOM and AIBOM Policies

    Choose whether to block on cryptographic risk or which AI model licenses to restrict.

  • Review Unified BOM Summary

    Compare software, cryptographic, or AI findings for the scanned file, then open each module for details.

  • Inspect Software Vulnerabilities

    Review package version, reported license, associated CVEs, and severity ratings.

  • Inspect Cryptographic Risk and Evidence

    Review classical and quantum risk classifications alongside source evidence showing where cryptographic assets were found.

  • Inspect AI Model Provenance

    Inspect the model format and architecture, then review repositories known to publish the same file.

Integrations & Supported Languages

Use Cases

Investigate a Newly Disclosed CVE

Check scanned artifacts for the affected package and version to scope the team's remediation work.

Plan Post-Quantum Migration

Use cryptographic findings and recommended replacements to identify assets needing specialist review before migration planning.

Review an AI Model Before Deployment

Review known publishing repositories and available declared licenses before approving a model for application use.

Secure Every Dependency.
Reduce Risk. Ship Safely.

Fill out the form and we’ll be in touch within 1 business day.
Trusted by 2,100+ businesses worldwide.