Supply Chain Security · SBOM · AI-BOM

SupplyTrust
End-to-End Visibility. From Code to Cloud.

Every application you ship is mostly code you did not write. SupplyTrust inventories each component across source, build, container, cloud and AI — in SPDX and CycloneDX — keeps watching it after release, and tells you which disclosures actually reach your running systems.

The Problem

Your software supply chain is bigger than you think—and harder to trust.

Modern software depends on components, suppliers, containers, APIs, cloud services, and AI models.

  • Unknown Third-Party & Transitive Dependencies

    Hidden dependencies make software composition difficult to understand and secure.

  • No Complete Software Supply Chain Visibility

    Disconnected SBOMs, repositories, vendors, and components obscure the complete supply chain.

  • Vulnerabilities Can Enter Through Trusted Components

    Trusted packages can introduce vulnerabilities, malware, and hidden exposure.

  • Supply Chain Attacks Are Difficult to Detect

    Tampered packages, dependency confusion, and malicious components can appear legitimate.

  • AI & Third-Party Components Add New Supply Chain Risk

    AI models, datasets, APIs, and plugins create new dependency risks.

  • Compliance & Risk Tracking Is Not Continuous

    Changing dependencies quickly make SBOM, compliance, and supplier risk assessments outdated.

Modern software

  • Components
  • Suppliers
  • Containers
  • APIs
  • Cloud services
  • AI models

SupplyTrust

SECURE • VERIFY • TRUST YOUR SUPPLY CHAIN

End-to-End Visibility. From Code to Cloud.

  • SBOM

    SPDX + CycloneDX

  • AI-BOM

    Models & Datasets

  • VEX

    Exploitability

  • Real-Time CVE Watch

  • Compliance

    50+ Standards

  • Supplier Risk Assessment

  • Third-Party Risk Visibility

  • Policy & Governance

    Automated Controls

  • Source Code

    Repositories
  • Build

    CI/CD Pipelines
  • Containers

    Registries
  • Cloud

    Artifacts & Images
  • AI/ML

    Models & Datasets
SPDXSTANDARD

SupplyTrust

TRUST EVERY COMPONENT

CycloneDXSTANDARD

AI-BOM

INTELLIGENCE FOR A SAFER SUPPLY CHAIN
  • Risk Visibility

    Know Your Risk
  • Trusted Components

    Verify & Assure
  • Vulnerability Insights

    Prioritize What Matters
  • Compliance Ready

    Audit with Confidence
  • Supplier Intelligence

    Stronger Partnerships
  • Reduce Risk
  • Faster Response
  • Stronger Compliance
  • More Resilient Business

BUILD SECURELY. TRUST CONTINUOUSLY.

Coverage & Integrations

Sources and standards

Every place a component enters your estate, in the formats auditors and tools already read.

Standards & Formats
  • SPDX
  • CycloneDX
  • VEX
  • OpenSSF Scorecard
  • SLSA
  • in-toto
  • Sigstore
Component Sources
  • GitHub
  • GitLab
  • Container Registries
  • AWS
  • Azure
  • Google Cloud
  • Oracle Cloud
  • Kubernetes
  • Artefact Repositories
  • AI Model Registries
Ecosystems
  • npm
  • PyPI
  • Maven
  • Go Modules
  • NuGet
  • RubyGems
  • Cargo
  • Base Images

FAQ

Frequently asked questions

What is the difference between an SBOM and an AI-BOM?

An SBOM lists the software components in a build — packages, libraries, base image layers. An AI-BOM extends the same idea to the AI supply chain: which pretrained models, fine-tuning datasets and vector stores a system depends on, and where each came from. SupplyTrust produces both from the same inventory.

Which SBOM formats do you produce?

SPDX and CycloneDX, the two formats tooling and auditors actually consume. Inventories are generated per build and kept versioned, so you can produce the bill of materials for a specific released artefact rather than for today's main branch.

How does VEX reduce the noise?

Most components a disclosure names are present but not reachable in your code path. A VEX statement records that judgement — affected, not-affected, under investigation, fixed — with the reasoning attached, so the same finding does not have to be re-triaged by every team that inherits it.

Does this replace our vulnerability scanner?

No. VulSense finds and prioritises vulnerabilities across the running estate; SupplyTrust answers what is in what you ship, where it came from and whether you can trust it. They share one asset graph, so a disclosure reaching a component resolves straight to the services and images that carry it.

Can it enforce policy, or only report?

Both. Licence rules, minimum versions, banned components and unsigned-artefact rules can be reported for visibility first, then enforced as pipeline gates once you are confident in the inventory.

Know what you ship

Connect a repository and a registry and watch the component inventory build itself — SBOM, AI-BOM and supplier rollup included.