Firmpath

Draft. Answers to the questions a security team asks before uploading an SBOM, written from how the service works today. Published together with the legal pages.

Security

Last updated date of publication

In short. Your SBOM is stored encrypted, is only ever served to people in your account, and is analysed without any AI model. To look up your components, we send their names and versions to public vulnerability databases, but never who you are. You can delete any of it yourself, at any time.

Where does an uploaded SBOM go?

Who can see it?

How do people sign in?

Can we delete our data?

Yes, yourselves, from the app: one release, a whole product, or the entire account. Deletion removes the file, its analysis, your decisions about its findings and every alert sent about it. Closing an account leaves no copy of its members' email addresses. The database keeps restorable history for up to 30 days, so within 30 days nothing remains.

What do you keep a record of?

Every decision with consequences is recorded with who made it and when: a vulnerability marked "not affected", a colleague added or removed, an upload withdrawn, a deletion. Under the Cyber Resilience Act you need to show who decided what about a vulnerability, and this is that record.

What about the vendor documents you show us?

We archive vendor advisories exactly as published, and you can always open the original. Content fetched from the internet is treated as hostile. It is displayed with raw HTML disabled, then cleaned, under a policy that allows no inline scripts and no loads from other sites, including images.

Found a security problem?

Tell us at security contact. We welcome good-faith reports and won't treat them as a breach of our terms. Please give us a reasonable time to fix the problem before publishing.

Who else handles data, and where: Privacy Policy.