For teams that ship firmware
Upload an SBOM for something you ship. We take the SDK apart, check every library in it against NVD and against what your chip vendors publish themselves, and show you which advisories reach your build. Each one links to the vendor's own document.
Free for one product. No card and no password: we email you a sign-in code.
Two to fix, one to look at, and two you can close with a VEX statement.
Why
Most scanners look each package up in NVD by name and version. Plenty of what affects firmware never shows up that way, even when it has a CVE.
Espressif, Silicon Labs and Nordic publish advisories of their own that never get a CVE. A CVE-keyed scanner has nothing to match.
A CVE can exist for weeks before NVD has a record of it, or links it to any product. Until then a lookup comes back empty.
NVD lists the bug against the SDK while your SBOM names the library, or against upstream while you ship a vendor's fork. The names don't match, so nothing is reported.
How it works
A CycloneDX or SPDX file, the output of west spdx or esp-idf-sbom, a platformio.ini, or the address of a public GitHub repository.
An SBOM usually names the SDK and stops there. We read that exact release of ESP-IDF, Zephyr, nRF Connect and others to see which libraries it bundles, at which versions.
Each one says why it applies: your version against the vendor's affected range, or the actual code in a vendor's fork. The vendor's own document is one click away.
Mark findings not affected, with a reason. Export them as CSV or a VEX file, or print a report for a customer or an auditor.
The CRA
Wherever it's made. Fines go up to €15M or 2.5% of worldwide turnover. Most of the work is knowing what's in each product, dealing with what turns up, and being able to show what you decided and when.
Manufacturers' obligations became law and the phase-in started.
Once you know an exploited vulnerability is in your product, you have 24 hours to send an early warning, 72 for a notification, then a final report. Your users have to be told too.
An SBOM per product, a disclosure policy and contact, security updates for at least five years, published fixes, and documentation kept for ten.
What you get
Affected, not affected, or needs a look, each with one sentence of why and the vendor's document behind it.
Vendor advisories read straight from the vendor, so the ones a CVE scanner can't see are in the list too.
Your own decisions as a CycloneDX VEX file, every finding as CSV, and a report that prints cleanly.
CycloneDX VEX · CSV · PDF
Your current releases are checked again every day, and you get an email when a new advisory reaches one.
Findings on CISA's known-exploited list are marked, because those are the ones the 24-hour clock is about.
Invite colleagues to your account. Delete a release, a product or the whole account yourself, whenever you want.
On the way: help with the CRA's 24-hour reports, drafted customer notices, and a step for your CI so every build gets checked without an upload.
Works with
If your toolchain writes an SBOM, upload that. If all you know is the SDK and its version, an SBOM that names just that is enough to start. We work out what the release bundles.
You don't need to replace a scanner, change your build, or send us firmware images. We only see component names and versions.
SDKs we take apart
Files we read
Where advisories come from
Where we're at
Finding what reaches your build works today. The reporting side we'd rather design with people who do this job, so if you get in touch, expect questions from us too.
Pricing
A product is one thing you ship. Uploading its next release replaces the last, so keeping it up to date never costs more.
Free
€0
1 product
Pro
€200/month
up to 5 products · or €2,000 a year · excl. VAT
Pro is open to early customers. Tell us what you ship on.
Larger teams
Let's talk
more than 5 products
Questions
platformio.ini works as it is. If all you know is the SDK and its version, an SBOM that names just that is enough to start. We take the release apart into what it bundles.Get in touch
Send a note and one of us will reply, usually within a couple of working days. If it doesn't sound like a fit, we'll say so.
Thanks, we've got it. One of us will be in touch.
Prefer email? Write to [email protected]. We only use your address to reply.