Product guide
SBOM, vulnerability, and decision context
Manage OSV data, CycloneDX scans, findings, policies, and risk acceptances in a traceable model.
Responsibility
Intelligence Management ingests vulnerability data, projects SBOM components, and evaluates findings against applicable policy context.
Verified features
- Full or incremental OSV synchronization
- Project- and environment-scoped CycloneDX scanning
- Immutable scan and evaluation history
- Central policy, risk acceptance, CLI, and API automation
Data and evaluation flow
Managed OSV sources update vulnerability data through full or incremental tasks. When a CycloneDX SBOM is scanned in organization, project, and environment context, components, dependencies, and findings are recorded; applicable policy produces a separate evaluation result for that immutable scan input.
Traceability
During technical acceptance, retain the source-synchronization task, SBOM checksum, scan identity, finding match, policy evaluation, and any risk acceptance in one evidence chain.
- Checkpoint, counters, and item-level failure result for full and incremental OSV tasks
- Consistent component, dependency-edge, and finding counts for the same SBOM input
- Separation of the new evaluation from historical results after policy or intelligence changes
- Risk acceptance matched to scope, rationale, expiry, and audit record
Analysis boundary
Verified intelligence scope covers OSV vulnerability data and CycloneDX component relationships. Malware detection, license compliance, namespace confusion, quarantine, and independent-assurance claims are not part of this scope.