Build, Scan & Prove Your SBOM — On Your Terms
ESL SBOMator is the all-in-one Software Bill of Materials platform: generate CycloneDX 1.6 & SPDX SBOMs, detect CVEs and license risk, and produce audit-ready evidence across software, firmware, hardware, and AI. Runs 100% on-premises or fully air-gapped — your source never leaves your perimeter.
More Than a Manifest Scanner
SBOMator integrates capabilities normally split across SCA, firmware analysis, AI governance, hardware inventory, endpoint monitoring, and compliance tooling โ connected into one evidence model.
Source Never Leaves Your Perimeter
Full analysis on your desktop, server, or CI runner โ no source upload, no telemetry, ready for regulated and air-gapped builds.
The Delivered Firmware Is the Boundary
Package lock files aren’t enough for embedded products. SBOMator follows evidence into binaries, archives, and firmware images โ not just the developer workstation.
Endpoint Reality Becomes Evidence
EDR-SBOM inventories installed software, MCP servers, and agent skills on real endpoints, detects integrity drift, and routes actionable alerts.
Evidence, Not Promises
Every claim points to an SBOM, VEX, scan result, hash, or approved record โ with a fail-closed quality gate and preserved manufacturer-review boundaries.
One Platform. Six Technical Planes.
Every major capability has its own deep-dive page. Start with the core scan-to-decision engine, or jump straight to the area you need.
Scan, Vulnerability & VEX
The core engine: CycloneDX 1.6 & SPDX across 15+ ecosystems, NVD/OSV/Grype with KEV, EPSS and CVSS v4.0, reachability-aware VEX, and a PyQt6 dashboard with Droid-as-Judge triage.
Learn more โEmbedded, Firmware & Native
Yocto/BitBake and Zephyr Kconfig-aware analysis, RTOS recognition (ThreadX, FreeRTOS, VxWorks, Micriumโฆ), cross-architecture binaries, and recursive firmware unpacking.
Learn more โHardware BOM โ FPGA & C-SCRM New
Xilinx MPSoC/RFSoC workflow โ Vivado IP, VHDL, HLS, bitstreams, boot artifacts, and PetaLinux ELF into nested CycloneDX HBOM with supplier and country-of-origin evidence.
Learn more โAI, Agents & Datasets New
G7-aligned AI/ML-BOM, hashed model artifacts, MCP integrity, HalluSquatting protection, SkillSpector + Droid agent-skill security, and local DataBOM dataset provenance.
Learn more โEDR-SBOM & Threat Detection New
Bumblebee endpoint inventory, integrity drift, and real-time HalluSquatting plus malicious-package detection โ proven against the keyv/cacheable “Mini Shai-Hulud” attack (Aug 2026).
Learn more โRegulatory Evidence โ CRA & FDA
EU CRA Annex VII index and DoC drafts, FDA Section 524B evidence with COMPLIANT/PARTIAL status mapping, IEC 62443, and OpenChain โ signed and hash-chained, review boundaries preserved.
Learn more โRuns Where You Do
The same generation engine powers the desktop GUI, the headless CLI, and the API โ on-premises or fully air-gapped.
Desktop or Server
PyQt6 GUI and headless CLI on Windows, Linux, and macOS.
CLI & FastAPI
Automate scans headlessly or via the HTTP API wrapper.
CI/CD Ready
Jenkins, GitHub Actions, Azure DevOps, Docker, Perforce & Git.
Air-Gapped Databases
Local NVD, KEV, OSV, Grype & malware feeds with smart updates.
See SBOMator in Action
This sample report shows how SBOMator analyzes a real project, identifies vulnerable components, and highlights security risk in a clear, actionable format.
OWASP WebGoat Demo Scan
This example uses the intentionally vulnerable OWASP WebGoat project to show how SBOMator surfaces component inventory, CVE exposure, severity distribution, and remediation priority — and how its quality gate flags an SBOM that is not regulator-ready before it ships.
Explore the full interactive report here.
- 202 total components identified
- 11 vulnerable components detected
- 111 application CVEs highlighted
- Severity breakdown: 20 Critical, 61 High, 25 Medium, 4 Low
- Quality gate: flagged NOT regulator-ready (unresolved fields)
- Direct links to vulnerability intelligence
This project is intentionally vulnerable and is used here to demonstrate SBOMator’s detection and reporting capabilities. Based on the OWASP WebGoat project, an open-source application maintained by OWASP.
How SBOMator Compares
ESL’s weighted assessment for embedded and regulated product development.
Disclosure: ESL — SBOMator’s developer and vendor — prepared this comparison; it is not an independent review or third-party benchmark. Full methodology →
| Rank | Platform | Score / 100 | Grade |
|---|---|---|---|
| 1 | SBOMator | 92.3 | A |
| 2 | Black Duck | 81.8 | A- |
| 3 | Anchore Enterprise | 75.5 | B+ |
| 4 | Sonatype | 73.8 | B |
| 5 | Mend | 69.5 | B- |
| 6 | Snyk | 66.0 | C+ |
| 7 | FOSSA | 62.0 | C |
ESL’s weighting for embedded/regulated use as of August 2026; other profiles may rank differently. Trademarks belong to their owners; the named vendors have not reviewed or endorsed this comparison.
Build One Connected Evidence Model
Know what is in the product. Know what changed. Preserve how the decision was made โ across software, AI, hardware, and firmware, without your source leaving your network.
SBOMator is a compliance-enablement and evidence platform; it does not replace legal conformity assessment or guarantee FDA clearance or CE marking. Regulatory evidence packages (EU CRA, FDA 524B, IEC, OpenChain) support โ but do not substitute for โ formal assessment, validation, and approval by the manufacturer. EDR-SBOM is endpoint-aware supply-chain assurance and complements, but does not replace, behavioral EDR or process/network telemetry. Third-party marks identify supported technologies; no partnership is implied.