ESL SBOMator – Secure Your Software Supply Chain
Enterprise Security & Compliance

Secure Your Software Supply Chain

ESL SBOMator generates comprehensive Software Bill of Materials (SBOM) reports with full license detection for any environment โ€” online or air-gapped. Affordable, secure, and built for organizations that refuse to compromise on cybersecurity.

100%
Air-Gap Ready
FDA
Compliant
24/7
Support
ESL SBOMator security visualization showing interconnected software components and vulnerability scanning

Complete SBOM Solution

Three powerful components working together to deliver end-to-end visibility, security, and compliance for your software supply chain.

Project Scan

The core of SBOMator. Launch scans, build comprehensive SBOMs with full license detection (Apache, LGPL, MIT, and more), and create detailed reports for compliance and security with ease.

  • Automated scanning
  • License compliance detection
  • Multi-language support (C/C++, Python, Java)

Database Management

Stay current with NVD, KEV, and OSV vulnerability databases. Auto-download when online, or manually update for air-gapped environments. Your data stays secure on your infrastructure.

  • NVD, KEV & OSV databases
  • Auto-download or manual update
  • Private on-premises deployment

Report Information

Capture device details and software metadata for regulated industries. Generate FDA-compliant documentation, detect licensing obligations, and create comprehensive audit reports automatically.

  • FDA & IEC 62304 compliance
  • License obligation tracking
  • Multiple export formats

See SBOMator in Action

This sample report shows how SBOMator analyzes a real project, identifies vulnerable components, and highlights security risk in a clear, actionable format.

OWASP WebGoat Demo Scan

This example uses the intentionally vulnerable OWASP WebGoat project to demonstrate how SBOMator surfaces component inventory, CVE exposure, severity distribution, and prioritization for remediation.

  • 197 total components identified
  • 10 vulnerable components detected
  • 109 known CVEs highlighted
  • Direct links to vulnerability intelligence
View Sample Report

This project is intentionally vulnerable and is used here to demonstrate SBOMator’s detection and reporting capabilities.

This sample is based on the OWASP WebGoat project, an open-source application maintained by OWASP.

Why Choose ESL SBOMator?

Built for security teams, compliance officers, and organizations that demand the highest standards of software supply chain visibility.

Works Anywhere

Full functionality in networked or air-gapped environments โ€” no forced cloud dependency

Cost-Effective

Affordable solution starting at $5,000 vs. competitors at $20,000-$50,000 annually

License Compliance

Automatic detection of open source licenses and obligations (Apache, LGPL, MIT, and more)

No Vendor Lock-In

One-time purchase option available โ€” no forced annual subscriptions

Data Privacy

Your code never leaves your infrastructure โ€” perfect for sensitive environments

Multi-Format Support

Works with C/C++, Python, Java, and supports all major SBOM formats

Trusted Across Industries

From healthcare to defense, ESL SBOMator delivers the security and compliance capabilities organizations need.

Healthcare & Medical Devices

Generate FDA-compliant documentation and meet stringent regulatory requirements for medical device software. Serving medical device manufacturers since 2008 with proven compliance solutions.

Key Requirements:
  • FDA 21 CFR Part 11
  • IEC 62304 compliance
  • Static code analysis

Banking & Financial Services

Maintain cybersecurity standards in highly regulated financial environments. Works seamlessly in secure, air-gapped banking infrastructure where uptime and data privacy are critical.

Key Requirements:
  • Air-gap deployment
  • On-premises security
  • License compliance tracking

Defense & Government

Operate in classified and secure environments while maintaining complete software supply chain visibility. No cloud dependency means your sensitive code stays within your infrastructure.

Key Requirements:
  • Zero internet dependency
  • NIST compliance
  • Classified system ready

Enterprise Software

Track dependencies, identify vulnerabilities, detect license obligations, and maintain compliance across your entire software portfolio. Affordable alternative to expensive enterprise tools.

Key Requirements:
  • Multi-language support
  • License detection
  • Cost-effective pricing
New Feature

AI/ML SBOM Add-on

Bring AI transparency to your software supply chain. Our upcoming AI/ML SBOM Add-on extends SBOMator with the elements regulators now expect for AI-enabled products โ€” aligned with the G7 SBOM for AI โ€” Minimum Elements (2026).

G7
Aligned
3
Checking Levels
100%
Air-Gap Ready

What’s coming in the AI/ML SBOM Add-on

Traditional SBOMs miss the components that actually drive risk in an AI system โ€” model weights, datasets, external inference APIs, and accelerators. The add-on closes that gap.

Local Model Detection

Discovers AI/ML artifacts across your codebase and hashes them as first-class SBOM components.

  • .onnx, .pt, .safetensors
  • .gguf and quantized formats
  • Framework detection

External AI API Inventory

Identifies calls to hosted inference services so your supply chain is fully documented.

  • OpenAI, Anthropic, Gemini
  • Azure AI & AWS Bedrock
  • Notebooks & scripts scanned

G7-Aligned CycloneDX

Reports enriched with AI-specific properties so auditors can filter, query, and prove compliance.

  • esl:ai_sbom_profile
  • esl:ai_sbom_check_level
  • Model & dataset metadata

Air-Gap Ready

Bundled offline guidance โ€” no internet required. Built for classified, medical, and industrial environments.

  • Offline HTML guides
  • No telemetry
  • Same air-gap workflow

Separate License Key

Activates with its own 16-digit key. Never overwrites your base SBOMator license โ€” buy it only when you need it.

  • Keys starting with 9
  • UI controls stay disabled until activated
  • Zero disruption to existing scans

Infrastructure Awareness

Enumerates accelerator and runtime dependencies so your AI stack is fully accounted for.

  • CUDA, TensorRT, ROCm
  • Accelerator drivers
  • Inference runtimes

Three Checking Levels

Match effort to compliance need. Switch any time โ€” settings persist in your .esl-project file alongside existing scan configuration.

Minimum

AI Inventory Only
  • Detects AI/ML frameworks
  • Finds local model artifacts
  • Hashes every artifact
  • Fast, lightweight scan

Maximum

Deep AI Supply-Chain Review
  • Scans notebooks & training scripts
  • Identifies external AI service calls
  • Enumerates inference infrastructure
  • Runs security & data-min checklist

Aligned with the G7 SBOM for AI โ€” Minimum Elements (2026)

Directly supports the seven G7 clusters โ€” Metadata, System-Level Properties, Models, Datasets, Infrastructure, Security Properties, and KPIs. Published jointly by the G7 Cybersecurity Working Group, BSI, and CISA.

New Capability ยท DataBOM

Your AI Training Data Now Needs an SBOM

Europe’s regulators just made dataset provenance a compliance requirement. SBOMator DataBOM already speaks that language โ€” 100% local, air-gap ready, zero data leaves your PC.

EDPB 03/2026
Guidelines on web scraping for generative AI
Art. 6 ยท 9 ยท 14
Legal basis, sensitive-data safeguards, source list
100% local
Your dataset never leaves your machine

What You Must Now Evidence โ€” For Every Dataset

“Publicly available” is not an exemption. Web scraping for AI training is fully regulated under the GDPR โ€” collection, storage, structuring and reuse.

Demand

Source inventory

A searchable list of scraped domains and URLs, with collection dates and periods โ€” published, not just filed away.

Demand

PII minimization

Syntax-based filters for identifiers โ€” emails, ID numbers, financial data โ€” applied and documented before training.

Demand

Special-category control

Health, political, ethnic and religious content: incidental collection tolerated only with demonstrable lifecycle safeguards.

Demand

Opt-out respect

robots.txt, ai.txt, CAPTCHAs and login walls now carry weight in the GDPR balancing test. Ignoring them has consequences.

Demand

Supply-chain evidence

Bought a scraped dataset? You must document its sources, exclusion criteria, warranties and the originating controller.

Demand

Accountability on paper

Legitimate-interest assessments and DPIAs, case by case. The first thing an authority asks for is your documentation.

A Trained Model Cannot Be Patched

Software provenance failures can be fixed after the fact โ€” re-scan, patch, redeploy. Data provenance failures are permanent: removing personal data from a trained model is close to impossible.

4%
of global annual turnover โ€” maximum GDPR fine exposure
0
ways to “untrain” personal data out of a shipped model
100%
of the evidence must exist before training starts

This Is Exactly What SBOMs Did to Software

The EDPB is applying the same principle to data โ€” before the incident that forces it.

Software supply chain (SBOM)AI training data (EDPB 03/2026)
Component inventory โ€” what’s in the buildSource list โ€” domains, URLs, searchable
Version & timestamp per componentCollection date per source
Supplier identityOriginating controller & contact point
License compliance per componentLegal basis per source
Vulnerability scan against inventoryPII & special-category screening
Attestations when buying binariesWarranties when buying datasets

Dataset Provenance, Scanned Like Firmware

The same scanner your security team already trusts for firmware SBOMs now generates the provenance evidence regulators expect for AI training data.

Dataset
directory ยท archive ยท JSONL / CSV / Parquet ยท crawl logs
SBOMator DataBOM scan
runs entirely on your machine
HTML provenance report
+ CycloneDX ML-BOM

Runs entirely inside your perimeter. Your dataset never leaves your PC.

Each Report Section Maps to an EDPB Demand

An evidence generator for your DPO and legal team โ€” the documented inputs a legitimate-interest assessment and DPIA are built on.

DataBOM report sectionEDPB requirement it evidences
Source inventory โ€” domains, counts, datesArt. 14(5)(b) transparency source list
PII scan โ€” emails, IDs, IPs, GPSData-minimization filters
Special-category flags โ€” with review samplesArt. 9 lifecycle safeguards
Secrets scanSecurity & minimization
Opt-out signal status โ€” robots.txt / ai.txtReasonable-expectations balancing
Risky-source flags โ€” minor-directed, sensitive sitesSource-exclusion expectation
Provenance completeness scoreAccountability ยท DPIA input
ESL-SBOMator ยท DataBOM Dataset ScanOffline mode

Last scan โ€” crawl_2026_q2 ยท 1,247,880 records

  • Source inventory: 4,318 domains ยท collection timestamps present for 96% of records
  • PII detected: 12,407 findings (emails 8,112 ยท phone numbers 3,051 ยท national IDs 1,244) โ€” review list generated
  • Special-category (Art. 9) flags: 342 records (health 201 ยท political 141) โ€” samples queued for review
  • Secrets: 3 findings (API keys) โ€” exclusion recommended
  • Opt-out signals: 118 source domains publish robots.txt / ai.txt disallow โ€” exclusion list exported
Provenance completeness score: 82 / 100
crawl_2026_q2_provenance_Report.html ยท crawl_2026_q2_databom.cdx.json saved locally โ€” nothing uploaded.

Air-Gapped by Design = GDPR by Design

Cloud scanning tools create the very GDPR problems they claim to solve. SBOMator’s architecture removes them before they exist.

Art. 28

No processor, no DPA

ESL never touches your data โ€” so there is no data-processing agreement to negotiate, no sub-processor list to audit, no vendor risk assessment for your dataset.

Ch. V

No international transfer

Nothing crosses a border because nothing crosses your firewall. No SCCs, no adequacy analysis, no transfer impact assessment.

Art. 5

Minimization by architecture

The scanner reads your dataset in place and stores nothing but the report you asked for. Storage limitation is enforced by design, not policy.

Art. 32

Your perimeter, your controls

Security of processing inherits the controls you already certified โ€” disk encryption, access control, physical security. No new attack surface.

Offline

True air-gap operation

Vulnerability and metadata databases install from an offline bundle. Fully disconnected networks are a supported configuration, not an afterthought.

License

Site license + support

One site license, real engineering support, no per-scan metering โ€” and no usage telemetry phoning home, because there is no home to phone.


Do you wish to know more ?