Secure Your Software Supply Chain
ESL SBOMator generates comprehensive Software Bill of Materials (SBOM) reports with full license detection for any environment โ online or air-gapped. Affordable, secure, and built for organizations that refuse to compromise on cybersecurity.
Complete SBOM Solution
Three powerful components working together to deliver end-to-end visibility, security, and compliance for your software supply chain.
Project Scan
The core of SBOMator. Launch scans, build comprehensive SBOMs with full license detection (Apache, LGPL, MIT, and more), and create detailed reports for compliance and security with ease.
- Automated scanning
- License compliance detection
- Multi-language support (C/C++, Python, Java)
Database Management
Stay current with NVD, KEV, and OSV vulnerability databases. Auto-download when online, or manually update for air-gapped environments. Your data stays secure on your infrastructure.
- NVD, KEV & OSV databases
- Auto-download or manual update
- Private on-premises deployment
Report Information
Capture device details and software metadata for regulated industries. Generate FDA-compliant documentation, detect licensing obligations, and create comprehensive audit reports automatically.
- FDA & IEC 62304 compliance
- License obligation tracking
- Multiple export formats
See SBOMator in Action
This sample report shows how SBOMator analyzes a real project, identifies vulnerable components, and highlights security risk in a clear, actionable format.
OWASP WebGoat Demo Scan
This example uses the intentionally vulnerable OWASP WebGoat project to demonstrate how SBOMator surfaces component inventory, CVE exposure, severity distribution, and prioritization for remediation.
You can explore the full interactive report here.
- 197 total components identified
- 10 vulnerable components detected
- 109 known CVEs highlighted
- Direct links to vulnerability intelligence
This project is intentionally vulnerable and is used here to demonstrate SBOMator’s detection and reporting capabilities.
This sample is based on the OWASP WebGoat project, an open-source application maintained by OWASP.
Why Choose ESL SBOMator?
Built for security teams, compliance officers, and organizations that demand the highest standards of software supply chain visibility.
Works Anywhere
Full functionality in networked or air-gapped environments โ no forced cloud dependency
Cost-Effective
Affordable solution starting at $5,000 vs. competitors at $20,000-$50,000 annually
License Compliance
Automatic detection of open source licenses and obligations (Apache, LGPL, MIT, and more)
No Vendor Lock-In
One-time purchase option available โ no forced annual subscriptions
Data Privacy
Your code never leaves your infrastructure โ perfect for sensitive environments
Multi-Format Support
Works with C/C++, Python, Java, and supports all major SBOM formats
Trusted Across Industries
From healthcare to defense, ESL SBOMator delivers the security and compliance capabilities organizations need.
Healthcare & Medical Devices
Generate FDA-compliant documentation and meet stringent regulatory requirements for medical device software. Serving medical device manufacturers since 2008 with proven compliance solutions.
- FDA 21 CFR Part 11
- IEC 62304 compliance
- Static code analysis
Banking & Financial Services
Maintain cybersecurity standards in highly regulated financial environments. Works seamlessly in secure, air-gapped banking infrastructure where uptime and data privacy are critical.
- Air-gap deployment
- On-premises security
- License compliance tracking
Defense & Government
Operate in classified and secure environments while maintaining complete software supply chain visibility. No cloud dependency means your sensitive code stays within your infrastructure.
- Zero internet dependency
- NIST compliance
- Classified system ready
Enterprise Software
Track dependencies, identify vulnerabilities, detect license obligations, and maintain compliance across your entire software portfolio. Affordable alternative to expensive enterprise tools.
- Multi-language support
- License detection
- Cost-effective pricing
AI/ML SBOM Add-on
Bring AI transparency to your software supply chain. Our upcoming AI/ML SBOM Add-on extends SBOMator with the elements regulators now expect for AI-enabled products โ aligned with the G7 SBOM for AI โ Minimum Elements (2026).
What’s coming in the AI/ML SBOM Add-on
Traditional SBOMs miss the components that actually drive risk in an AI system โ model weights, datasets, external inference APIs, and accelerators. The add-on closes that gap.
Local Model Detection
Discovers AI/ML artifacts across your codebase and hashes them as first-class SBOM components.
- .onnx, .pt, .safetensors
- .gguf and quantized formats
- Framework detection
External AI API Inventory
Identifies calls to hosted inference services so your supply chain is fully documented.
- OpenAI, Anthropic, Gemini
- Azure AI & AWS Bedrock
- Notebooks & scripts scanned
G7-Aligned CycloneDX
Reports enriched with AI-specific properties so auditors can filter, query, and prove compliance.
- esl:ai_sbom_profile
- esl:ai_sbom_check_level
- Model & dataset metadata
Air-Gap Ready
Bundled offline guidance โ no internet required. Built for classified, medical, and industrial environments.
- Offline HTML guides
- No telemetry
- Same air-gap workflow
Separate License Key
Activates with its own 16-digit key. Never overwrites your base SBOMator license โ buy it only when you need it.
- Keys starting with 9
- UI controls stay disabled until activated
- Zero disruption to existing scans
Infrastructure Awareness
Enumerates accelerator and runtime dependencies so your AI stack is fully accounted for.
- CUDA, TensorRT, ROCm
- Accelerator drivers
- Inference runtimes
Three Checking Levels
Match effort to compliance need. Switch any time โ settings persist in your .esl-project file alongside existing scan configuration.
Minimum
- Detects AI/ML frameworks
- Finds local model artifacts
- Hashes every artifact
- Fast, lightweight scan
Medium
- Parses Hugging Face metadata
- Reads config.json & model cards
- Detects dataset manifests
- Captures intended use & data flow
Maximum
- Scans notebooks & training scripts
- Identifies external AI service calls
- Enumerates inference infrastructure
- Runs security & data-min checklist
Your AI Training Data Now Needs an SBOM
Europe’s regulators just made dataset provenance a compliance requirement. SBOMator DataBOM already speaks that language โ 100% local, air-gap ready, zero data leaves your PC.
What You Must Now Evidence โ For Every Dataset
“Publicly available” is not an exemption. Web scraping for AI training is fully regulated under the GDPR โ collection, storage, structuring and reuse.
Source inventory
A searchable list of scraped domains and URLs, with collection dates and periods โ published, not just filed away.
PII minimization
Syntax-based filters for identifiers โ emails, ID numbers, financial data โ applied and documented before training.
Special-category control
Health, political, ethnic and religious content: incidental collection tolerated only with demonstrable lifecycle safeguards.
Opt-out respect
robots.txt, ai.txt, CAPTCHAs and login walls now carry weight in the GDPR balancing test. Ignoring them has consequences.
Supply-chain evidence
Bought a scraped dataset? You must document its sources, exclusion criteria, warranties and the originating controller.
Accountability on paper
Legitimate-interest assessments and DPIAs, case by case. The first thing an authority asks for is your documentation.
A Trained Model Cannot Be Patched
Software provenance failures can be fixed after the fact โ re-scan, patch, redeploy. Data provenance failures are permanent: removing personal data from a trained model is close to impossible.
This Is Exactly What SBOMs Did to Software
The EDPB is applying the same principle to data โ before the incident that forces it.
| Software supply chain (SBOM) | AI training data (EDPB 03/2026) |
|---|---|
| Component inventory โ what’s in the build | Source list โ domains, URLs, searchable |
| Version & timestamp per component | Collection date per source |
| Supplier identity | Originating controller & contact point |
| License compliance per component | Legal basis per source |
| Vulnerability scan against inventory | PII & special-category screening |
| Attestations when buying binaries | Warranties when buying datasets |
Dataset Provenance, Scanned Like Firmware
The same scanner your security team already trusts for firmware SBOMs now generates the provenance evidence regulators expect for AI training data.
Runs entirely inside your perimeter. Your dataset never leaves your PC.
Each Report Section Maps to an EDPB Demand
An evidence generator for your DPO and legal team โ the documented inputs a legitimate-interest assessment and DPIA are built on.
| DataBOM report section | EDPB requirement it evidences |
|---|---|
| Source inventory โ domains, counts, dates | Art. 14(5)(b) transparency source list |
| PII scan โ emails, IDs, IPs, GPS | Data-minimization filters |
| Special-category flags โ with review samples | Art. 9 lifecycle safeguards |
| Secrets scan | Security & minimization |
| Opt-out signal status โ robots.txt / ai.txt | Reasonable-expectations balancing |
| Risky-source flags โ minor-directed, sensitive sites | Source-exclusion expectation |
| Provenance completeness score | Accountability ยท DPIA input |
Last scan โ crawl_2026_q2 ยท 1,247,880 records
- ✔Source inventory: 4,318 domains ยท collection timestamps present for 96% of records
- ⚠PII detected: 12,407 findings (emails 8,112 ยท phone numbers 3,051 ยท national IDs 1,244) โ review list generated
- ⚠Special-category (Art. 9) flags: 342 records (health 201 ยท political 141) โ samples queued for review
- ✘Secrets: 3 findings (API keys) โ exclusion recommended
- ✔Opt-out signals: 118 source domains publish robots.txt / ai.txt disallow โ exclusion list exported
Air-Gapped by Design = GDPR by Design
Cloud scanning tools create the very GDPR problems they claim to solve. SBOMator’s architecture removes them before they exist.
No processor, no DPA
ESL never touches your data โ so there is no data-processing agreement to negotiate, no sub-processor list to audit, no vendor risk assessment for your dataset.
No international transfer
Nothing crosses a border because nothing crosses your firewall. No SCCs, no adequacy analysis, no transfer impact assessment.
Minimization by architecture
The scanner reads your dataset in place and stores nothing but the report you asked for. Storage limitation is enforced by design, not policy.
Your perimeter, your controls
Security of processing inherits the controls you already certified โ disk encryption, access control, physical security. No new attack surface.
True air-gap operation
Vulnerability and metadata databases install from an offline bundle. Fully disconnected networks are a supported configuration, not an afterthought.
Site license + support
One site license, real engineering support, no per-scan metering โ and no usage telemetry phoning home, because there is no home to phone.
Do you wish to know more ?