sbomify icon
sbomify icon

sbomify

sbomify is the trust center for your software supply chain. Store every SBOM and compliance document in one place, track them across products and releases, and share them with customers and regulators on demand. CycloneDX and SPDX, built for EU CRA compliance.

sbomify screenshot 1

Cost / License

Platforms

  • Online
  • Linux
  • Docker
0likes
0comments
0articles

Features

No features, maybe you want to suggest one?

sbomify News & Activities

Highlights All activities

Recent activities

sbomify information

  • Developed by

    GB flagsbomify, ltd
  • Licensing

    Open Source (Apache-2.0) and Freemium product.
  • Pricing

    Subscription that costs up to $199 per month + free version with limited functionality.
  • Written in

  • Alternatives

    5 alternatives listed
  • Supported Languages

    • English

GitHub repository

  •  57 Stars
  •  13 Forks
  •  112 Open Issues
  •   Updated  
View on GitHub
sbomify was added to AlternativeTo by Viktor Petersson on and this page was last updated .
No comments or reviews, maybe you want to be first?

What is sbomify?

Most teams can produce an SBOM. Far fewer can tell you which version shipped, whether it meets the rules that now apply, or hand it to a customer without a week of digging. sbomify answers those questions, and gives you a trust center to answer them from.

Bring SBOMs in from wherever they are made. Upload through the web interface or the API, or wire up CI with the sbomify GitHub Action. Anything valid in CycloneDX or SPDX is welcome, whichever tool produced it.

Once inside, they are organised the way you actually ship. Components hold SBOMs or documents. Products group the components you sell. Releases are versioned snapshots, so a question about last quarter's build has an exact answer. Workspaces decide who sees what.

Compliance is checked, not assumed. Built in plugins validate against the EU Cyber Resilience Act (BSI TR-03183-2), NTIA Minimum Elements, the CISA 2025 draft and FDA medical device guidance, and vulnerability scanning runs alongside. You find out where you stand before a customer does.

Then you publish. Your trust center gives customers a public page per product, the CycloneDX Transparency Exchange API serves machines that ask on their own, and an MCP server lets AI agents query your workspace directly.

Alongside SBOMs, sbomify stores the documents that travel with them: specifications, manuals, audit reports, attestations.

Open source. Self host it, or use app.sbomify.com.

Official Links