Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Supply chain security, explained clearly
Your guide to the alphabet soup of software supply chain security — SAST, SCA, reachability, secrets, containers, Kubernetes, runtime, pentesting, the BOM suite (SBOM, CBOM, AIBOM, QBOM), and the regulations behind them. Clear, plain-English explanations, from the fundamentals to what actually matters in practice.

BOM SuiteFeatured
What Is an AIBOM? The AI Bill of Materials, Explained
What an AI Bill of Materials is, what it inventories, how to generate one, and why the EU AI Act is about to make it mandatory.
Read the guide →All guides

BOM Suite
What Is an SBOM? A Complete Guide to the Software Bill of Materials
What a software bill of materials is, what goes in one, how to generate it, SPDX vs CycloneDX, and the regulations that now require it.

BOM Suite
Cryptographic Bill of Materials (CBOM): What It Is and the Tools to Build One
What a CBOM is, what it inventories, why it matters before the 2030 quantum deadlines, and the tools that generate one.