Share SBOMs with customers without losing your mind
Stop emailing zip files. Stop maintaining spreadsheets of who has what version. Issue a secure link, watch the access log, sleep at night.
How it works
From SBOM to customer in under 60 seconds.
Generate a share link
Pick the SBOM, set an expiration (1 day to a year, 30 days by default), optionally attach compliance attestations.
Send the link to your customer
A clean URL like sbomvault.ai/share/abc123. No accounts required on the recipient side.
They access a branded view
Component inventory, active CVEs, license posture, compliance status — read-only and searchable.
You see every access
Full audit log: who opened it, when, from what IP, what they downloaded, when the link expired.
What your customers get
And why their procurement teams stop bugging yours.
01
Time-limited by default
Links expire automatically. No more SBOMs floating around in customer inboxes years later.
02
Audit-trail every access
Every view, every download, every IP — recorded and exportable. Required for SOC 2 evidence.
03
Always current
Link to the SBOM, not a file. New release? The same link automatically points to the new SBOM.
04
Branded customer view
Your logo, your colors. Looks like part of your product, not a third-party tool.
05
Multiple export formats
Customers download CycloneDX (JSON or XML), SPDX (JSON or Tag-Value), CSV, or PDF — whichever their procurement team requires.
06
Revocable instantly
Customer relationship ends? Revoke the link with one click. Future access blocked, audit trail preserved.
Acme Product · v3.2.1
Shared by acme.com · expires in 14 days
Components
247
Active CVEs
3
Licenses
12
A real Trust Portal page, branded to your organization.
Share the compliance proof, withhold the secrets
A customer needs your SBOM for their compliance — they don't need your proprietary module names, internal suppliers, or build fingerprints. Every share runs through a redaction engine before it leaves, so you disclose exactly what you intend and nothing more.
Per-share redaction
Mask a component (it shows as REDACTED so the count stays honest), drop it entirely (even its dependency edges), share only third-party OSS, or strip suppliers, hashes, and CPEs — with a preview of exactly what the recipient will see.
Mark components private
Flag a proprietary component once and it is dropped from every share by default — across the download, the machine-readable VEX feed, and the recipient viewer alike.
Org-wide never-share list
Set component prefixes that must never leave — enforced on every share, retroactively, and impossible to override per share. Plus a default redaction so safe sharing is the org default, not a checklist.
One redaction engine applies before serialization, so CycloneDX, SPDX, CSV, the VEX feed, and the in-app viewer are all covered — and a redacted download is re-generated from the normalized components, never the raw uploaded bytes, so withheld data cannot leak through.
Ship your next SBOM with a link, not a zip
Trust Portal is included on Growth and Enterprise. Start free on Starter with 5 share links to try SBOM sharing.
Try freeFrequently asked questions
- How do I share an SBOM with a customer using Trust Portal?
- Pick the SBOM and generate a share link with an expiration from 1 day up to a year (30 days by default). Send the clean URL to your customer; no account is required on the recipient side to view the branded, read-only SBOM.
- What export formats can customers download from the Trust Portal?
- Customers can download CycloneDX (JSON or XML), SPDX (JSON or Tag-Value), CSV, or PDF, whichever format their procurement team requires.
- Can I revoke a Trust Portal share link?
- Yes. You can revoke a link with one click. Future access is blocked while the audit trail is preserved. Links are also time-limited by default and expire automatically.
- Which plans include Trust Portal?
- Trust Portal is included on the Growth and Enterprise plans. The Starter plan can start free with 5 share links to try SBOM sharing.