SBOMVault
Security at SBOMVault.ai

We protect your SBOMs like you protect your customers

A platform that holds your software supply chain data has to clear a higher bar. Here's exactly what we do.

Security controls

01

Encryption at rest

All SBOM files are stored in encrypted blob storage with AES-256. Database fields containing sensitive metadata are encrypted with envelope keys rotated quarterly.

02

Encryption in transit

TLS 1.3 enforced on all endpoints. HSTS preload, modern cipher suites only. All data in transit — including connections to our managed database and internal services — is encrypted with TLS.

03

Access controls

Role-based access (Owner, Admin, Member, Viewer) with least-privilege defaults. Enterprise customers get SAML/OIDC SSO, SCIM provisioning, and IP allowlisting.

04

Audit logging

Every API call, file access, and admin action is recorded in a hash-chained, tamper-evident audit log — Ed25519-signed and independently verifiable against a published public key. Logs are retained for 30 days (Starter), 1 year (Growth), or 10 years (Enterprise).

05

Tokenized sharing

SBOM share links use cryptographically random tokens with configurable expiry and access caps. Recipient access is logged with IP and user agent.

06

Isolated tenancy

Each organization's data is isolated by org_id at the database row level, enforced by middleware on every query.

Certifications & frameworks

SOC 2 Type IIIn progress (Schellman)
ISO 27001Roadmap (2027)
GDPRCompliant
EU CRA-alignedCompliant

Operational practices

  • Quarterly third-party penetration tests
  • Continuous dependency scanning on our own codebase
  • Vulnerability disclosure program at security@sbomvault.ai
  • All employees complete annual security training
  • Production access requires hardware MFA and is logged
  • Incident response plan with 24-hour customer notification

Reporting a vulnerability

We take security disclosures seriously. If you believe you've found a vulnerability in SBOMVault.ai, please email security@sbomvault.ai. We acknowledge reports within 24 hours and will keep you updated through resolution. We do not pursue legal action against good-faith researchers who follow our disclosure policy.

Need a security review packet?

We provide SOC 2 progress reports, pen test summaries, and DPA templates to Enterprise prospects.

Request security packet