We protect your SBOMs like you protect your customers
A platform that holds your software supply chain data has to clear a higher bar. Here's exactly what we do.
Security controls
01
Encryption at rest
All SBOM files are stored in encrypted blob storage with AES-256. Database fields containing sensitive metadata are encrypted with envelope keys rotated quarterly.
02
Encryption in transit
TLS 1.3 enforced on all endpoints. HSTS preload, modern cipher suites only. All data in transit — including connections to our managed database and internal services — is encrypted with TLS.
03
Access controls
Role-based access (Owner, Admin, Member, Viewer) with least-privilege defaults. Enterprise customers get SAML/OIDC SSO, SCIM provisioning, and IP allowlisting.
04
Audit logging
Every API call, file access, and admin action is recorded in a hash-chained, tamper-evident audit log — Ed25519-signed and independently verifiable against a published public key. Logs are retained for 30 days (Starter), 1 year (Growth), or 10 years (Enterprise).
05
Tokenized sharing
SBOM share links use cryptographically random tokens with configurable expiry and access caps. Recipient access is logged with IP and user agent.
06
Isolated tenancy
Each organization's data is isolated by org_id at the database row level, enforced by middleware on every query.
Certifications & frameworks
Operational practices
- ✓Quarterly third-party penetration tests
- ✓Continuous dependency scanning on our own codebase
- ✓Vulnerability disclosure program at security@sbomvault.ai
- ✓All employees complete annual security training
- ✓Production access requires hardware MFA and is logged
- ✓Incident response plan with 24-hour customer notification
Reporting a vulnerability
We take security disclosures seriously. If you believe you've found a vulnerability in SBOMVault.ai, please email security@sbomvault.ai. We acknowledge reports within 24 hours and will keep you updated through resolution. We do not pursue legal action against good-faith researchers who follow our disclosure policy.
Need a security review packet?
We provide SOC 2 progress reports, pen test summaries, and DPA templates to Enterprise prospects.
Request security packet