Runs entirely in your browser
Zero runtime dependencies, zero backend. Parsing and analysis happen on the reviewer’s machine, so a confidential supplier SBOM never leaves it.
Run it locally →Deterministic, evidence-backed verdicts
The same SBOM always produces the same findings. Every finding carries a rule ID, a dependency-path evidence trail, an obligation and a recommended action.
See the finding rules →Copyleft that actually propagates
Strong copyleft walks up the dependency graph. Static or undeclared linkage makes the parent a derivative work; weak copyleft owes a relinking mechanism.
How it decides →Milestone diff, not re-assessment
Identity-based comparison detects added and removed components, version bumps, license changes, newly introduced copyleft and regressions to NOASSERTION.
Dashboard tour →CI-ready release gate
The gate exits non-zero on policy violations, so a non-conforming SBOM is rejected at supplier intake instead of at the milestone review.
CLI reference →An agent layer that cannot overrule it
An MCP server exposes the engine as nine tools. The model may explain and draft correspondence — it can never set a risk tier.
MCP server →