SBOM Hub & VEX

One system of record for every SBOM in the enterprise

Regulators, customers, and acquirers all expect an SBOM and a VEX document on demand — and most teams are still storing them in shared drives. SBOM Hub gives compliance and AppSec teams one place to ingest, generate, and continuously monitor every first-party and third-party SBOM across the enterprise.
SBOM Hub hero graphic showing SBOM and VEX management
Loved by security teams, painless for developers at:

How SBOM Hub works

Produce SBOMs and VEX that satisfy regulators and customers on demand
Mandates like EO 14028, the EU Cyber Resilience Act, FedRAMP, PCI DSS, and FDA rules require an SBOM, and enterprise buyers now ask for one mid-deal. SBOM Hub generates CycloneDX or SPDX SBOMs — plus a VEX document — automatically, so you answer in the format they need without manual exports.
Manage every SBOM in one place instead of shared drives
SBOMs tend to scatter across SharePoint, Google Drive, and email, with no canonical version per release and no consistent home for the ones vendors and acquisitions send you. SBOM Hub stores first-party and third-party SBOMs in a single inventory.
Catch new vulnerabilities in software you already shipped or accepted
A static SBOM in a folder reflects risk the day it was created, not today. SBOM Hub continuously monitors every stored component against the Endor Labs vulnerability database, so a new advisory updates risk everywhere without re-scanning.
“Endor Labs helped us cut through the noise and focus on what matters. With fewer alerts and more accuracy, our teams now spend more time building and less time chasing false positives.”
Michael Hammond

Information Security Engineer, Zebra Technologies

SBOM and VEX generation graphic
SBOM & VEX generation
Generate SBOMs and reachability-based VEX documents automatically in CI, in whatever format your stakeholders require.
Generate CycloneDX or SPDX SBOMs for every supported language automatically in CI, with no per-language plugin.
Produce a VEX document alongside every SBOM, with reachability-based justification for whether a listed vulnerability affects the product.
Meet evidence requirements for EO 14028, CRA, FedRAMP, PCI DSS, FDA, and customer questionnaires without manual exports.
Learn more
Central system of record
Store and score every first-party and third-party SBOM in one inventory.
Store first-party and third-party SBOMs in one inventory instead of scattered folders and email threads.
Ingest vendor SBOMs by giving them endorctl to run in their own pipeline, so updates land in your hub as they ship.
Apply the same Endor Labs scoring — security, activity, popularity, quality — to imported SBOMs as to your own code.
Learn more
Central system of record graphic for SBOMs and VEX documents
Continuous monitoring graphic showing ongoing dependency risk checks
Continuous monitoring
Keep every stored SBOM current as new advisories land, without re-scanning.
Get alerted when a new vulnerability affects a component already listed in a stored SBOM, with no need to re-scan.
Find every application containing a specific component or CVE — across your code and your vendors' — by searching the hub.
Respond to the next Log4Shell in minutes instead of days by pivoting from a CVE to the affected applications.
Learn more
Flowchart showing integration paths from GitHub, GitLab, and PHP to Slack and Microsoft platforms, with a C# icon connected to Slack.

Your Tools, Your Languages
All Secured

Learn how Endor Labs fits into your ecosystem.
Flow diagram connecting software development tools and platforms including .NET, JetBrains, GitHub, Google, and Vercel.

FAQs

What's the difference between an SBOM and a VEX?

An SBOM lists the components in your software; a VEX document says which of the listed vulnerabilities actually affect the product. SBOM Hub produces both, using reachability analysis to justify each VEX statement.

Which formats does it support?

It generates and ingests both CycloneDX (JSON or XML) and SPDX (JSON or Tag-Value), so you can hand customers and auditors the exact format they ask for.

Can it store SBOMs we receive from vendors?

Yes. SBOM Hub is a system of record for both first-party and third-party SBOMs. Vendors can run endorctl in their own pipeline so their updates land in your hub as they ship.

How does it help when a new CVE like Log4Shell breaks?

Every stored component is continuously monitored against the Endor Labs vulnerability database. You pivot from the CVE to every affected application — in your code and your vendors' — in minutes, without re-generating anything.

Do we have to regenerate SBOMs after every new advisory?

No. Risk profiles update automatically as the vulnerability database adds advisories, so a stored SBOM stays current without a re-scan or re-export.

Which regulations does this help with?

SBOM Hub supports evidence requirements for EO 14028, the EU Cyber Resilience Act, FedRAMP, PCI DSS, FDA medical device rules, and enterprise customer security questionnaires.

Code without compromise