














.webp)
.webp)
An SBOM lists the components in your software; a VEX document says which of the listed vulnerabilities actually affect the product. SBOM Hub produces both, using reachability analysis to justify each VEX statement.
It generates and ingests both CycloneDX (JSON or XML) and SPDX (JSON or Tag-Value), so you can hand customers and auditors the exact format they ask for.
Yes. SBOM Hub is a system of record for both first-party and third-party SBOMs. Vendors can run endorctl in their own pipeline so their updates land in your hub as they ship.
Every stored component is continuously monitored against the Endor Labs vulnerability database. You pivot from the CVE to every affected application — in your code and your vendors' — in minutes, without re-generating anything.
No. Risk profiles update automatically as the vulnerability database adds advisories, so a stored SBOM stays current without a re-scan or re-export.
SBOM Hub supports evidence requirements for EO 14028, the EU Cyber Resilience Act, FedRAMP, PCI DSS, FDA medical device rules, and enterprise customer security questionnaires.