Platform · Supply Chain

SBOM ingestion, CVE matching, fourth-party visibility.

Ingest SBOMs from JFrog Xray, GitHub Dependency Graph, AWS ECR, or direct upload. CVE matching runs continuously; new vulnerabilities create supply chain risk entries with CVSS scoring and fix-version recommendations.

Capabilities

SBOM & Supply Chain — what's in the box.

+

Multi-source ingestion

JFrog Xray, GitHub Dependency Graph, AWS ECR, plus CycloneDX and SPDX format direct upload.

+

Continuous CVE matching

New CVE publications trigger fresh matches against ingested SBOMs. Critical / High matches escalate within hours.

+

Fourth-party identification

Sub-dependencies surface as fourth parties in the supply chain map. Risk tier inherits from the vendor relationship.

+

Fix-version recommendations

Each CVE match includes affected component version range and recommended fix versions where available.

SBOM & supply chain

From ingested SBOM to routed finding.

+

SBOM ingestion

Ingest CycloneDX and SPDX SBOMs — via source connectors (JFrog Xray, GitHub, AWS ECR) or upload — with continuous CVE monitoring running without further configuration.

+

Continuous CVE matching

Ingested components are matched against known vulnerabilities continuously, surfacing CVSS score, affected component and suggested fix version.

+

Routed to engineering

CVE findings route to ServiceNow, Jira or GitHub Issues by affected component or vendor — risk intelligence lands in the backlog where it gets fixed.

+

Feeds the risk register

SBOM CVE matches create supply-chain risks in the ERM register automatically, with full CVSS and component context.

Stop running this in spreadsheets.

Verisq's SBOM & Supply Chain is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.

See pricing Back to home