Available Reports
| Report | Purpose | Documentation |
|---|---|---|
| SBOM | Software Bill of Materials - inventory of all software components | SBOM Report |
| VEX | Vulnerability Exploitability - communicate which vulnerabilities are actionable | VEX Report |
| CBOM | Cryptographic Bill of Materials - inventory of crypto assets | CBOM Report |
| PQC | Post-Quantum Cryptography Compliance - readiness for quantum threats | PQC Report |
| Findings | Security Findings - comprehensive security analysis results | Findings Report |
Use Case: Regulatory Compliance
When preparing for regulatory submissions (e.g., FDA, EU Cyber Resilience Act), you typically need:- SBOM - Required by most regulations to demonstrate software transparency
- VEX - Demonstrates how youβre addressing known vulnerabilities
- PQC Report - Shows cryptographic posture for quantum readiness
Use Case: Continuous Compliance in CI/CD
Integrate compliance artifact generation into your release pipeline:- Upload binary image β Upload Image
- Wait for scan completion β List Scans
- Download artifacts β Individual report endpoints above
Use Case: Third-Party Audits
For supply chain audits:- Generate SBOM for software inventory
- Generate CBOM for cryptographic material inventory
- Generate Findings Report for security posture overview
Automation Script
Download all compliance artifacts for a binary image:Related
API Reference User Guides- SBOM Export Guide - UI walkthrough and use cases
- VEX Export Guide - Vulnerability disclosure workflows
- CBOM Export Guide - Cryptographic inventory
- PQC Compliance Guide - Detailed report contents and generation