SBOM Risk Pack
Turn one existing CycloneDX or SPDX JSON SBOM into a deterministic open-source licence review queue and buyer-ready evidence pack.
Delivery timing. Target handoff: within 5 UK business days after complete intake for the published fixed scope. This is a target, not a guaranteed SLA. We confirm the dated handoff window in writing before substantive work starts; incomplete intake pauses the clock.
Free proof path
Try the atomic task before you buy SBOM Risk Pack.
These are real no-signup tools already linked to this workflow by commercial intent or source-repository provenance. They prove a narrow task only; they do not claim to replace the paid workflow, monitoring, review or supported delivery.
Free SBOM Buyer-Readiness Checklist
A free checklist for preparing an existing CycloneDX or SPDX SBOM for licence review and buyer due-diligence evidence.
Gzip → Text
Decompress a gzip file into readable text without sending it to a server.
Incident Evidence PDF Merger
Combine incident evidence into one PDF without uploading documents.
Incident YAML → JSON
Convert incident or compliance YAML into JSON for review and handoff.
Product-to-free-tool attribution contains only product slug, tool slug and placement. It never includes pasted input, uploaded-file contents or generated output.
Small SaaS vendors entering enterprise procurement, software agencies handing code to clients and due-diligence providers.
Bring one existing SBOM and get a bounded licence-policy review queue without uploading or executing source code.
Deterministic component normalisation, allow/deny/needs-review policy, human component disposition queue and an evidence pack carrying input/tool provenance.
What the service includes
- One customer-provided CycloneDX JSON or SPDX JSON SBOM up to 5 MiB
- Deterministic component normalisation
- Allow/deny/needs-review licence policy with unknown states kept for review
- Human disposition queue and buyer-ready evidence pack
A 10-minute proof, not a slide deck
- 01Load a controlled existing SBOM
- 02Inspect normalised components and licence states
- 03Review needs-review dispositions
- 04Export the provenance-backed evidence pack
Clear boundaries
- Not a legal opinion or licence clearance
- Not a vulnerability scanner or CVE-coverage claim
- No arbitrary remote clone/build, uploaded-code execution or CRA certification
Buy the fixed-scope service. No account required.
Pay securely with Stripe. After payment, we use the checkout email to arrange the secure intake and handoff described for this product. Do not email sensitive source material unless the handoff instructions explicitly ask for it.
Delivery timing. Target handoff: within 5 UK business days after complete intake for the published fixed scope. This is a target, not a guaranteed SLA. We confirm the dated handoff window in writing before substantive work starts; incomplete intake pauses the clock.
Business purchase. By paying you order the fixed scope described here and agree to the Terms. See Refund & Cancellation and Privacy before checkout.