Know what's actually in your software, including the AI parts
Every dependency, every package, every model your code touches is something you're accountable for. Regulators know it too. The EU AI Act wants documentation of what's inside your AI systems, and "we're not sure" isn't an answer.
SBOMix scans your repository and generates a complete software bill of materials in seconds:
CycloneDX and SPDX output - the two formats compliance teams and customers actually ask for
AI-BOM generation - inventories the models, providers, and AI dependencies in your stack, not just the npm packages
Vulnerability enrichment - components checked against known CVEs, so the SBOM tells you something instead of just existing
GitHub Action - drop it in your pipeline and every build ships with a fresh SBOM
Hosted dashboard - scan results, findings, and exports in one place
Who it's for
Engineering leads who get asked "can you send us your SBOM?" by enterprise customers. Compliance teams staring down EU AI Act Article 11 documentation. Anyone shipping AI features who can't currently list what models their product depends on.
Why it exists
Most SBOM tools stop at package manifests. They'll tell you about lodash and miss the fact that your app calls three different LLM providers. SBOMix treats AI dependencies as first-class inventory, because that's the part auditors are starting to ask about.
Open source, built by a CCIE with 25 years in enterprise security. Try it at sbomix.com.
