Map SBOM components. Document AI governance gaps with cited evidence.

Browser-based · SBOM files stay local · CVE lookup uses OSV.dev
SPDX & CycloneDX · maps to EU AI Act & NIST AI RMF

SBOM Analyzer — three steps

Upload a software bill of materials, match components to known vulnerabilities, and review findings with compliance context — in your browser.

1

Upload

Drop a CycloneDX or SPDX file. Processing runs locally — your SBOM is not sent to our servers.

Produces: Parsed component inventory ready for vulnerability lookup.
2

Match vulnerabilities

Components are checked against OSV.dev for known CVEs. Results appear in seconds with severity and package context.

Produces: A prioritized vulnerability list tied to each dependency.
3

Review & report

Explore findings, framework alignment (NTIA, NIST, and related supply-chain guidance), and stakeholder-ready views for security and compliance teams.

Produces: A prioritized CVE list and framework context you can share with engineering and leadership.

AI Governance Review — five phases, one evidence package

A structured accountability workflow for deployed AI systems. Complete in one sitting or save progress and return — each phase builds on the last.

1

Define System

Name the AI system, describe its purpose, and classify its EU AI Act risk tier. The tool guides you through each field with plain-language explanations of why each one matters to regulators and auditors.

Produces: A formal system record with unique ID, risk classification, and accountable owner.
2

Component Inventory

Answer 32 guided questions across six governance domains: Models, Data, Vendors, Infrastructure, Controls, and Monitoring. Questions include regulatory context tags — EU AI Act, GDPR, NIST AI RMF, G7 Hiroshima AI Process, ISO/IEC 42001, OECD AI principles, and SBOM-for-AI minimum elements.

Produces: A complete, structured evidence record across all six governance domains.
3

Gap Analysis

The gap register is generated automatically from your answers. Each gap includes its regulatory citation, the risk if left unaddressed, and suggested evidence types that may help close it.

Produces: A regulatory-cited gap register organized by severity — Critical, Major, Minor.
4

Assess & Assign

For each gap, assign an owner, choose a remediation approach, and set a target date. This is where a list of findings becomes an action plan — ownership and target dates flow into every stakeholder report.

Produces: A working action plan with owners and dates embedded into every report.
5

Evidence Package

Generate five stakeholder-specific HTML reports from the single record you've built. The board report uses narrative and summary; the technical record includes every question and answer; the legal package focuses on GDPR and EU AI Act obligations; the CISO report covers control gaps, monitoring obligations, and remediation owners; the procurement review maps vendor accountability, contractual gaps, and AI supply chain risk.

Produces: Board summary · Technical review record · Legal/DPO package · CISO assessment · Procurement review.
Start AI Review

Browser-based · no account required on the free tier

Built for teams who need defensible evidence

Governance, legal, security, and procurement stakeholders use TechnoSoluce when cited gap analysis and role-specific reports matter more than checkbox scores.

Governance & compliance

EU AI Act and NIST AI RMF gap registers with regulatory citations — self-assessment outputs, not certifications.

Security & engineering

CycloneDX and SPDX upload, OSV-backed CVE mapping, and supply-chain risk views — processed locally, without sending SBOM files to our servers.

Legal & procurement

GDPR and EU AI Act obligation packages, vendor accountability maps, and procurement reviews that surface contractual and AI supply chain gaps.

Part of the ERMITS product family — alongside VendorSoluce™ and CyberCorrect™.

Contact for a trial or scoping call FAQ