Platform features

SBOM supply-chain analysis and AI governance review share one platform. The sections below detail AI Governance Review; open SBOM Analyzer for dependency and vulnerability workflows.

SBOM Analyzer — dependency and CVE mapping

Upload SPDX or CycloneDX bills of materials, map components to known vulnerabilities, and align findings with compliance frameworks — processed in your browser.

SBOM ingestion

Support for SPDX and CycloneDX formats with component inventory and dependency graphing.

CVE & severity mapping

Match components to vulnerability databases with prioritised risk views for remediation teams.

Compliance alignment

Compare SBOM fields against NTIA minimum elements and EO 14028-style expectations — mapping aid, not compliance certification.

Client-side processing

Your SBOM files are not uploaded to our servers — analysis runs locally in the browser.

Open SBOM Analyzer → Try the demo

Guided 5-Phase Assessment Workflow

Every phase has a defined input and a specific deliverable. You always know where you are and what comes next.

1

Define System

Name the AI system, describe its purpose, and classify its EU AI Act risk tier. Guided field-by-field with plain-language explanations.

Produces: Formal system record with unique ID, risk classification, and accountable owner.

2

Component Inventory

32 guided questions across Models, Data, Vendors, Infrastructure, Controls, and Monitoring. Each question shows why it matters and which regulation it maps to.

Produces: A complete, structured evidence record across all six governance domains.

3

Gap Analysis

Auto-generated from your answers. Each gap includes its regulatory citation, the risk if left unaddressed, and suggested evidence types that may help close it.

Produces: Regulatory-cited gap register by severity — Critical, Major, Minor.

4

Assess & Assign

Assign an owner, remediation approach, and target date to each gap. This information flows into every report automatically.

Produces: Working action plan with owners and dates embedded in every report.

5

Evidence Package

Generate five downloadable HTML reports, each written for its audience — from board summary to technical review detail.

Produces: Board summary · Technical review record · Legal/DPO package · CISO assessment · Procurement review.

32 Questions Across Six Governance Domains

Questions include regulatory context tags where applicable — see which framework each item references.

Domain 1
Models

Foundation model, fine-tuning approach, model card availability, and version control. Maps to EU AI Act transparency requirements.

Domain 2
Data

Training data provenance, data quality controls, personal data handling, and retention. Maps to GDPR Articles 5, 13, and 25.

Domain 3
Vendors

Third-party AI service providers, sub-processors, contractual obligations, and exit planning. Maps to NIST AI RMF Govern 1.6.

Domain 4
Infrastructure

Compute environment, deployment architecture, access controls, and network isolation. Maps to NIST AI RMF Manage 2.2.

Domain 5
Controls

Human oversight mechanisms, fallback procedures, output validation, and incident response. Maps to EU AI Act Article 14 and 17.

Domain 6
Monitoring

Ongoing performance tracking, drift detection, logging, and post-market surveillance obligations. Maps to EU AI Act Article 72.

Automatic Gap Analysis with Regulatory Citations

Generated from your answers. Each gap notes the related regulation, the risk, and suggested evidence types that may help close it.

Severity classification

Each gap is rated Critical, Major, or Minor based on regulatory weight and organizational risk.

Regulatory citation

Each gap cites the article, section, or control it maps to — EU AI Act, GDPR, NIST AI RMF, or SBOM-for-AI where applicable.

Risk if unaddressed

Plain-language explanation of what the gap means for regulatory exposure, operational risk, or audit readiness.

Evidence required

Description of document, record, or control that could address the gap — a starting point for your evidence plan.

Five Stakeholder-Specific Reports

One workflow. One record. Five downloadable HTML reports — each written and organized for its intended audience.

Executive / Board Report

Risk posture summary, gap count by severity, and accountability ownership — written for board-level review. No technical background required to understand it.

Technical / Review Record

Full inventory of questions, answers, and gaps with regulatory citations. Structured for technical review and internal assurance workflows — not a substitute for independent audit or legal opinion.

Legal / DPO Package

GDPR data handling gaps, EU AI Act obligations, and evidence of controls — organized for Data Protection Officers and legal counsel review.

CISO / Risk Assessment

Security controls, infrastructure gaps, monitoring coverage, and incident response readiness — organized for security leadership and risk committee review.

Procurement Review

Vendor obligations, third-party AI service gaps, and contractual accountability — structured for procurement teams and supplier due diligence.

All five, one workflow

No extra work to produce different views. The tool generates all five from the same record — downloaded as self-contained HTML files.

Start AI Review

Regulatory Frameworks

Questions and gaps reference published regulations and standards where applicable. These are tool-generated indicators — not regulatory certifications or legal opinions.

EU AI Act
Risk Tier Classification

Unacceptable, High, Limited, and Minimal risk tiers. Articles 6, 9, 13, 14, 17, and 72 cited throughout the inventory and gap register.

GDPR
Data Protection by Design

Articles 5, 13, 22, and 25 covering lawfulness of processing, transparency, automated decision-making, and privacy by design.

NIST AI RMF 1.0
Govern · Map · Measure · Manage

All four core functions referenced. Specific subcategory citations (e.g. Govern 1.1, Manage 2.2) embedded in each relevant gap.

SBOM-for-AI
Minimum Elements

Emerging SBOM-for-AI minimum element requirements covering model provenance, training data lineage, and component transparency.

The entire review runs in your browser

On the free browser tier, questions, gap generation, and reports run locally. AI governance answers are not uploaded to TechnoSoluce servers. SBOM CVE lookup queries OSV.dev. See the Trust page for tier-specific details.