How TechnoSoluce Works

Six steps, browser-local

Upload an SBOM, get OSV-backed CVEs, role reports, and exports. Free tier works without an account. See sample reports Pricing

Get an SBOM

No file yet? Usually:

  • Build — CycloneDX/SPDX from repo or CI (e.g. Maven, npm, containers).
  • Request — from your software vendor.
  • Exploresample reports or app samples.

More detail: FAQ

Step 1

Upload your SBOM

CycloneDX, SPDX, or SWID (JSON or XML). Analysis stays in your browser. Need a file? See Get an SBOM.

Step 2

Live vulnerability scan

Real-time OSV.dev lookups per component.

Step 3

Aggregate risk signals

Vulnerability counts and heuristics roll up to portfolio-style views. Figures are indicative— not actuarial or certification-grade.

Step 4

Compliance assessment

Tool-assisted mapping to NTIA, NIST SP 800-161, ISO 27001:2022—gaps are indicators; validate in your program.

Step 5

Strategic intelligence

Per-component flags; exec and stakeholder text generated from the run.

Step 6

Export and act

PDF, HTML, JSON, CSV, or Excel—pick the format for each audience.

What you get

Outputs matched to each role, from board to engineering.

For security teams

  • CVSS v3 scores per component
  • OSV.dev live CVEs — not cached
  • Ransomware + supply chain risk
  • Batch analysis (up to 10 files)
Most popular

For compliance officers

  • NTIA EO 14028 compliance
  • NIST SP 800-161 mapping
  • ISO 27001:2022 gap analysis
  • Audit-ready evidence export

For executives

  • Executive summary with key findings
  • Board-ready PDF export
  • Stakeholder narratives auto-generated per audience

Know where your software stands?

Take the free diagnostic — 15 questions, instant results, personalized recommendations.