Map SBOM components.
Document AI governance gaps with cited evidence.
Upload a CycloneDX or SPDX SBOM for real CVE findings — or run a five-phase AI accountability review with stakeholder-ready evidence.
SBOM Analyzer — three steps
Upload a software bill of materials, match components to known vulnerabilities, and review findings with compliance context — in your browser.
Upload
Drop a CycloneDX or SPDX file. Processing runs locally — your SBOM is not sent to our servers.
Match vulnerabilities
Components are checked against OSV.dev for known CVEs. Results appear in seconds with severity and package context.
Review & report
Explore findings, framework alignment (NTIA, NIST, and related supply-chain guidance), and stakeholder-ready views for security and compliance teams.
AI Governance Review — five phases, one evidence package
A structured accountability workflow for deployed AI systems. Complete in one sitting or save progress and return — each phase builds on the last.
Define System
Name the AI system, describe its purpose, and classify its EU AI Act risk tier. The tool guides you through each field with plain-language explanations of why each one matters to regulators and auditors.
Component Inventory
Answer 32 guided questions across six governance domains: Models, Data, Vendors, Infrastructure, Controls, and Monitoring. Questions include regulatory context tags — EU AI Act, GDPR, NIST AI RMF, G7 Hiroshima AI Process, ISO/IEC 42001, OECD AI principles, and SBOM-for-AI minimum elements.
Gap Analysis
The gap register is generated automatically from your answers. Each gap includes its regulatory citation, the risk if left unaddressed, and suggested evidence types that may help close it.
Assess & Assign
For each gap, assign an owner, choose a remediation approach, and set a target date. This is where a list of findings becomes an action plan — ownership and target dates flow into every stakeholder report.
Evidence Package
Generate five stakeholder-specific HTML reports from the single record you've built. The board report uses narrative and summary; the technical record includes every question and answer; the legal package focuses on GDPR and EU AI Act obligations; the CISO report covers control gaps, monitoring obligations, and remediation owners; the procurement review maps vendor accountability, contractual gaps, and AI supply chain risk.
Browser-based · no account required on the free tier
Built for teams who need defensible evidence
Governance, legal, security, and procurement stakeholders use TechnoSoluce when cited gap analysis and role-specific reports matter more than checkbox scores.
Governance & compliance
EU AI Act and NIST AI RMF gap registers with regulatory citations — self-assessment outputs, not certifications.
Security & engineering
CycloneDX and SPDX upload, OSV-backed CVE mapping, and supply-chain risk views — processed locally, without sending SBOM files to our servers.
Legal & procurement
GDPR and EU AI Act obligation packages, vendor accountability maps, and procurement reviews that surface contractual and AI supply chain gaps.
Part of the ERMITS product family — alongside VendorSoluce™ and CyberCorrect™.