Skip to main content

CBOM (CycloneDX)

Purpose: Machine-readable cryptographic inventory using CycloneDX 1.6+ cryptographic-asset components. When to use: Feed enterprise posture platforms, Dependency-Track-style tools, or any CycloneDX-aware pipeline. This is the portable inventory artifact.

Example

Caveats

  • Private keys and secrets are extracted for metadata only and discarded. Snippets are redacted before output.
  • The CBOM must remain identical if optional AI enrichment is toggled on or off (enrichment annotates; it never reclassifies).
  • Static discovery is incomplete by nature — the CBOM is an inventory of what was found, not a completeness certificate.