Open-source vulnerability database with ecosystem-aware component matching.
EndoScan
SBOM risk intelligence
Surface component risk before it becomes an incident.
EndoScan ingests CycloneDX and SPDX inventories, enriches them with lifecycle and vulnerability intelligence, and surfaces ownership-aware alerts before advisories land in the wrong inbox.
Data sources
Provider model built into the schema.
Lifecycle and vulnerability data is cached per component version, with provider boundaries and TTLs modeled directly in the database.
Authoritative lifecycle and support window data for components and runtimes.
Package metadata, dependency graphs, and maintenance signals.
Per-application lifecycle mapping overrides for internal support policies.