Skip to content

One Scan.Complete Visibility.

FLOM is a Multi-BOM software composition analysis platform. One scan gives you visibility across software, AI and cryptographic composition.

SBOM · CBOM · AIBOM from a single scan

ApplicationComponentsTransitive dependenciesKnown risk

Know what your software is made of.

Modern applications may contain hundreds or thousands of software components, AI technologies and cryptographic implementations.

FLOM provides visibility into this composition from a single platform, so software risk, AI risk and cryptographic risk can be understood together rather than in isolation.

  • Software risk

  • AI risk

  • Cryptographic risk

Scan where your software already lives.

FLOM accepts composition data from the places software is actually built, stored and shipped.

Example supported ecosystems and input sources

  • GitHub
  • GitLab
  • Docker Hub
  • Nexus Repository
  • JFrog Artifactory
  • APKs
  • CLI
  • Source Code ZIP

Illustrative of supported ecosystems, not an exhaustive list. Confirm the full matrix before publishing.

How software composition data reaches FLOMFive input channels — Upload files, Source code, Repositories, Container registries, CLI — feed into FLOM, which producesSBOM, CBOM, AIBOM.Upload filesSource codeRepositoriesContainer registriesCLIFLOM™SBOMCBOMAIBOM

Centralized intelligence behind every scan.

Scans are evaluated against a centrally maintained intelligence set, so results stay consistent across projects, teams and ecosystems.

  • 400,000+Vulnerability records
  • 2,000+License identifiers
  • 10+Programming languages and ecosystems

Discover. Analyze. Remediate. Govern.

One lifecycle from first scan to enforced policy.

  1. 01

    Discover

    Scan the places software is built and shipped.

    • Version control systems
    • Containers
    • Binaries
    • CI/CD pipelines
    • CLI
    • Source-code archives
  2. 02

    Analyze

    Use centralized intelligence to identify real-world risks.

    • Multi-source vulnerability intelligence
    • Direct and transitive dependency analysis
    • Interactive dependency graph
  3. 03

    Remediate

    Prioritize what matters and understand the consequences of change.

    • Prioritize issues
    • Guided remediation
    • Blast radius
    • Machine-learning risk evaluation
  4. 04

    Govern

    Apply policy and enforce it before release.

    • Security and licensing policies
    • Compliance drift detection
    • Enforcement before release
    • Executive and technical reporting

One platform. Three views of composition.

The same scan, read three ways: software, cryptography and AI.

ApplicationOne scanOpen-source componentsThird-party componentsDirect dependenciesTransitive dependenciesHidden dependencies

SBOM

Software Composition

Understand the software you depend on, including the parts you did not choose directly.

  • Open-source components
  • Third-party components
  • Direct dependencies
  • Transitive dependencies
  • Hidden dependencies

SBOM generation is based on CycloneDX specifications.

ApplicationOne scanCryptographic primitivesKeysCertificatesAlgorithmsPost-quantum migration considerations

CBOM

Cryptographic Composition

See where cryptography is used across your estate, and what will need to change.

  • Cryptographic primitives
  • Keys
  • Certificates
  • Algorithms
  • Post-quantum migration considerations

Cryptographic inventory across scan targets.

ApplicationOne scanAI modelsTraining-data lineageAI-specific dependenciesTransparencyEmerging regulatory requirements

AIBOM

AI Composition

Make AI usage visible, traceable and defensible as expectations on it increase.

  • AI models
  • Training-data lineage
  • AI-specific dependencies
  • Transparency
  • Emerging regulatory requirements

AI usage and lineage across the scanned estate.

Built across the whole software lifecycle.

Discover

  • Comprehensive open-source discovery
  • Multi-source application scanning
  • Continuous open-source monitoring
  • Multi-ecosystem support

Understand

  • Direct and transitive dependency analysis
  • Interactive dependency graph
  • Application risk dashboards
  • Multi-source vulnerability intelligence

Build & Report

  • Automated SBOM generation
  • Automated CBOM and AIBOM generation
  • Executive reporting
  • Technical reporting

Govern

  • Open-source license compliance
  • Custom risk and security policies
  • Full SDLC security coverage
  • Supply-chain attack protection
  • Machine-learning risk evaluation

Scan something. See everything.

Point FLOM at a repository, image or archive and see the composition behind it.