One Scan.Complete Visibility.
FLOM is a Multi-BOM software composition analysis platform. One scan gives you visibility across software, AI and cryptographic composition.
SBOM · CBOM · AIBOM from a single scan
Know what your software is made of.
Modern applications may contain hundreds or thousands of software components, AI technologies and cryptographic implementations.
FLOM provides visibility into this composition from a single platform, so software risk, AI risk and cryptographic risk can be understood together rather than in isolation.
Software risk
AI risk
Cryptographic risk
Scan where your software already lives.
FLOM accepts composition data from the places software is actually built, stored and shipped.
Example supported ecosystems and input sources
- GitHub
- GitLab
- Docker Hub
- Nexus Repository
- JFrog Artifactory
- APKs
- CLI
- Source Code ZIP
Illustrative of supported ecosystems, not an exhaustive list. Confirm the full matrix before publishing.
Centralized intelligence behind every scan.
Scans are evaluated against a centrally maintained intelligence set, so results stay consistent across projects, teams and ecosystems.
- 400,000+Vulnerability records
- 2,000+License identifiers
- 10+Programming languages and ecosystems
Discover. Analyze. Remediate. Govern.
One lifecycle from first scan to enforced policy.
- 01
Discover
Scan the places software is built and shipped.
- Version control systems
- Containers
- Binaries
- CI/CD pipelines
- CLI
- Source-code archives
- 02
Analyze
Use centralized intelligence to identify real-world risks.
- Multi-source vulnerability intelligence
- Direct and transitive dependency analysis
- Interactive dependency graph
- 03
Remediate
Prioritize what matters and understand the consequences of change.
- Prioritize issues
- Guided remediation
- Blast radius
- Machine-learning risk evaluation
- 04
Govern
Apply policy and enforce it before release.
- Security and licensing policies
- Compliance drift detection
- Enforcement before release
- Executive and technical reporting
One platform. Three views of composition.
The same scan, read three ways: software, cryptography and AI.
SBOM
Software Composition
Understand the software you depend on, including the parts you did not choose directly.
- Open-source components
- Third-party components
- Direct dependencies
- Transitive dependencies
- Hidden dependencies
SBOM generation is based on CycloneDX specifications.
CBOM
Cryptographic Composition
See where cryptography is used across your estate, and what will need to change.
- Cryptographic primitives
- Keys
- Certificates
- Algorithms
- Post-quantum migration considerations
Cryptographic inventory across scan targets.
AIBOM
AI Composition
Make AI usage visible, traceable and defensible as expectations on it increase.
- AI models
- Training-data lineage
- AI-specific dependencies
- Transparency
- Emerging regulatory requirements
AI usage and lineage across the scanned estate.
Built across the whole software lifecycle.
Discover
- Comprehensive open-source discovery
- Multi-source application scanning
- Continuous open-source monitoring
- Multi-ecosystem support
Understand
- Direct and transitive dependency analysis
- Interactive dependency graph
- Application risk dashboards
- Multi-source vulnerability intelligence
Build & Report
- Automated SBOM generation
- Automated CBOM and AIBOM generation
- Executive reporting
- Technical reporting
Govern
- Open-source license compliance
- Custom risk and security policies
- Full SDLC security coverage
- Supply-chain attack protection
- Machine-learning risk evaluation
Scan something. See everything.
Point FLOM at a repository, image or archive and see the composition behind it.