Skip to content

Bill of materials

Provenance

Hardware and software bill of materials, with the evidence pack that comes out of it.

Beta Internal use

What it is

Every device the company holds, who holds it and what state it is in; every component every release ships, deduplicated by package URL across the whole estate; and security findings joined to both, so "is this advisory ours" is a lookup rather than a scan. Exports are control-tagged — organised by control reference, each section stating what the register evidences and what it does not — and every export is recorded in a hash-chained audit log.

Who it is for. Used by RODMENA for its own asset register and SBOM. Not sold; listed so the catalogue is complete.

  • SBOM
  • CycloneDX
  • SPDX
  • VEX
  • Asset register
  • Internal

What it does

Asset register

Every device with its custodian, state, encryption status and classification. Offboarding and incident response both start here.

Components, deduplicated

Components are deduplicated by package URL across the estate, so thirty products sharing a base image are one row and thirty occurrences.

Evidence, not assertions

Exports are organised by control reference and state their own limits; the audit log records the digest of the bytes produced.

Ready to look at Provenance?

The product site has the documentation and the way in. For procurement questions, a pilot or an integration, talk to us directly.