Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

CycloneDX is an efficient standard for Software Bill of Materials (SBOM) that is specifically crafted for application security and the analysis of supply chain components. The governance and ongoing development of this specification are overseen by the CycloneDX Core working group, which has its roots in the OWASP community. A thorough and precise catalog of both first-party and third-party components is crucial for identifying potential risks. Ideally, BOMs should encompass all direct and transitive components, as well as the interdependencies that exist among them. By implementing CycloneDX, organizations can swiftly fulfill essential requirements and progressively evolve to incorporate more advanced applications in the future. Furthermore, CycloneDX meets all SBOM criteria set forth in the OWASP Software Component Verification Standard (SCVS), ensuring comprehensive compliance and security management. This capability makes it an invaluable tool for organizations aiming to enhance their software supply chain integrity.

Description

Scribe continuously attests to your software's security and trustworthiness: ✓ Centralized SBOM Management Platform – Create, manage and share SBOMs along with their security aspects: vulnerabilities, VEX advisories, licences, reputation, exploitability, scorecards, etc. ✓ Build and deploy secure software – Detect tampering by continuously sign and verify source code, container images, and artifacts throughout every stage of your CI/CD pipelines ✓ Automate and simplify SDLC security – Control the risk in your software factory and ensure code trustworthiness by translating security and business logic into automated policy, enforced by guardrails ✓ Enable transparency. Improve delivery speed – Empower security teams with the capabilities to exercise their responsibility, streamlining security control without impeding dev team deliverables ✓ Enforce policies. Demonstrate compliance – Monitor and enforce SDLC policies and governance to enhance software risk posture and demonstrate the compliance necessary for your business

API Access

Has API No 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

GitHub Yes 
GitLab Yes 
Aqua Yes 
ArmorCode Yes 
Bitbucket No 
Bytesafe Yes 
Checkov Yes 
CircleCI No 
Cloudsmith Yes 
Contrast Security Yes 
Cybellum Yes 
Debricked Yes 
Google Yes 
JFrog Yes 
MergeBase Yes 
Microsoft Entra ID No 
OWASP Threat Dragon Yes 
XML Yes 
Xygeni Yes 

Integrations

GitHub Yes 
GitLab Yes 
Aqua No 
ArmorCode No 
Bitbucket Yes 
Bytesafe No 
Checkov No 
CircleCI Yes 
Cloudsmith No 
Contrast Security No 
Cybellum No 
Debricked No 
Google No 
JFrog No 
MergeBase No 
Microsoft Entra ID Yes 
OWASP Threat Dragon No 
XML No 
Xygeni No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Pricing Details

Free
Free Trial Yes 
Free Version Yes 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises Yes 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac Yes 
Linux Yes 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs No 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

CycloneDX

Website

cyclonedx.org

Vendor Details

Company Name

Scribe Security

Founded

2021

Country

Israel

Website

scribesecurity.com

Product Features

Cybersecurity

AI / Machine Learning No 
Behavioral Analytics No 
Endpoint Management No 
IOC Verification No 
Incident Management No 
Tokenization No 
Vulnerability Scanning No 
Whitelisting / Blacklisting No 

DevOps

Approval Workflow No 
Dashboard No 
KPIs No 
Policy Management No 
Portfolio Management No 
Prioritization No 
Release Management No 
Timeline Management No 
Troubleshooting Reports No 

Alternatives

Alternatives

CodeSentry Reviews

CodeSentry

CodeSecure