Skip to content

SBOM360 User Documentation

Version 1.0 — a complete guide for Organizations, Vendors, and Customers on managing Software Bills of Materials, vulnerabilities, and VEX statements.

SBOM360 brings the software supply chain into one place: submitting and scanning SBOMs, triaging vulnerabilities, exchanging VEX statements, and notifying affected customers.


Start with your role

Everything you can see and do on the platform depends on your user type. Pick the guide that matches your account:

  • :material-shield-account: Organization


    Manage products, vendors and customers, triage vulnerabilities, and send vulnerability notifications.

    Start here →

  • :material-truck-delivery: Vendor / Supplier


    Submit SBOMs for your assigned products, respond to alerts, and publish VEX statements.

    Start here →

  • :material-account-group: Customer


    Register deployments, receive vulnerability alerts, and request VEX assessments.

    Start here →


New to SBOM360?

Read these three chapters first — they explain what the platform does, who does what, and how a vulnerability travels from an SBOM to a customer notification.

  1. Platform Overview — what SBOM360 covers.
  2. User Roles — Organization, Vendor and Customer capabilities side by side.
  3. End-to-End Compliance Workflow — the full lifecycle, from SBOM upload to customer notification.

Common tasks

I want to… Go to
Upload an SBOM and link it to a product SBOM Management
Invite a vendor and set SBOM requirements Vendor Management
Triage a CVE and assign it to someone Vulnerability Queue and Triage
Notify customers about a vulnerability Customer Notifications
Submit an SBOM as a vendor SBOM Management (Vendor)
Answer a vulnerability alert with a VEX statement VEX Statements
Automate SBOM uploads from CI/CD Profile, Settings and API Access
Register a deployment as a customer My Deployments
Acknowledge an alert I received Security Inbox
Ask whether a CVE affects my deployment VEX Requests

Reference

About this documentation

Every instruction here reflects a feature that exists in the platform today.