Skip to content

Frequently Asked Questions

Who can invite a vendor?

Only Organization users can invite vendors, from the Vendors page. Vendors cannot invite other vendors or create their own accounts without an invitation.

Can a vendor create their own products?

No. Products are created and assigned by the organization. Vendors can only view and submit SBOMs for products already assigned to them.

What SBOM formats does SBOM360 accept?

CycloneDX (JSON/XML, v1.2–v1.6) and SPDX (JSON/XML/RDF, v2.2–v2.3), up to 50 MB per file.

How do I know if my organization received my SBOM?

Vendors can check the SBOM Submissions list or the specific product's Version History; a scan-status badge confirms whether the file was received, scanned, and completed.

What is the difference between a notification and a VEX request?

A notification is sent by the organization to alert a vendor or customer about a vulnerability. A VEX request is submitted by a customer (or escalated by the organization to a vendor) asking for an official exploitability assessment on a specific CVE.

Can a customer see other customers' deployments or alerts?

No. Customers only see their own registered deployments and the notifications and VEX requests tied to their own account.

How do I automate SBOM uploads from my CI/CD pipeline?

As a vendor, go to Profile → API Access to retrieve your access token, then use the ready-to-copy GitHub Actions or GitLab CI snippet shown on the My Products or SBOM upload pages, storing the token as a CI/CD secret.

What happens if I mark a CVE as a VEX override at the organization level?

An organization-level VEX override records the organization's own assessment for its environment (for example, marking a CVE as a false positive) and, if enabled, is applied automatically to suppress that finding in future scans of the same product.