QorBOM™ gives audit firms, MSSPs, and consultancies a turnkey CBOM scanner under their own brand. CycloneDX 1.6 + SPDX 3.0 output. Signed by QorTrace's methodology. EU CRA-ready. Your logo on every report.
Limited early-access cohort · Apply before Q3 2026 launch · No payment yet
One endpoint. Paste a GitHub repo or upload a tarball. Get back a signed CycloneDX 1.6 BOM with every cryptographic primitive mapped to its post-quantum readiness. Audit-grade, regulator-defensible.
Drop in your logo, primary color, and disclaimer text. Every report your client sees carries your branding — not ours. Procurement loves it; you keep margin.
Sell at your hourly rate; we run the scans behind the scenes. Transparent per-scan platform pricing means your blended margin is predictable. No annual minimums for the first 25 partners.
The EU Cyber Resilience Act (CRA) makes CBOMs a binding requirement by 2027. US Executive Orders 14028 and 14306 push the same direction. NIST FIPS 203 / 204 / 205 are now binding for federal contractors. Your enterprise clients are going to ask you for this — be ready before they do.
QorBOM™ is built on top of QorTrace's methodology — the same one used to ship Threat Radar, Atlas, and audit engagements for treasuries, custodians, and exchanges. Every output we emit is regulator-defensible, peer-review-ready, and traceable to a public methodology pin.
Every BOM emitted carries this immutable methodology version + a SHA-256 over the canonical-sorted JSON. Reproducible by your peer-review process. Versioned via the QorTrace public methodology log so changes are publicly visible — auditors can cite the exact methodology used on the date of any historical scan.
Outputs map 1:1 to the evidence formats regulators and procurement teams already accept. No translation layer needed for your workpapers.
We don't store client repository contents beyond the scan window. Source code is fetched, scanned in-memory, and discarded. Only the BOM persists.
No proprietary BOM format, no lock-in. CycloneDX + SPDX are open standards — your clients can switch tooling tomorrow if they want to.
Each badge maps to a verifiable spec, citation, or audit trail. Hover for the full scope; the color band on each badge indicates whether QorBOM™ has implemented it, is aligned with it, or has an active roadmap commitment.
Tell us about your firm. We'll reach out within two business days with onboarding details and a sandbox API key. No payment is collected before the platform launches.
We use strictly-necessary cookies to run the app. With your consent we also use analytics cookies to understand how QorTrace is used so we can improve it. Cookie Policy · Privacy Policy