Discover
Static + runtime scanners walk your codebase, container images, network captures, and config to surface every algorithm in use — including the ones buried in third-party deps you didn't write.
Point QorBom at any GitHub repo, container image, or Go/Rust/JS dependency tree. We produce a signed Cryptographic Bill-of-Materials aligned with NIST FIPS 203/204/205 and EU CRA.
Generate, version, and ship cryptographic bills of materials stamped with your own brand. Big-4 + boutique audit practices license the engine; we keep the methodology NIST FIPS-203/204/205 current so you don't have to.
A CBOM is a machine-readable inventory of every cryptographic primitive in a software stack — the keys, algorithms, certificates, and protocols that protect each layer. Think of it as an SBOM, but quantum-aware: it surfaces exactly which assets will break when classical RSA & ECC retire, and where to migrate first.
Static + runtime scanners walk your codebase, container images, network captures, and config to surface every algorithm in use — including the ones buried in third-party deps you didn't write.
Findings normalize into a signed, versioned CBOM keyed to NIST FIPS 203/204/205 and CISA's 2024 reporting schema. Every primitive carries an exposure score, owner, and proof of provenance.
The CBOM becomes a living migration plan: drift alerts when a new RSA key ships, partner-firm sign-offs on each retirement, and an audit-trail every regulator already asks for.
The same engine your branded portal will run. Anonymous + rate-limited + the first 25 findings + 25 components are returned.
Live, anonymous. The first 25 findings + 25 components are returned so you can see exactly what an audit-ready CBOM looks like. Apply for an API key for the full output.
Subdomain, logo, color, footer. Tenant-isolated. We don't show up in the URL bar or in the report PDF. Your client sees you, not us.
Pull CBOMs through a plain HTTP API or our CLI. Pipe them into your existing GRC stack. CycloneDX 1.6 + SPDX 3.0.1 are first-class outputs.
Every report cites the exact methodology hash that generated it. Re-run a year later, get a diff — defensible in a regulator's review.
We update for every NIST draft, CISA notice, and EU CRA delegated act. You inherit the changes without re-platforming.
Scans are ephemeral. We never write your client's repo contents to disk. Hashes only. SOC-2-track architecture, auditable by inspection.
Trust page, methodology page, SLA, DPA, and standardised SoC questionnaire. Your client's CISO has answers before they ask.
Fire a POST, get back a CBOM signed against the current methodology version. The response is what you ship to your client — no transformation, no manual cleanup.
READ THE FULL API DOCS →curl -X POST https://api.qorbom.com/v1/scans \
-H "Authorization: Bearer $QORBOM_KEY" \
-H "Content-Type: application/json" \
-d '{
"repo_url": "https://github.com/acme/payments",
"branch": "main",
"format": "cyclonedx-1.6"
}'Sign a partnership letter, pick a tenant subdomain, drop a logo, configure your first scan. No build-out. No backlog for our engineering team. The founding cohort gets concierge onboarding + locked-in pricing.
QorTrace is the engine behind every QorBOM — the actual scanner that walks a client's codebase, container images, and runtime traffic to produce the inventory. If you're standing in front of a real engagement, that's the next call.
We use strictly-necessary cookies to run the app. With your consent we also use analytics cookies to understand how QorTrace is used so we can improve it. Cookie Policy · Privacy Policy