TraceGuard documentation
Everything you need to ingest SBOMs, prioritize vulnerabilities, triage findings with VEX, and stay continuously audit-ready.
Get started
What TraceGuard is, the ingest → parse → scan → findings pipeline, and how the pieces fit together.
Open →Core concepts
Organizations, projects, BOMs, components, vulnerabilities, findings, VEX, and assurance.
Open →Quickstart
Get your first SBOM scanned in about five minutes.
Open →Glossary
SBOM, VEX, KEV, EPSS, CycloneDX, SPDX, applicability — defined.
Open →Guides
Task-based walkthroughs for SBOM ingestion, triage, VEX, and evidence.
Open →Developers
BetaTokens & scopes, the GitHub SBOM Action, the MCP server, and the API.
Open →