Software supply-chain security

TraceGuard documentation

Everything you need to ingest SBOMs, prioritize vulnerabilities, triage findings with VEX, and stay continuously audit-ready.

Get started

What TraceGuard is, the ingest → parse → scan → findings pipeline, and how the pieces fit together.

Open →

Core concepts

Organizations, projects, BOMs, components, vulnerabilities, findings, VEX, and assurance.

Open →

Quickstart

Get your first SBOM scanned in about five minutes.

Open →

Glossary

SBOM, VEX, KEV, EPSS, CycloneDX, SPDX, applicability — defined.

Open →

Guides

Task-based walkthroughs for SBOM ingestion, triage, VEX, and evidence.

Open →

Developers

Beta

Tokens & scopes, the GitHub SBOM Action, the MCP server, and the API.

Open →