# Top Free Software Bill of Materials (SBOM) Software - Page 2

## How Many Software Bill of Materials (SBOM) Software Products Does G2 Track?

**Total Products under this Category:** 34

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+3.17%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: August 06, 2026_

## How Does G2 Rank Software Bill of Materials (SBOM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 900+ Authentic Reviews
- 34+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

**Sponsored**

### OX Security

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1008169&secure%5Bchosen_at%5D=2026-08-09T16%3A08%3A48Z&secure%5Bdisplayable_resource_id%5D=1008169&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1008169&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1312693&secure%5Bresource_id%5D=1008169&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-bill-of-materials-sbom%2Ffree%3Fpage%3D2&secure%5Btoken%5D=444204062a9e9fa309d1f3173d1d19be975ec07cbaa66d4b72650322223c9b33&secure%5Burl%5D=https%3A%2F%2Fwww.ox.security%2Fbook-a-demo%2F&secure%5Burl_type%5D=custom_url)

### [Qwiet AI](https://www.g2.com/products/qwiet-ai/reviews)

Qwiet AI delivers comprehensive application security by combining agentic AI with advanced code analysis. In a single scan, the platform provides uniquely accurate SAST, SCA, SBOM, secrets detection, and container analysis that helps dev and security teams find and fix vulnerabilities faster. With its proprietary Code Property Graph (CPG) technology and AI/ML models, Qwiet AI achieves up to 95% reduction in false positives compared to traditional tools, while offering contextual AutoFix that understands the unique context of your code, even across complex enterprise applications. Q: What makes Qwiet AI different from other AppSec solutions? A: Qwiet AI stands out through its agentic AI approach, which enables autonomous vulnerability detection and remediation. The platform's Code Property Graph technology allows for deeper code analysis and more accurate vulnerability detection, resulting in dramatically fewer false positives than traditional tools. This advanced technology enables the platform to understand code relationships and context at a deeper level, leading to precise vuln detection and contextually appropriate fixes. Q: What security capabilities does the platform include? A: The platform provides comprehensive security coverage including: - Static Application Security Testing (SAST) using a patented CPG-based approach, for vuln detection that is objectively the fastest and most accurate available per the OWASP benchmark - Software Composition Analysis (SCA) for third-party dependency scanning and vulnerability detection in open source components - Automated SBOM generation for supply chain transparency and compliance requirements - Advanced secrets detection to prevent credential exposure and secure sensitive information - Container security analysis built in - AI-powered AutoFix for automated vulnerability remediation with contextually aware patches, powered by the CPG and a custom AI/ML engine with its own LLM - Custom rule creation capabilities for organization-specific security requirements Q: How does Qwiet AI improve development workflows? A: Qwiet AI integrates seamlessly into existing CI/CD pipelines and developer workflows. The platform's speed (up to 40x faster than traditional scanners) and accuracy mean developers spend less time investigating false positives and more time coding. The AutoFix capability helps developers resolve issues quickly with AI-generated patches that are contextually aware and tailored to your codebase. Additionally, the platform provides IDE integrations and pull request analysis to catch vulnerabilities early in the development process. Q: What do customers think? A: Qwiet AI provides enterprise-grade support with dedicated customer success representatives and technical account managers. The platform consistently receives high marks for customer support, with a 97% "would recommend" rate in Gartner's Voice of the Customer. Customers receive comprehensive onboarding assistance, ongoing technical support, and regular check-ins to ensure successful implementation and adoption. Q: How can I get started with Qwiet AI? A: Qwiet AI offers self-service access, self-guided demos, and AE-guided demos, depending on your needs. You can request a personalized demo through the company website at qwiet.ai to see how the platform addresses their specific security challenges. You can also sign up for self-service access through the web site, or access documentation and integration guides there.

**Average Rating:** 4.8/5.0

**Total Reviews:** 3

#### Who Is the Company Behind Qwiet AI?

- **Seller:** [Qwiet AI](https://www.g2.com/sellers/qwiet-ai)
- **HQ Location:** San Jose, California, United States
- **Twitter:** @ShiftLeftInc  
1,164 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=dbca0b84e2c33a23f09717f495d5c8693d9858bba84b3152d5262dae9d5bc5e0&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fqwiet&secure%5Burl_type%5D=linkedin_company_website)  
45 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Large, 33% Small

#### What Do G2 Reviewers Say About Qwiet AI?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **responsive and collaborative support** from Qwiet AI, enhancing integration into their CI/CD pipelines.
- Users value the **highly responsive customer support** of Qwiet AI, which facilitates seamless integration processes.
- Users value the **easy integrations** of Qwiet AI, appreciating its thorough documentation for seamless CI/CD pipeline incorporation.
- Users value the **comprehensive documentation** from Qwiet AI, facilitating seamless integration into CI/CD pipelines.
- Users value the **effective team collaboration** fostered by Qwiet AI’s responsive support and thorough integration documentation.

##### Cons

- Users find the lack of a graphical interface for policies frustrating, relying solely on the **command line interface**.
- Users find the **limited customization options** frustrating, as policy creation relies solely on the CLI without a user interface.
- Users find the **limited features** of Qwiet AI frustrating, lacking a user-friendly interface for policy creation.
- Users find the lack of a user interface for creating policies a significant **UX improvement** concern for Qwiet AI.

#### What Are Recent G2 Reviews of Qwiet AI?

**["A great easy-to-use SAST Scanner"](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)**

**Rating:** 5.0/5.0 stars

_— Verified User in Retail_

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)

**["Seamless Integration with Responsive Support"](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)**

**Rating:** 5.0/5.0 stars

_— Brooks S._

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)

### [SCANOSS](https://www.g2.com/products/scanoss/reviews)

SCANOSS is the industry-leading open source software intelligence provider, offering the largest database of open source information available. SCANOSS delivers cutting-edge tools and services that help businesses and developers detect, manage, and secure their open source components. By identifying license obligations, security vulnerabilities, and other risk concerns, SCANOSS ensures that organisations can harness the power of open source safely and securely throughout the development pipeline.

**Average Rating:** 4.3/5.0

**Total Reviews:** 2

#### Who Is the Company Behind SCANOSS?

- **Seller:** [SCANOSS](https://www.g2.com/sellers/scanoss)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e9ad0cb5bc7f8eadedb40833e1d3b44ede507c82f885c3670c1ad7ffe0761d1f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fscanoss&secure%5Burl_type%5D=linkedin_company_website)  
24 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of SCANOSS?

**["SCANOSS Open Source Inventorying Engine"](https://www.g2.com/survey_responses/scanoss-review-7288704)**

**Rating:** 4.5/5.0 stars

_— Joe H._

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7288704)

**["Great product with a valuable solution but the paid SaaS Tier might be a bit expensive for some"](https://www.g2.com/survey_responses/scanoss-review-7283528)**

**Rating:** 4.0/5.0 stars

_— Joe H._

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7283528)

### [Vigiles](https://www.g2.com/products/vigiles/reviews)

Vigiles is a best-in-class vulnerability monitoring and remediation tool that combines a curated CVE database, continuous security feed based on your SBOM, powerful filtering, and easy triage tools so you don’t get blindsided by vulnerabilities.

**Average Rating:** 4.2/5.0

**Total Reviews:** 6

#### Who Is the Company Behind Vigiles?

- **Seller:** [Timesys](https://www.g2.com/sellers/timesys)
- **Year Founded:** 1996
- **HQ Location:** Pittsburgh, US
- **Twitter:** @Timesys  
540 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5e55208e74e888cc5733ffc011cda8f939829410d9548b06dd128583ee8ba8d4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftimesys-corporation%2F&secure%5Burl_type%5D=linkedin_company_website)  
52 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 83% Small, 17% Large

#### What Are Recent G2 Reviews of Vigiles?

**["Vigiles review"](https://www.g2.com/survey_responses/vigiles-review-8911852)**

**Rating:** 4.0/5.0 stars

_— Tushar T._

[Read full review](https://www.g2.com/survey_responses/vigiles-review-8911852)

**["A Revolutionary Security Solution for Peace of Mind"](https://www.g2.com/survey_responses/vigiles-review-8284121)**

**Rating:** 4.0/5.0 stars

_— Prashant S._

[Read full review](https://www.g2.com/survey_responses/vigiles-review-8284121)

- [&lsaquo; Prev‹ Prev](/categories/software-bill-of-materials-sbom/free?order=popular#product-list)
- [1](/categories/software-bill-of-materials-sbom/free?order=popular#product-list)
- 2
- Next &rsaquo;Next ›

Spotlight Categories

[Network Monitoring Software](https://www.g2.com/categories/network-monitoring)

[Robotic Process Automation (RPA) Software](https://www.g2.com/categories/robotic-process-automation-rpa)

[Experience Management Software](https://www.g2.com/categories/experience-management)

[Zero Trust Networking Software](https://www.g2.com/categories/zero-trust-networking)

[Managed File Transfer (MFT) Software](https://www.g2.com/categories/managed-file-transfer-mft)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Software Bill of Materials (SBOM) Themes](/categories/software-bill-of-materials-sbom/themes)