# Best Software Bill of Materials (SBOM) Software - Page 2

## How Many Software Bill of Materials (SBOM) Software Products Does G2 Track?

**Total Products under this Category:** 34

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+3.17%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: August 06, 2026_

## How Does G2 Rank Software Bill of Materials (SBOM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 900+ Authentic Reviews
- 34+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

**Sponsored**

### CAST Highlight

Portfolio-level insights for app modernization, AI readiness, tech debt, OSS risks CAST Highlight is a SaaS software intelligence technology that delivers rapid, fact-based insights across your entire application portfolio. By automatically analyzing the source code of hundreds or thousands of applications, CAST Highlight helps organizations assess cloud maturity, AI & Agentic readiness, software health, open source risk, resiliency, technical debt, and sustainability from a single lightweight scan. CAST Highlight is designed for CIOs, CTOs, enterprise architects, cloud leaders, application owners, security teams, and modernization teams that need a fact-based way to prioritize modernization, cloud, and AI adoption decisions at scale. It helps teams identify which applications are ready to move quickly, which require remediation, and where hidden software risks may affect transformation cost, timelines, security, resilience, or business outcomes. Unlike traditional manual or survey-based assessments, CAST Highlight analyzes application source code directly to rapidly segment portfolios, prioritize modernization paths, and uncover risks before they impact transformation programs. Organizations use CAST Highlight to: - Accelerate cloud migration and modernization planning - Segment applications by cloud maturity and transformation path - Identify high-value AI adoption opportunities - Assess Agentic Readiness across application portfolios - Prioritize technical debt, resiliency, and maintainability improvements - Assess open source vulnerabilities and IP / license exposure - Evaluate software sustainability with Green Impact insights - Reduce complexity, cost, and risk across transformation programs Businesses move faster using CAST to understand, improve, and transform their software. Through semantic analysis of source code, CAST generates dashboards and 3D maps for executives, technologists, and AI to navigate inside individual applications and across entire portfolios. This intelligence enables companies to steer, speed, and report on initiatives such as technical debt, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1008169&secure%5Bchosen_at%5D=2026-08-08T20%3A51%3A11Z&secure%5Bdisplayable_resource_id%5D=1008169&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1008169&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=58553&secure%5Bresource_id%5D=1008169&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-bill-of-materials-sbom%3Fpage%3D2&secure%5Btoken%5D=8951e6ba00bf6b6b8118f540c1997b83ff4b3970d481d9f01107d73be1a8f145&secure%5Burl%5D=https%3A%2F%2Fwww.castsoftware.com%2Ftryhighlight%3Futm_campaign%3Dg2_clicks_ads%26utm_source%3Dcast_highlight%26utm_medium%3Dtrial_request&secure%5Burl_type%5D=free_trial)

### [SonarQube](https://www.g2.com/it/products/sonarqube/reviews)

Sonar, lo standard del settore per la verifica del codice e la revisione automatizzata del codice, aiuta a ridurre le interruzioni, migliorare la sicurezza e ridurre i rischi associati alla codifica AI e agentica. Come piattaforma di verifica indipendente, Sonar consente alle organizzazioni di sviluppare in modo sicuro alla velocità dell'AI. Sonar è la base per l'ingegneria del software ad alte prestazioni, analizzando oltre 750 miliardi di righe di codice al giorno per garantire che le applicazioni siano sicure, affidabili e manutenibili. Radicato nella comunità open source, Sonar è fidato da oltre 7 milioni di sviluppatori a livello globale, inclusi team di ServiceNow, Booking.com, Deutsche Bank, AstraZeneca e Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### Who Is the Company Behind SonarQube?

- **Venditore:** [SonarSource Sàrl](https://www.g2.com/it/sellers/sonarsource-sarl)
- **Sito web dell'azienda:** www.sonarsource.com
- **Anno di Fondazione:** 2008
- **Sede centrale:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Tecnologia dell'informazione e servizi, Software per computer
- **Company Size:** 41% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano come SonarQube **segnala efficientemente i problemi di qualità e sicurezza del codice** , garantendo una base di codice pulita e manutenibile.
- Gli utenti apprezzano le **funzionalità di filtraggio e prioritizzazione dei problemi** di SonarQube, migliorando l'attenzione sui compiti ad alta priorità.
- Gli utenti apprezzano le funzionalità di **identificazione e prioritizzazione dei problemi** di SonarQube, migliorando l'attenzione sui compiti critici.
- Gli utenti trovano **la facilità d'uso** di SonarQube inestimabile per mantenere la qualità del codice e integrarsi perfettamente nei flussi di lavoro di sviluppo.
- Gli utenti apprezzano le **facili integrazioni** con gli strumenti CI/CD esistenti, migliorando il loro flusso di lavoro di sviluppo senza problemi.

##### Cons

- Gli utenti affrontano sfide con **bug del software** poiché SonarQube può consumare eccessivamente RAM e occasionalmente segnalare falsi positivi.
- Gli utenti trovano la configurazione di SonarQube **complessa** , soprattutto per i principianti, portando a difficoltà e avvisi travolgenti da gestire.
- Gli utenti incontrano **falsi positivi** che complicano le valutazioni, sebbene esistano opzioni di mitigazione attraverso un'analisi dettagliata e la personalizzazione delle regole.
- Gli utenti trovano che la **complessità nella configurazione** di SonarQube e gli avvisi eccessivi possano ostacolare un uso efficace e l'efficienza.
- Gli utenti trovano la **configurazione complessa** di SonarQube impegnativa, soprattutto per i principianti non familiari con il processo di configurazione.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube: Integrazione Facile, Interfaccia Semplice e Solida Scansione Gratuita della Qualità del Codice"](https://www.g2.com/it/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/it/survey_responses/sonarqube-review-12975264)

**["SonarQube individua i problemi in anticipo con rapporti chiari e attuabili"](https://www.g2.com/it/survey_responses/sonarqube-review-13204491)**

**Rating:** 4.0/5.0 stars

_— Kewin M._

[Read full review](https://www.g2.com/it/survey_responses/sonarqube-review-13204491)

#### What Are G2 Users Discussing About SonarQube?

- [A cosa serve SonarLint?](https://www.g2.com/it/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/it/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/it/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/it/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/it/discussions/what-is-sonarqube-and-its-features)

### [Xygeni](https://www.g2.com/it/products/xygeni/reviews)

Proteggi il tuo Sviluppo e Consegna del Software! Xygeni Security è specializzata nella Gestione della Postura di Sicurezza delle Applicazioni (ASPM), utilizzando approfondimenti contestuali per dare priorità e gestire efficacemente i rischi di sicurezza riducendo al minimo il rumore e gli avvisi travolgenti. Le nostre tecnologie innovative rilevano automaticamente il codice dannoso in tempo reale al momento della pubblicazione di nuovi componenti o aggiornamenti, notificando immediatamente i clienti e mettendo in quarantena i componenti interessati per prevenire potenziali violazioni. Con una copertura estesa che abbraccia l'intera catena di fornitura del software, inclusi componenti Open Source, processi e infrastrutture CI/CD, rilevamento di anomalie, perdita di segreti, Infrastruttura come Codice (IaC) e sicurezza dei container, Xygeni garantisce una protezione robusta per le tue applicazioni software. Fidati di Xygeni per proteggere le tue operazioni e dare potere al tuo team di costruire e consegnare con integrità e sicurezza.

**Average Rating:** 4.6/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Xygeni?

- **Venditore:** [Xygeni Security](https://www.g2.com/it/sellers/xygeni-security)
- **Anno di Fondazione:** 2021
- **Sede centrale:** Madrid, ES
- **Twitter:** @xygeni  
178 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0302db05d62f71019af9c96a9c2a81cfa4c370ac1ddef2c863b931a5bb7be15a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fxygeni%2F&secure%5Burl_type%5D=linkedin_company_website)  
30 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Company Size:** 60% Small, 40% Medium

#### What Do G2 Reviewers Say About Xygeni?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti elogiano Xygeni per le sue **funzionalità di sicurezza complete** , migliorando la protezione mantenendo efficienti i processi di sviluppo software.
- Gli utenti apprezzano la **prioritizzazione contestuale del rischio** di Xygeni, che consente di concentrarsi in modo efficiente sui problemi di sicurezza più critici.
- Gli utenti apprezzano la **gestione efficace del rischio** di Xygeni, garantendo la sicurezza senza ostacolare la velocità di sviluppo.
- Gli utenti elogiano le **robuste funzionalità di sicurezza** di Xygeni, garantendo una gestione efficiente delle vulnerabilità e la conformità durante tutto lo sviluppo.
- Gli utenti apprezzano l' **integrazione CI/CD senza soluzione di continuità** di Xygeni, che migliora la sicurezza senza ostacolare la velocità di sviluppo.

##### Cons

- Gli utenti sperimentano **un'installazione difficile** con Xygeni a causa degli aggiustamenti manuali necessari per configurazioni CI/CD specifiche.
- Gli utenti trovano la **curva di apprendimento per i nuovi utenti** impegnativa, necessitando di familiarità con le migliori pratiche di AppSec per approfondimenti più profondi.

#### What Are Recent G2 Reviews of Xygeni?

**["Lo strumento essenziale per la sicurezza proattiva e lo sviluppo sicuro"](https://www.g2.com/it/survey_responses/xygeni-review-11393516)**

**Rating:** 4.5/5.0 stars

_— Marcos C._

[Read full review](https://www.g2.com/it/survey_responses/xygeni-review-11393516)

**["Rivoluzionato il nostro flusso di lavoro sulla sicurezza con un'efficienza unificata e guidata dall'IA"](https://www.g2.com/it/survey_responses/xygeni-review-11998435)**

**Rating:** 5.0/5.0 stars

_— Yerassyl K._

[Read full review](https://www.g2.com/it/survey_responses/xygeni-review-11998435)

### [BINARLY](https://www.g2.com/products/binarly/reviews)

Binarly is an AI-powered platform dedicated to protecting devices from emerging firmware and hardware threats. Founded in 2021 and headquartered in Pasadena, California, Binarly leverages advanced machine learning and deep code inspection at the binary level to provide comprehensive visibility into hardware and firmware vulnerabilities. This approach enables security teams to detect and respond to sophisticated attacks below the operating system, ensuring robust protection for enterprise device infrastructures.

#### Who Is the Company Behind BINARLY?

- **Seller:** [BINARLY](https://www.g2.com/sellers/binarly)
- **Year Founded:** 2021
- **HQ Location:** Santa Monica, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=39af51e1893105779ac55a8fa419bb924356c7fc07f03cac45d384721ed5de9b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbinarlyinc&secure%5Burl_type%5D=linkedin_company_website)  
48 employees on LinkedIn®

### [CAST SBOM Manager](https://www.g2.com/it/products/cast-sbom-manager/reviews)

CAST SBOM Manager consente agli utenti di creare, personalizzare e mantenere automaticamente le Distinte Base del Software (SBOM) con il massimo livello di controllo e flessibilità. Rileva le dipendenze open source e i rischi correlati (vulnerabilità e avvisi di sicurezza, licenze, obsolescenza) direttamente dalla scansione del codice sorgente, e permette di creare e mantenere nel tempo i metadati SBOM (componenti proprietari, licenze personalizzate, vulnerabilità) e molto altro.

#### Who Is the Company Behind CAST SBOM Manager?

- **Venditore:** [CAST](https://www.g2.com/it/sellers/cast)
- **Anno di Fondazione:** 1990
- **Sede centrale:** New York
- **Twitter:** @SW\_Intelligence  
1,887 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 dipendenti su LinkedIn®
- **Proprietà:** Bridgepoint

### [CBOM Secure](https://www.g2.com/products/cbom-secure/reviews)

CBOM Secure is a machine-readable Cryptographic Bill of Materials (CBOM) platform that delivers continuous visibility and control over cryptography across source code, binaries, containers, and runtime environments. It automatically discovers and inventories algorithms, keys, certificates, protocols, and libraries, creating a centralized, normalized system of record. By mapping cryptographic assets to real execution paths, CBOM helps organizations distinguish dormant components from active usage, prioritize risk, and accelerate incident response. The platform supports compliance with standards such as NIST, FIPS 140-3, CMMC 2.0, and ISO 27001 while identifying legacy and quantum-vulnerable cryptography to enable structured post-quantum migration. Available on-premises, in the cloud, SaaS, or hybrid, CBOM transforms undocumented cryptography into a governed, audit-ready security control.

#### Who Is the Company Behind CBOM Secure?

- **Seller:** [Encryption Consulting](https://www.g2.com/sellers/encryption-consulting)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1d654ade21ce2eb9ddbaad24f7ea185be39146c33ee0a0785f0245a9416b8338&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fencryptionconsulting%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [CipherScan](https://www.g2.com/products/cipherscan/reviews)

CipherScan by QuantumGenie is an AI-native cryptographic discovery platform that inventories cryptographic assets across source code, cloud infrastructure, certificates, keys, databases, and endpoints, generating a Cryptographic Bill of Materials (CBOM) to identify classical and quantum-vulnerable cryptography ahead of post-quantum migration. CipherScan performs one-time or continuous cryptographic discovery through QuantumGenie's numerous integrations across enterprise environments. QuantumGenie supports integration across Microsoft Azure, Amazon Web Services, Google Cloud, GitHub, Bitbucket, GitLab, MongoDB, PostgreSQL, MySQL, Jenkins, Thales, Splunk, CrowdStrike, IBM Cloud, ServiceNow, Datadog, Redis, and other infrastructure and data platforms. Therefore, CipherScan by QuantumGenie is a pioneer in post-quantum cryptography. CipherScan by QuantumGenie has also recently launched on Microsoft Marketplace, arriving alongside the validation by Google Cloud Marketplace Solution. CipherScan is also available on Visual Studio Code Marketplace and is soon coming on AWS Marketplace and Splunk Cloud Marketplace.

#### Who Is the Company Behind CipherScan?

- **Seller:** [QuantumGenie](https://www.g2.com/sellers/quantumgenie)
- **Year Founded:** 2024
- **HQ Location:** Westlake Village, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9a73b7e8e233496390af8a7e80849cdbfd42cdad81f753880e46d80b475d7121&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fquantumgenie&secure%5Burl_type%5D=linkedin_company_website)  
12 employees on LinkedIn®

### [Enso Security](https://www.g2.com/products/enso-security/reviews)

Enso Application Security Posture is a platform for AppSec teams to manage their day-to-day work, implement their security strategy into an AppSec organizational program, enforce it and automate it. And all of that in a scalable rapidly changing environment. AppSec teams struggle with prioritization - they may have a vision and concept of how to handle AppSec, but they don’t know where to invest and what actions to take. To keep up with R&D velocity and scale, Enso provides full visibility on the application inventory, focuses the AppSec teams on the most important tasks and insights, and takes a policy-based “call to action” approach so that the AppSec professionals won’t waste their time looking for application changes, prioritizing, or doing manual work.

#### Who Is the Company Behind Enso Security?

- **Seller:** [Enso Security](https://www.g2.com/sellers/enso-security)
- **HQ Location:** Boston, Massachusetts, United States
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=45fc4b87f2801662fd8218d907d0fb3e5470d80ca99df2f38b47aa42e4a8c865&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fenso-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,331 employees on LinkedIn®

### [Eracent SBOM-HQ](https://www.g2.com/it/products/eracent-sbom-hq/reviews)

SBOM-HQ™ - da Eracent SBOM-HQ™ fornisce un insieme completo di dati, funzionalità di reportistica e analisi che aiutano le organizzazioni a minimizzare i rischi e a conformarsi ai mandati e alle direttive informatiche. Mentre SBOM-HQ™ offre valore ai team di sviluppo di applicazioni interne e commerciali, è anche unico nel suo approccio per soddisfare i requisiti delle organizzazioni che acquistano o si abbonano a software da numerosi editori. Questi "consumatori di software" dovranno gestire dozzine, centinaia o addirittura migliaia di SBOM per i prodotti che utilizzano, e questo è impraticabile o impossibile da fare uno alla volta. SBOM-HQ™ si basa su un repository centralizzato e unico di librerie, componenti e altri dati correlati dagli SBOM. Riduce drasticamente il tempo di risposta quando viene segnalata una vulnerabilità poiché elimina la necessità di esaminare gli SBOM individualmente. Come funziona SBOM-HQ™? I clienti caricano i loro file SBOM tramite l'interfaccia utente. Durante questo processo semplice, gli utenti possono assegnare informazioni correlate che possono essere utilizzate per supportare la reportistica, i filtri, l'accesso ai dati e altro ancora. Queste informazioni includono Editore, Linea di Business, Componente dell'Applicazione e altro. SBOM-HQ™ "decompone" ogni SBOM caricato e registra il prodotto software a cui appartiene l'SBOM e tutto il contenuto dell'SBOM. Questo si traduce in un indice di componenti e librerie mappati ai prodotti. Se una vulnerabilità viene segnalata da NIST o un'altra organizzazione, i clienti ricevono un rapporto immediato di ogni prodotto in uso nella loro organizzazione che include il componente o la libreria interessata. SBOM-HQ™ è continuamente monitorato e aggiornato, e sfrutta i dati sulle vulnerabilità da NIST e altre fonti globali affidabili. Utilizza questi dati per visualizzare punteggi di rischio, livelli di criticità e altro. SBOM-HQ™ fornisce anche visibilità sui tipi di licenza per ciascun componente e libreria, riducendo il rischio di utilizzare inconsapevolmente una libreria che ha restrizioni eccessive quando sono disponibili opzioni meno rischiose. Il sistema offre il tracciamento delle versioni - la versione in uso, le versioni più recenti disponibili e la cronologia delle versioni - così come le date del ciclo di vita che supportano la gestione dell'obsolescenza. La libreria open source dedicata all'interno della libreria di dati sui prodotti IT-Pedia® di Eracent fornisce una solida base per l'analisi e la reportistica di SBOM-HQ™. Chi può beneficiare dell'uso di SBOM-HQ? SBOM-HQ è progettato per supportare tutti i team impegnati nell'uso e nell'operazione del software. DevOps – SBOM-HQ si integra nel CI/CD per generare e arricchire gli SBOM con dati di rischio in tempo reale, garantendo rilasci sicuri e conformi. Procurement – SBOM-HQ fornisce ai team di approvvigionamento intuizioni guidate dagli SBOM sulla qualità del software e sui rischi di licenza, consentendo una selezione più intelligente dei fornitori e acquisti di software più sicuri. Team CyberSec – SBOM-HQ valuta gli aspetti di sicurezza informatica del software acquistato e monitora le nuove vulnerabilità che appaiono. ITOps – SBOM-HQ espone le debolezze del software e aiuta a mitigare i rischi. Team Legali e di Licenza – SBOM-HQ offre una chiara visibilità sulle licenze open source, segnala i conflitti in anticipo e fornisce report di conformità pronti per l'audit. Perché SBOM-HQ? SBOM-HQ è progettato per supportare gli acquirenti e gli utenti di software, non solo gli editori di software. Mentre la maggior parte delle soluzioni SBOM si ferma al ciclo di vita dello sviluppo software, SBOM-HQ va oltre. Consente ai consumatori di software di monitorare continuamente non solo ciò che costruiscono, ma anche ciò che acquistano - dalla progettazione e approvvigionamento, attraverso l'integrazione, fino alla produzione nei propri data center. Con SBOM-HQ, la trasparenza si estende oltre lo sviluppo, offrendo visibilità e controllo su tutta la catena di fornitura del software. Per saperne di più su SBOM-HQ™, registrati per una prova gratuita su sbomhq.com o contatta Eracent oggi stesso!

#### Who Is the Company Behind Eracent SBOM-HQ?

- **Venditore:** [Eracent](https://www.g2.com/it/sellers/eracent)
- **Anno di Fondazione:** 2000
- **Sede centrale:** Riegelsville, Pennsylvania
- **Twitter:** @eracent  
141 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=061a86884957635bea8a86590cc6a3e69ada768cfe44044151ae7d03f750a122&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F15155&secure%5Burl_type%5D=linkedin_company_website)  
69 dipendenti su LinkedIn®

### [FOSSA](https://www.g2.com/it/products/fossa/reviews)

L'open source è una parte fondamentale del tuo software. Nel prodotto software moderno medio, oltre l'80% del codice sorgente distribuito è derivato dall'open source. Ogni componente può avere implicazioni legali, di sicurezza e di qualità a cascata per i tuoi clienti, rendendolo una delle cose più importanti da gestire correttamente. FOSSA ti aiuta a gestire i tuoi componenti open source. Ci integriamo nel tuo flusso di lavoro di sviluppo per aiutare il tuo team a tracciare, gestire e risolvere automaticamente i problemi con l'open source che utilizzi per: - Rimanere conforme alle licenze software e generare i documenti di attribuzione richiesti - Applicare politiche di utilizzo e licenza durante tutto il tuo flusso di lavoro CI/CD - Monitorare e risolvere le vulnerabilità di sicurezza - Segnalare proattivamente problemi di qualità del codice e componenti obsoleti Abilitando l'open source, aiutiamo i team di sviluppo ad aumentare la velocità di sviluppo e a ridurre il rischio.

**Average Rating:** 4.2/5.0

**Total Reviews:** 15

#### Who Is the Company Behind FOSSA?

- **Venditore:** [FOSSA](https://www.g2.com/it/sellers/fossa)
- **Anno di Fondazione:** 2015
- **Sede centrale:** San Francisco, California
- **Twitter:** @getfossa  
774 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=00194647467978e04baaa89e8e6cbe7c0e0a4d673296571deb5ed1510ffbe675&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ffossa%2F&secure%5Burl_type%5D=linkedin_company_website)  
59 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Software per computer
- **Company Size:** 47% Small, 33% Medium

#### What Do G2 Reviewers Say About FOSSA?

_AI-generated summary from verified user reviews_

##### Pros

- Gli utenti apprezzano le **facili integrazioni** di FOSSA, che funzionano senza problemi con Maven e Gardle nei loro pipeline.
- Gli utenti beneficiano della **risoluzione efficace dei problemi** di Fossa, identificando le vulnerabilità e raccomandando soluzioni per le dipendenze delle librerie.
- Gli utenti apprezzano le **soluzioni di rimedio efficaci** di FOSSA, che identificano e suggeriscono correzioni per le vulnerabilità nelle applicazioni.
- Gli utenti apprezzano FOSSA per la sua **gestione efficace del rischio** , identificando rapidamente i problemi delle librerie e raccomandando soluzioni.
- Gli utenti apprezzano le **analisi di sicurezza** di FOSSA che identificano le vulnerabilità e raccomandano soluzioni per le loro applicazioni.

#### What Are Recent G2 Reviews of FOSSA?

**["Fossa per applicazioni aziendali"](https://www.g2.com/it/survey_responses/fossa-review-10931000)**

**Rating:** 4.0/5.0 stars

_— Pavan Kumar G._

[Read full review](https://www.g2.com/it/survey_responses/fossa-review-10931000)

**[""L'Esperienza FOSSA""](https://www.g2.com/it/survey_responses/fossa-review-8576931)**

**Rating:** 5.0/5.0 stars

_— Elvis M._

[Read full review](https://www.g2.com/it/survey_responses/fossa-review-8576931)

### [Heeler](https://www.g2.com/it/products/heeler/reviews)

Heeler consente ai team di sicurezza delle applicazioni di "shift left" con il contesto di cui hanno bisogno per ridurre il rumore, accelerare la remediation e andare oltre la gestione tradizionale delle vulnerabilità. Combinando ASPM, SCA con contesto statico e runtime, e modellazione delle minacce in tempo reale, Heeler trasforma i programmi AppSec da reattivi a proattivi e scalabili. Come Heeler Aiuta i Team AppSec • Ridurre il Rumore: I team AppSec e gli sviluppatori sono sommersi dai risultati. Heeler fornisce un contesto unificato di codice, runtime, business e sicurezza, riducendo il rumore degli avvisi fino al 95%, in modo che i team possano concentrarsi su questioni critiche e risolvere ciò che conta di più. • Correggere la Remediation: La remediation è rotta. La maggior parte dello sforzo è speso per raggiungere una soluzione, non per implementarla. Heeler automatizza il ciclo di vita della remediation, riducendo sforzo e tempo, permettendo ai team AppSec di scalare insieme all'ingegneria. • Andare Oltre le Vulnerabilità: Con Heeler, la modellazione continua delle minacce in tempo reale diventa realtà. Scomporre le applicazioni in esecuzione, tracciare i cambiamenti, confrontare i deployment e fermare i rischi in tempo reale, tutto prima che raggiungano la produzione. Perché Heeler è Essenziale Le applicazioni moderne sono più complesse e dinamiche che mai, espandendo le superfici di attacco e rendendo quasi impossibile la modellazione della sicurezza end-to-end senza gli strumenti giusti. Heeler colma questa lacuna, affrontando le cause principali dei programmi AppSec non scalabili: • Mancanza di Contesto: I silos di dati disparati rendono difficile comprendere il comportamento delle applicazioni e identificare i rischi. • Processi Laboriosi: Senza un contesto unificato, gli sforzi di sicurezza sono manuali, non scalabili e spingono l'identificazione dei rischi troppo a destra. • Modalità di Spegnimento Incendi: I team di sicurezza e ingegneria sono intrappolati nell'affrontare troppi risultati e spesso concentrano il loro tempo sulle minacce sbagliate, lasciando nessuna capacità per iniziative "secure-by-design". Capacità Chiave • ProductDNA (Contesto Unificato): Automatizza un catalogo di servizi in tempo reale, mappando i cambiamenti ai deployment e modellando ogni servizio con contesto integrato di codice, runtime, business e sicurezza. • Modellazione delle Minacce in Tempo Reale: Consente la modellazione continua delle minacce con strumenti per scomporre le applicazioni, tracciare i cambiamenti, confrontare i deployment e scoprire i rischi in tempo reale. • ASPM: Heeler riduce il rumore degli avvisi fino al 95% e automatizza i flussi di lavoro di remediation, scalando la sicurezza senza problemi con le esigenze ingegneristiche. • SCA con Contesto Statico e Runtime: Combina dati statici e runtime con contesto di business e deployment, fornendo una SCA di nuova generazione che dà priorità a ciò che conta, rafforza la sicurezza e semplifica i flussi di lavoro AppSec. Heeler garantisce che i team AppSec e gli sviluppatori abbiano il contesto di cui hanno bisogno per "shift left" e costruire applicazioni "secure-by-design"—senza sforzo.

#### Who Is the Company Behind Heeler?

- **Venditore:** [Heeler Security](https://www.g2.com/it/sellers/heeler-security)
- **Anno di Fondazione:** 2023
- **Sede centrale:** N/A
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a1a68756cf4887b6fb99c645e3d205020401407b871bdb78a3753c9ca3752015&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fheeler-security&secure%5Burl_type%5D=linkedin_company_website)  
20 dipendenti su LinkedIn®

### [Hilt](https://www.g2.com/products/hilt/reviews)

Hilt monitors how data actually moves across your environment, not just whether policies are followed. Using proprietary eBPF kernel probes, Hilt captures every data movement event at the base level across cloud workloads, endpoints, and network boundaries. A three-tier behavioral detection engine (deterministic rules, behavioral ML, and model inference) identifies anomalous data movement in real time including transfers where permissions were valid and no policy was violated, but the behavior was wrong. Automated containment blocks exfiltration in under one second. Deployed in minutes with one command, no code changes, and no SDK. Built for latency-sensitive environments including financial services, hedge funds, and law firms.

#### Who Is the Company Behind Hilt?

- **Seller:** [Hilt AI](https://www.g2.com/sellers/hilt-ai)
- **HQ Location:** Milton Keynes, GB
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8c5ec45d8068b9366441dc4d2be35aa75125f947ca7e31ff2ce02f5c0122cecc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fhilt-ai%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [MergeBase](https://www.g2.com/it/products/mergebase/reviews)

MergeBase sta rivoluzionando la protezione della catena di fornitura del software con una soluzione SCA completa e orientata agli sviluppatori che offre il minor numero di falsi positivi nel settore e una copertura DevOps completa, dalla codifica/costruzione al deployment e al run-time. Lo strumento SCA di MergeBase analizza le librerie open-source/di terze parti per le vulnerabilità. La nostra missione è proteggere la catena di fornitura del software. Forniamo una soluzione completa e orientata agli sviluppatori che ha i tassi di falsi positivi più bassi del settore e una copertura completa del processo DevOps.

**Average Rating:** 4.5/5.0

**Total Reviews:** 20

#### Who Is the Company Behind MergeBase?

- **Venditore:** [MergeBase Software](https://www.g2.com/it/sellers/mergebase-software)
- **Anno di Fondazione:** 2018
- **Sede centrale:** Coquitlam, British Columbia
- **Twitter:** @mergebasesecure  
86 follower su Twitter
- **Pagina LinkedIn®:** [www.linkedin.com](https://www.g2.com/it/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=69ee19fad389ad4f98212a51bf0a5efb0b41c459dc4f4e8ece60f23d0d5ab74b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmergebase%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 dipendenti su LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Software per computer
- **Company Size:** 40% Small, 35% Medium

#### What Are Recent G2 Reviews of MergeBase?

**["Rilevatore di rischi e vulnerabilità MergeBase"](https://www.g2.com/it/survey_responses/mergebase-review-7833957)**

**Rating:** 4.5/5.0 stars

_— Prashant S._

[Read full review](https://www.g2.com/it/survey_responses/mergebase-review-7833957)

**["Rivoluzionare la protezione della catena di fornitura del software con la piattaforma SCA di MergeBase"](https://www.g2.com/it/survey_responses/mergebase-review-7670163)**

**Rating:** 5.0/5.0 stars

_— Disha K._

[Read full review](https://www.g2.com/it/survey_responses/mergebase-review-7670163)

### [Qwiet AI](https://www.g2.com/products/qwiet-ai/reviews)

Qwiet AI delivers comprehensive application security by combining agentic AI with advanced code analysis. In a single scan, the platform provides uniquely accurate SAST, SCA, SBOM, secrets detection, and container analysis that helps dev and security teams find and fix vulnerabilities faster. With its proprietary Code Property Graph (CPG) technology and AI/ML models, Qwiet AI achieves up to 95% reduction in false positives compared to traditional tools, while offering contextual AutoFix that understands the unique context of your code, even across complex enterprise applications. Q: What makes Qwiet AI different from other AppSec solutions? A: Qwiet AI stands out through its agentic AI approach, which enables autonomous vulnerability detection and remediation. The platform's Code Property Graph technology allows for deeper code analysis and more accurate vulnerability detection, resulting in dramatically fewer false positives than traditional tools. This advanced technology enables the platform to understand code relationships and context at a deeper level, leading to precise vuln detection and contextually appropriate fixes. Q: What security capabilities does the platform include? A: The platform provides comprehensive security coverage including: - Static Application Security Testing (SAST) using a patented CPG-based approach, for vuln detection that is objectively the fastest and most accurate available per the OWASP benchmark - Software Composition Analysis (SCA) for third-party dependency scanning and vulnerability detection in open source components - Automated SBOM generation for supply chain transparency and compliance requirements - Advanced secrets detection to prevent credential exposure and secure sensitive information - Container security analysis built in - AI-powered AutoFix for automated vulnerability remediation with contextually aware patches, powered by the CPG and a custom AI/ML engine with its own LLM - Custom rule creation capabilities for organization-specific security requirements Q: How does Qwiet AI improve development workflows? A: Qwiet AI integrates seamlessly into existing CI/CD pipelines and developer workflows. The platform's speed (up to 40x faster than traditional scanners) and accuracy mean developers spend less time investigating false positives and more time coding. The AutoFix capability helps developers resolve issues quickly with AI-generated patches that are contextually aware and tailored to your codebase. Additionally, the platform provides IDE integrations and pull request analysis to catch vulnerabilities early in the development process. Q: What do customers think? A: Qwiet AI provides enterprise-grade support with dedicated customer success representatives and technical account managers. The platform consistently receives high marks for customer support, with a 97% "would recommend" rate in Gartner's Voice of the Customer. Customers receive comprehensive onboarding assistance, ongoing technical support, and regular check-ins to ensure successful implementation and adoption. Q: How can I get started with Qwiet AI? A: Qwiet AI offers self-service access, self-guided demos, and AE-guided demos, depending on your needs. You can request a personalized demo through the company website at qwiet.ai to see how the platform addresses their specific security challenges. You can also sign up for self-service access through the web site, or access documentation and integration guides there.

**Average Rating:** 4.8/5.0

**Total Reviews:** 3

#### Who Is the Company Behind Qwiet AI?

- **Seller:** [Qwiet AI](https://www.g2.com/sellers/qwiet-ai)
- **HQ Location:** San Jose, California, United States
- **Twitter:** @ShiftLeftInc  
1,164 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=dbca0b84e2c33a23f09717f495d5c8693d9858bba84b3152d5262dae9d5bc5e0&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fqwiet&secure%5Burl_type%5D=linkedin_company_website)  
45 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Large, 33% Small

#### What Do G2 Reviewers Say About Qwiet AI?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **responsive and collaborative support** from Qwiet AI, enhancing integration into their CI/CD pipelines.
- Users value the **highly responsive customer support** of Qwiet AI, which facilitates seamless integration processes.
- Users value the **easy integrations** of Qwiet AI, appreciating its thorough documentation for seamless CI/CD pipeline incorporation.
- Users value the **comprehensive documentation** from Qwiet AI, facilitating seamless integration into CI/CD pipelines.
- Users value the **effective team collaboration** fostered by Qwiet AI’s responsive support and thorough integration documentation.

##### Cons

- Users find the lack of a graphical interface for policies frustrating, relying solely on the **command line interface**.
- Users find the **limited customization options** frustrating, as policy creation relies solely on the CLI without a user interface.
- Users find the **limited features** of Qwiet AI frustrating, lacking a user-friendly interface for policy creation.
- Users find the lack of a user interface for creating policies a significant **UX improvement** concern for Qwiet AI.

#### What Are Recent G2 Reviews of Qwiet AI?

**["Seamless Integration with Responsive Support"](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)**

**Rating:** 5.0/5.0 stars

_— Brooks S._

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)

**["A great easy-to-use SAST Scanner"](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)**

**Rating:** 5.0/5.0 stars

_— Verified User in Retail_

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)

### [rezilion](https://www.g2.com/products/rezilion/reviews)

Rezilion's software attack surface management platform automatically secures the software you deliver to customers, giving teams time back to build. Rezilion works across your stack, helping you to know what software is in your environment, what is vulnerable, and what is actually exploitable, so you can focus on what matters and remediate automatically. KEY FEATURES: - Dynamic SBOM Create an instant inventory of all the software components in your environment - Vulnerability Validation Know which of your software vulnerabilities are exploitable, and which are not, through runtime analysis - Vulnerability Remediation Cluster vulnerabilities to eliminate multiple problems at once and automatically execute remediation work to save teams time. WITH REZILION, ACHIEVE: - 85% reduction in patching work after filtering out unexplainable vulnerabilities - 24/7 Continuous monitoring of your software attack surface -600% Faster time to remediate when you focus on what matters and patch automatically - 360-degree visibility across your entire DevSecOps stack -- not just in silos

**Average Rating:** 4.4/5.0

**Total Reviews:** 11

#### Who Is the Company Behind rezilion?

- **Seller:** [rezilion](https://www.g2.com/sellers/rezilion)
- **Year Founded:** 2018
- **HQ Location:** Be'er Sheva, Israel
- **Twitter:** @rezilion\_  
198 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b8dfa9915fe9aa05122fd1eceb40d06bb86b4b13a0a47b85d93cfb44a4099477&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F18716043&secure%5Burl_type%5D=linkedin_company_website)  
5 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 45% Medium, 36% Large

#### What Are Recent G2 Reviews of rezilion?

**["Platform for Automated Software Supply Chain Security"](https://www.g2.com/survey_responses/rezilion-review-8137689)**

**Rating:** 4.0/5.0 stars

_— Dr. Rajesh V._

[Read full review](https://www.g2.com/survey_responses/rezilion-review-8137689)

**["A New Era of Software Supply Chain Security"](https://www.g2.com/survey_responses/rezilion-review-8402929)**

**Rating:** 5.0/5.0 stars

_— Jawahar A._

[Read full review](https://www.g2.com/survey_responses/rezilion-review-8402929)

### [SCANOSS](https://www.g2.com/products/scanoss/reviews)

SCANOSS is the industry-leading open source software intelligence provider, offering the largest database of open source information available. SCANOSS delivers cutting-edge tools and services that help businesses and developers detect, manage, and secure their open source components. By identifying license obligations, security vulnerabilities, and other risk concerns, SCANOSS ensures that organisations can harness the power of open source safely and securely throughout the development pipeline.

**Average Rating:** 4.3/5.0

**Total Reviews:** 2

#### Who Is the Company Behind SCANOSS?

- **Seller:** [SCANOSS](https://www.g2.com/sellers/scanoss)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e9ad0cb5bc7f8eadedb40833e1d3b44ede507c82f885c3670c1ad7ffe0761d1f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fscanoss&secure%5Burl_type%5D=linkedin_company_website)  
24 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of SCANOSS?

**["SCANOSS Open Source Inventorying Engine"](https://www.g2.com/survey_responses/scanoss-review-7288704)**

**Rating:** 4.5/5.0 stars

_— Joe H._

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7288704)

**["Great product with a valuable solution but the paid SaaS Tier might be a bit expensive for some"](https://www.g2.com/survey_responses/scanoss-review-7283528)**

**Rating:** 4.0/5.0 stars

_— Joe H._

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7283528)

- [&lsaquo; Prev‹ Prev](/categories/software-bill-of-materials-sbom?order=popular#product-list)
- [1](/categories/software-bill-of-materials-sbom?order=popular#product-list)
- 2
- [3](/categories/software-bill-of-materials-sbom?order=popular&page=3#product-list)
- [Next &rsaquo;Next ›](/categories/software-bill-of-materials-sbom?order=popular&page=3#product-list)

Spotlight Categories

[Anti Money Laundering Software](https://www.g2.com/categories/anti-money-laundering)

[Fleet Management Software](https://www.g2.com/categories/fleet-management)

[Third Party & Supplier Risk Management Software](https://www.g2.com/categories/third-party-supplier-risk-management)

[Retail POS Systems](https://www.g2.com/categories/retail-pos)

[Social Media Management Tools](https://www.g2.com/categories/social-media-mgmt)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Software Bill of Materials (SBOM) Themes](/categories/software-bill-of-materials-sbom/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Software bill of materials (SBOM) solutions generate, ingest, manage, and monitor a machine-readable inventory of the components within software supply chains. The components covered include libraries, packages, modules, associated licenses, and more. Companies and developers use SBOM software to deliver and annotate comprehensive SBOMs for their software’s third party and open source components .

These solutions allow users to comply with government mandates that require the provision of a minimum SBOM. Maintaining and monitoring SBOMs also helps companies perform continuous risk assessments, though vulnerability remediation is not the primary focus of such tools. [software composition analysis (SCA) tools](https://www.g2.com/categories/software-composition-analysis) scan software supply chains’ components and dependencies at the code level to identify and remediate security vulnerabilities, whereas SBOM software automates the standardized presentation of those elements for transparency, observability, and compliance.

To qualify for inclusion in the Software Bill of Materials (SBOM) category, a product must:

- Automatically ingest and generate SBOMs in standard formats like CycloneDX and SPDX
- Continuously monitor and update SBOMs based on component versions, associated licenses, dependencies, and more
- Alert users of non-compliant elements in their software supply chain
- Allow users to annotate SBOMs
- Facilitate compliance with government regulations

Show More