

lynkctl is Interlynk's SBOM generator for embedded and firmware software. It runs after your existing build, with no rebuild and no source instrumentation, and reads the actual compiler and linker invocations the build emits to produce an accurate bill of materials. It reconciles those inputs against the linker map, so it captures the firmware dependencies that manifest-based scanners miss: vendor SDKs, static archives, and source copied into a tree without a package manifest. lynkctl works with Make, CMake, IAR, and TI Code Composer projects, runs fully air-gapped with no network access, and outputs CycloneDX 1.6+ and SPDX 3+. It is built for regulated and safety-critical firmware teams that have to prove what actually shipped for FDA 524B, the EU CRA, and NIS2.

Interlynk's SBOM Automation & Compliance Platform is an enterprise platform for regulated software and devices. It generates SBOMs for everything a team ships, from embedded C/C++ firmware to cloud services, then handles what comes after generation: ingest and enrich existing SBOMs, monitor continuously for new vulnerabilities with VEX, manage supplier and open-source risk, and share audit-ready documents. Interlynk produces validated CycloneDX and SPDX output and works with the scanners and formats teams already run. It maps SBOM work directly to FDA 524B, the EU CRA, and NIS2, the part most generation-first tools leave to the customer.
Interlynk is the SBOM and software supply chain security platform for teams building products under FDA 524B, EU CRA, IEC 62304, PCI DSS 4.0, SEBI CSCRF, and DORA. We turn the evidence regulators ask for — SBOM, AIBOM, CBOM, VEX/VDR, and supporting documentation — into build output instead of paperwork, so compliance keeps pace with your release cycle. Medical device, energy, and AI teams use Interlynk to ship audit-ready evidence on every build. Our open-source SBOM tooling (sbomqs, sbomasm, sbomgr) is trusted by security teams and government agencies worldwide.