← Product
Product · 01 SBOM & Inventory

Know exactly what’s inside every release.

The CRA requires manufacturers to produce and maintain a software bill of materials. KONFORMA turns that into a self-service step: connect your code, get a release-specific inventory, and see how complete it is.

GitHub or manual import

Connect a repository to pull the inventory GitHub already generates, or upload a CycloneDX/SPDX file directly, your source code never leaves your environment.

Completeness, not just a component list

A readiness score tells you whether your inventory is actually complete enough to stand behind, not just how many packages were found.

One inventory per release

Firmware 2.4 and Firmware 2.5 of the same product can have different components. Each release keeps its own inventory instead of one inventory averaged across versions.

Deep matching for C/C++ and embedded

Beyond package-manager metadata, components are matched against a curated database so embedded and firmware components aren’t missed.

Frequently asked

Which formats are supported?+

CycloneDX and SPDX imports, plus direct GitHub connection which builds an inventory from your repository’s dependency data.

Does my source code leave my environment?+

No. On GitHub import, KONFORMA fetches the software inventory GitHub already generates, not your code.

Is this suitable for embedded and firmware products?+

Yes. Components are matched against a curated database built specifically to catch embedded and C/C++ libraries that package-manager metadata alone would miss.

Build your first inventory in minutes.