Skip to content

Experimental prototype · 11 September 2026

One SBOM.What to investigate.

CRAFT reads a product’s software bill of materials and lists the components and vulnerabilities to verify.

  • CycloneDX
  • SPDX JSON
  • No account
  • File not stored

The problem

The first question still takes days.

In a manufacturer of 50 to 300 people, the software bill of materials lives in a spreadsheet, a build pipeline, and two engineers’ heads. When a library shows up in an alert, nobody can immediately say which shipped products embed it.

How it works

From file to table, in three steps.

01

Upload

A CycloneDX or SPDX JSON SBOM, without creating an account.

02

Analysis

Components are extracted, then matched against public vulnerabilities.

03

Understand

A table of items to investigate, with no verdict on your product.

Preview

What you see after upload

Counters and rows come from your file.

Preview of the results table structure.

your-sbom.json

CycloneDX or SPDX

Components
Identified vulnerabilities
Critical
To investigate
Preview of the results table structure.
ComponentVersionCVESeverityAction

Analysis

Analyze an SBOM

You will see the number of components, potentially applicable CVEs, their severity, and the action: investigate.

Drop a JSON SBOM

CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.

CycloneDX preferred. SPDX JSON accepted. 10 MB max. Public PURLs go to OSV; internal PURLs are not sent.

Who builds this

Built by one person.

Jean-Pierre

Founder of CRAFT · SkyZon

Engineering student, ESME Sudria

I am building CRAFT for SMEs that manufacture a digital product under their own brand: those that will have to prove what is inside, without a €60k consultancy or a scanner designed for a large account.

LinkedIn profile

Next

A file is not always enough.

If you do not have an SBOM yet, an eight-question diagnostic produces a PDF report. Otherwise, a written message is enough: no appointment required.