Offer now: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Coming early Q4 2026

Trust Repository

Collect and share SBOMs, VEX and support dates for the Cyber Resilience Act.

Your suppliers send you their software bills of materials (SBOMs), vulnerability statements (VEX) and end-of-life dates, and you share your own with your customers. Trust Repository keeps each version, date and download on record.

Book a Demo
How it maps to the EU Cyber Resilience Act

EU-based company · EU-hosted · Software supply chain security since 2018.

The software transparency challenge

Your customers want to know what is in the software you ship, which vulnerabilities affect it and how long you support it. You need the same answers from the suppliers whose software you use. Many companies are both a supplier and a customer.

Every customer asks separately

Each one sends its own questionnaire about SBOMs, vulnerabilities and support dates.

Every supplier sends different files

SBOMs, advisories, VEX or a PDF, each in its own format and on its own schedule.

Email and spreadsheets keep no history

Nobody can say which version covered which release, or who read it.

Suppliers publish into their own space in Trust Repository, or you upload what they send. Every document is checked, versioned and kept with its release, and customers fetch the current version.

What the Cyber Resilience Act asks for

The EU Cyber Resilience Act (CRA) sets cybersecurity requirements for products with digital elements sold in the EU. They cover the components you source from suppliers as well as the code you write.

September 11, 2026

Manufacturers report actively exploited vulnerabilities and severe incidents.

December 11, 2027

The main obligations apply, including the software bill of materials.

Software bill of materials

Draw up an SBOM in a machine-readable format, covering at least the top-level dependencies.

In Trust RepositoryCollect SBOMs from your suppliers and publish your own, per release, in CycloneDX or SPDX.

Due diligence on third-party components

Exercise due diligence when you integrate components sourced from third parties.

In Trust RepositorySupplier SBOM, VEX and assessments per supplier and release, each SBOM checked against known advisories.

Vulnerability handling

Handle vulnerabilities throughout the product's lifecycle.

In Trust RepositoryFindings per release, and VEX statements that record whether each one affects the product.

Support period

Tell users how long the product receives security updates.

In Trust RepositoryEnd-of-support and end-of-security-fix dates per version range, published as ECMA-428 (Common Lifecycle Enumeration) documents.

Reporting

Report actively exploited vulnerabilities and severe incidents.

In Trust RepositoryA per-release record of components and findings, so you know which releases are affected.

Trust Repository for both suppliers and customers

Use it to collect documents from your suppliers, to share your own with your customers, or both.

Collect from your suppliers

Invite the companies that ship parts of your product or the software you use. They publish into their own space.

Supplier onboarding
Invite by email or by short code. The supplier signs up to its own space and sees only its own products and releases.
Automated or manual intake
Suppliers push SBOM, VEX and other transparency documents from their CI/CD pipeline over the REST API, or upload them in the browser.
Vulnerability checks
Every SBOM is checked against known advisories when it arrives, and again whenever it or its VEX changes. The advisory data updates hourly, and findings are deduplicated per release.
Documents that are not SBOMs
Add a supplier yourself and upload a PDF assessment or a signed statement. Replace it with a real SBOM later without losing the history.
The Suppliers list with the invite supplier action and subscribed products
The Suppliers list with the invite supplier action and subscribed products

Publish to your customers

Your customers and partners fetch the current documents themselves and subscribe to updates. When a regulator asks, you share from the same record.

Trust Portal
A branded portal for your products. Each release lists its SBOM, VEX, release notes and lifecycle dates for download.
You decide who sees what
Make a product public, limit it to signed-in organizations, or restrict it to named access groups such as customers under NDA.
Lifecycle events
End of life, end of support and end of security fixes per version range, published as ECMA-428 documents.
Publishing pipeline
Before a release goes out, build an aggregate SBOM for it, enrich the SBOM with vulnerability data and VEX, or redact it.
Public Trust Portal with product list, lifecycle events and downloadable artifacts
Public Trust Portal with product list, lifecycle events and downloadable artifacts

Upload from CI/CD or by hand

Push SBOM, VEX and other transparency documents from the same pipeline that builds the release. Suppliers without a pipeline upload in the browser, and both end up in the same record.

  • REST API for products, releases, files, VEX statements and lifecycle dates
  • Tokens scoped by permission, so uploading and publishing can be separate steps
  • Webhooks tell your other systems when something is published
release job in CI
# Upload the SBOM this build produced
curl -X POST "$API/component-releases/$ID/artifacts?type=SBOM&name=sbom.json" \
-H "Authorization: Bearer $UPLOAD_TOKEN" \
-H "Content-Type: application/json" \
--data-binary @sbom.json
 
# Publish with a token that holds catalog:publish
curl -X POST "$API/component-releases/$ID/publish" \
-H "Authorization: Bearer $PUBLISH_TOKEN"

Every release documented until end of life

Trust Repository normalizes, scopes and versions documents on the way in. Every change creates a new revision, and published revisions do not change after the fact. Each release keeps its own findings, VEX statements, downloads and lifecycle dates.

Product page with releases, their vulnerability and SBOM quality counts, and the next lifecycle date

Risk and quality on every release

Component count, SBOM quality issues, vulnerabilities and licenses per release.

Each SBOM is checked against the CISA minimum elements, BSI TR-03183-2 (the CRA guideline) and SPDX license rules. Missing producers, missing hashes and invalid license identifiers show up as quality issues on the release.

VEX analysis dialog with state, justification and response fields

Record which vulnerabilities affect your product

Use the standard VEX (Vulnerability Exploitability eXchange) format to record whether each vulnerability affects your product, and why. Publish it with the release, and add a new analysis whenever your assessment changes.

Dashboard with counts for products, releases, suppliers and subscribers plus visitor and download charts

What was published and who downloaded it

The dashboard shows products, releases, suppliers and subscribers, with portal visitors, active subscribers and downloads over time. Signed-in downloads are recorded per document.

The Activity feed lists what your suppliers have published, newest first: new products, new releases and each revision with its update reason.

Vulnerability page with severity, VEX status, EPSS, KEV listings, VEX history and EUVD data

Every vulnerability with its context

Severity, EPSS, CISA and EU KEV listings, and the EUVD and NVD records for each finding, next to the VEX history for the release.

Compatible with the Transparency Exchange API (ECMA-TC54) and lifecycle metadata (ECMA-428).

Frequently asked questions

Common questions from compliance, product security and supplier management teams.

How does Trust Repository help with the EU Cyber Resilience Act (CRA)?
It collects the software transparency information that CRA reporting depends on, including the timelines: SBOMs from your suppliers and your own per release, VEX statements, and end-of-life and end-of-support dates. When you report a vulnerability, you can see which releases contain the affected component. Reporting obligations have applied since September 11, 2026, and the main obligations apply from December 11, 2027.
Can Trust Repository help with audits and customer security questionnaires?
Yes. Each release keeps its documents, findings, VEX statements and lifecycle dates in one record. Every change creates a new revision, published revisions do not change after the fact, and signed-in downloads are recorded per document. When an auditor or a customer asks which components you ship and what you know about them, you answer from that record.
Which transparency documents can suppliers publish in Trust Repository?
SBOM in CycloneDX and SPDX, VEX, end-of-life and end-of-support lifecycle events, release notes and signatures. You can also upload PDF assessments or signed statements by hand for suppliers who have nothing machine-readable.
Do suppliers need access to our systems to share SBOMs?
No. A supplier signs up to its own space and sees only its own products and releases. It needs no access to your CI/CD or repositories, and it cannot see your other suppliers.
What happens to supplier documents if a supplier leaves Trust Repository?
Documents from a product you subscribe to are your data from the moment you subscribe. If the supplier later leaves the platform, you keep them.
Does Trust Repository check supplier SBOMs for vulnerabilities?
Yes. Every SBOM is checked against known advisories when it arrives, and again whenever it or its VEX changes. The advisory data updates hourly. Findings are deduplicated per release, and VEX statements record whether each one affects the product.
Can SBOM and VEX uploads be automated from CI/CD?
Yes. The REST API accepts SBOM, VEX and other transparency documents from any CI system with a scoped token. A token can be allowed to upload without being allowed to publish, and webhooks notify your other systems when something is published.
What if a supplier cannot provide an SBOM?
Add the supplier yourself and upload what you do have. A PDF assessment is stored as a dated record, and you can replace it with a real SBOM later without losing the history.
How does Trust Repository relate to SBOM Observer?
Trust Repository collects and shares the evidence, and does basic analysis on it: vulnerability checks and default policy checks. SBOM Observer adds impact analysis across internal and supplier software, and custom policies that it enforces continuously.
Which standards does Trust Repository support?
SBOM in CycloneDX and SPDX, VEX, and lifecycle metadata as ECMA-428. Trust Repository is compatible with the Transparency Exchange API (ECMA-TC54).
Where is Trust Repository hosted?
In the EU. Bitfront is an EU company. Single-tenant hosting is available with Enterprise agreements.

Bytesafe Platform

Software Supply Chain Security and Transparency

Three products that block risky packages at install, collect supplier transparency documents, and analyze them.

See Trust Repository

Book a 30-minute walkthrough: collecting from a supplier, publishing a release and what your customers see.

Book a Demo