bomkeeper.dev

Your SBOMs don't outlive your pipeline. Bomkeeper keeps them.

The evidence vault for software bills of materials: tamper-proof, signed and retained for ten years. In your own storage or as a managed service.

Join the waitlist View on GitHub

Supports the CRA's retention requirements. Complements OWASP Dependency-Track — doesn't replace it.

Evidence bundle Controller X200 · 3.2.1
SEALED
Placed on market2027-12-11
Retained until2037-12-11
FormatCycloneDX 1.6
StorageWORM, locked
sha256 9f2c…e41a
signature valid · RFC 3161 timestamp
Verifiable offline — even without Bomkeeper
Designed to fit your stack
CycloneDX SPDX Dependency-Track GitHub Actions Azure DevOps GitLab CI Amazon S3 Azure Blob Storage MinIO
The problem

CI pipelines are built to forget.

Generating SBOMs is solved. Keeping them isn't. Most teams create them as build artifacts — in a system designed to throw artifacts away.

Artifacts expire

CI systems delete build artifacts after days or weeks. The SBOM of last year's release is already gone.

No proof

A JSON file in a bucket proves nothing. Nobody can show it is unchanged and belongs to exactly what you shipped.

Slow answers

A customer, auditor or authority asks about a release from three years ago. The answer takes days — if it exists at all.

What the Cyber Resilience Act asks of manufacturers
  1. Sep 11, 2026 Reporting duties for actively exploited vulnerabilities, starting with a 24-hour early warning.
  2. Dec 11, 2027 Full application: a machine-readable SBOM is part of every product's technical documentation.
  3. +10 years Technical documentation must be kept for ten years after placing on the market, or the support period if longer.
Regulation (EU) 2024/2847. This is a summary, not legal advice.
How it works

One step in CI. Ten years of evidence.

Keep generating SBOMs with Syft, Trivy or cdxgen. Add Bomkeeper right after, and every release is archived the moment it ships.

.github/workflows/release.yml
$ bomkeeper push sbom.cdx.json \
    --product controller-x200 --release 3.2.1
✓ SHA-256 computed over original bytes
✓ Signed and timestamped (RFC 3161)
✓ Locked in WORM storage until 2037-12-11
→ verify anytime, offline: bomkeeper verify
  1. 01
    Push One step after your SBOM generator. Bomkeeper takes the file byte for byte, with product and release attached.
  2. 02
    Seal A SHA-256 hash over the original bytes, a signature and a trusted RFC 3161 timestamp.
  3. 03
    Retain Locked in WORM storage — S3 Object Lock or Azure immutable blobs — until the retention date. Nobody can change or delete it.
  4. 04
    Verify Anyone can check a bundle offline with the open-source verifier. In ten years, even without us.
10 yrs minimum retention for SBOMs under the CRA
0 delete endpoints. Not even for admins.
1 step in your pipeline
Bomkeeper + Dependency-Track

Dependency-Track for today. Bomkeeper for the record.

Dependency-Track analyses what you run now and retires old versions to stay fast. Bomkeeper keeps every version you ever shipped — and feeds Dependency-Track automatically.

Analysis OWASP Dependency-Track
  • —Continuous vulnerability and policy monitoring
  • —Focused on the current, active versions
  • —Retention cleans up inactive versions
forward on push
replay any release
Evidence Bomkeeper
  • ✓Every shipped release, for ten years and more
  • ✓Original bytes, sealed and locked
  • ✓Rebuild Dependency-Track from the archive anytime
Bomkeeper is an independent project and not affiliated with or endorsed by the OWASP Foundation.
Open core

Open where trust matters.

Everything you need to read and verify your evidence without us is open source. The comfort on top is what you pay for.

Open source Apache-2.0
  • ✓Evidence bundle format and specification
  • ✓CLI: push, get, verify
  • ✓Storage adapters for S3 Object Lock and Azure immutable blobs
  • ✓GitHub Action for your release workflow
Bomkeeper Server Commercial
  • +Products, versions and releases with market dates
  • +Search one component across every shipped release
  • +Dependency-Track forwarding and replay
  • +Time-limited audit shares with a tamper-proof access log

Exit guarantee: if Bomkeeper ever disappears, your evidence doesn't. Every bundle stays readable and verifiable with the open-source tools.

Self-host or cloud

Your storage or ours. Your evidence either way.

Run Bomkeeper in your own cloud account, or let us operate it — with the bundles in your bucket or in EU data centres.

Open source CLI and your own locked bucket
Free
  • Archive and verify from CI
  • S3 or Azure WORM storage
  • Community support on GitHub
Star on GitHub
Cloud Design partners wanted
We run it, you ship
/ month
  • Everything in Bomkeeper Server
  • Bring your own storage or EU-hosted
  • SSO, roles and audit shares
  • Full export, anytime
Join the waitlist
Self-hosted server In your Azure, AWS or Kubernetes
Annual license
  • Everything in Bomkeeper Server
  • Deployment templates for your cloud
  • Updates and support with SLA
Talk to us
Consulting

A vault is one part. Get help with the rest of the CRA.

Archiving SBOMs is only one obligation. Vulnerability handling, reporting, cloud and pipeline security belong to the same job.

FL
Florian Lenz Creator of Bomkeeper · Microsoft Azure MVP · independent cloud & security consultant from Cologne
Fixed-scope package CRA evidence in 5 days
  1. 1Inventory of your products, releases and build pipelines
  2. 2Bomkeeper set up in your own cloud account
  3. 3SBOM generation and archiving wired into CI
  4. 4Report with gaps, risks and next steps
Book a free intro call Technical and process support. It doesn't replace legal advice.
Early access

Be ready before December 2027.

The open-source core is planned for early 2027, a cloud beta with design partners for spring 2027. Join the list and help shape what gets built first.

We only use your email to contact you about Bomkeeper. Unsubscribe anytime. See our privacy policy.

Questions

Does Bomkeeper make us CRA compliant?

No tool can. Bomkeeper supports the CRA's retention requirements for SBOMs and technical documentation. Compliance also needs secure development, vulnerability handling and reporting processes.

We already use Dependency-Track. Why add Bomkeeper?

Dependency-Track is built for analysing the current state. Bomkeeper keeps the unchanged originals of every shipped release for ten years, proves they are untouched, and can replay them into Dependency-Track.

What happens if Bomkeeper shuts down?

The bundle format and the verifier are open source. Your evidence stays readable and verifiable without us — especially if it lives in your own storage.

Where is our data stored?

In your own S3 or Azure account with object lock enabled, or in EU data centres when you use the cloud service.

Which SBOM formats are supported?

CycloneDX and SPDX. Bomkeeper stores the file byte for byte, exactly as your generator produced it.