Generating SBOMs is solved. Keeping them isn't. Most teams create them as build artifacts — in a system designed to throw artifacts away.
Artifacts expire
CI systems delete build artifacts after days or weeks. The SBOM of last year's release is already gone.
No proof
A JSON file in a bucket proves nothing. Nobody can show it is unchanged and belongs to exactly what you shipped.
Slow answers
A customer, auditor or authority asks about a release from three years ago. The answer takes days — if it exists at all.
What the Cyber Resilience Act asks of manufacturers
Sep 11, 2026Reporting duties for actively exploited vulnerabilities, starting with a 24-hour early warning.
Dec 11, 2027Full application: a machine-readable SBOM is part of every product's technical documentation.
+10 yearsTechnical documentation must be kept for ten years after placing on the market, or the support period if longer.
Regulation (EU) 2024/2847. This is a summary, not legal advice.
How it works
One step in CI. Ten years of evidence.
Keep generating SBOMs with Syft, Trivy or cdxgen. Add Bomkeeper right after, and every release is archived the moment it ships.
.github/workflows/release.yml
$ bomkeeper push sbom.cdx.json \
--product controller-x200 --release 3.2.1
✓ SHA-256 computed over original bytes
✓ Signed and timestamped (RFC 3161)
✓ Locked in WORM storage until 2037-12-11
→ verify anytime, offline: bomkeeper verify
01
PushOne step after your SBOM generator. Bomkeeper takes the file byte for byte, with product and release attached.
02
SealA SHA-256 hash over the original bytes, a signature and a trusted RFC 3161 timestamp.
03
RetainLocked in WORM storage — S3 Object Lock or Azure immutable blobs — until the retention date. Nobody can change or delete it.
04
VerifyAnyone can check a bundle offline with the open-source verifier. In ten years, even without us.
10 yrsminimum retention for SBOMs under the CRA
0delete endpoints. Not even for admins.
1step in your pipeline
Bomkeeper + Dependency-Track
Dependency-Track for today. Bomkeeper for the record.
Dependency-Track analyses what you run now and retires old versions to stay fast. Bomkeeper keeps every version you ever shipped — and feeds Dependency-Track automatically.
AnalysisOWASP Dependency-Track
—Continuous vulnerability and policy monitoring
—Focused on the current, active versions
—Retention cleans up inactive versions
forward on push replay any release
EvidenceBomkeeper
✓Every shipped release, for ten years and more
✓Original bytes, sealed and locked
✓Rebuild Dependency-Track from the archive anytime
Bomkeeper is an independent project and not affiliated with or endorsed by the OWASP Foundation.
Open core
Open where trust matters.
Everything you need to read and verify your evidence without us is open source. The comfort on top is what you pay for.
Open sourceApache-2.0
✓Evidence bundle format and specification
✓CLI: push, get, verify
✓Storage adapters for S3 Object Lock and Azure immutable blobs
✓GitHub Action for your release workflow
Bomkeeper ServerCommercial
+Products, versions and releases with market dates
+Search one component across every shipped release
+Dependency-Track forwarding and replay
+Time-limited audit shares with a tamper-proof access log
Exit guarantee: if Bomkeeper ever disappears, your evidence doesn't. Every bundle stays readable and verifiable with the open-source tools.
Self-host or cloud
Your storage or ours. Your evidence either way.
Run Bomkeeper in your own cloud account, or let us operate it — with the bundles in your bucket or in EU data centres.
The open-source core is planned for early 2027, a cloud beta with design partners for spring 2027. Join the list and help shape what gets built first.
Questions
Does Bomkeeper make us CRA compliant?
No tool can. Bomkeeper supports the CRA's retention requirements for SBOMs and technical documentation. Compliance also needs secure development, vulnerability handling and reporting processes.
We already use Dependency-Track. Why add Bomkeeper?
Dependency-Track is built for analysing the current state. Bomkeeper keeps the unchanged originals of every shipped release for ten years, proves they are untouched, and can replay them into Dependency-Track.
What happens if Bomkeeper shuts down?
The bundle format and the verifier are open source. Your evidence stays readable and verifiable without us — especially if it lives in your own storage.
Where is our data stored?
In your own S3 or Azure account with object lock enabled, or in EU data centres when you use the cloud service.
Which SBOM formats are supported?
CycloneDX and SPDX. Bomkeeper stores the file byte for byte, exactly as your generator produced it.