Vannus / Catalog / CycloneDX

CycloneDX

This entry runs no foundation model. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Software Bill of Materials (SBOM) standard and tooling — generates machine-readable dependency inventories ensuring every smuggled package in the supply chain is explicitly known and auditable

Security, open-source
Model provenance

No foundation model. CycloneDX does not run one, so this criterion does not apply and is excluded from the grade rather than counted against it. CycloneDX is an OWASP/Ecma International specification (ECMA-424) defining a bill-of-materials document format for software supply chain transparency. It is a data standard, not software, and invokes no foundation model. Established from the product’s own public documentation and what it does. If that is out of date, tell us at right of reply.

Who controls it

Not yet assessed. We publish a sovereignty position only where the vendor documents one — we do not infer it from a domain or a company name.

Compliance the vendor states
NTIA SBOMExecutive Order 14028

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit CycloneDX ↗ Grade your whole stack →