Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Stay compliant with regulations and ahead of industry trends. Manage your Software Bill of Materials (SBOM) effortlessly across your entire software portfolio.
## Secure Your Software Supply Chain: Manage Risk, Compliance, and Regulations
Show the rest of the publisher’s description (7 more lines)
With more than 90% of companies using open source software (OSS), protecting your software supply chain is critical to mitigating security, legal, and quality risks to your business. Make safer open source choices across the software development life cycle (SDLC), and innovate fearlessly with less risk.
We're bringing Sonatype's best-in-class component scanning and vulnerability data together with market-leading SBOM management support to provide procurement, regulations compliance, and security teams with the tools they need to manage SBOMs for their software and the SBOMs they receive for their third-party software.
Comprehensive SBOM management and compliance at scale enhances your overall security posture, enabling you to stay ahead of evolving cybersecurity threats:
- Generate, unify, and distribute accurate SBOMs (Software Bill of Materials) in CycloneDX and SPDX formats from a centralized platform.
- Streamline risk prioritization and compliance management, addressing security, audit, and regulatory requirements efficiently.
Get started today with Sonatype SBOM Manager!
As the industry-leading software supply chain management platform, the Sonatype Platform is the choice of organizations currently using or evaluating solutions such as Mend, Jfrog, Snyk, or GitLab. Sonatype provides a comprehensive and integrated solution for all aspects of the software development lifecycle, from secure development to release automation, helping organizations reduce risk and accelerate their time to market.
Highlights
Highlighted by the publisher on AWS Marketplace.
Simplify compliance, identify critical risks, and guide vendor negotiations with third party software audit through SBOM Managers smart and scalable database.
Meet regulation and compliance standards by sharing SBOMs at scale with automated VEX information and keep your customers and regulators up to date.
Automatically monitor first party and third party SBOMs for new security vulnerability and malware risks and respond quickly powered by Sonatypes industry leading component intelligence.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
1 listed- Units
Refund terms
As stated by the publisher on AWS Marketplace.
We do not offer a refund policy.
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

