Skip to content

Hermes SBOM Risk Analyzer

Know which components in your software actually put you at risk.
Upload your CycloneDX (JSON) or SPDX (JSON) Software Bill of Materials below to isolate true operational threats:

πŸ›‘οΈ Zero-Server Sovereign Privacy Guarantee

Zero-Server Privacy Guarantee: Your software bill of materials and proprietary code manifests never leave your device. All parsing, vulnerability resolution, and attack path graph traversals run 100% client-side.

100% IN-BROWSER ZERO-KNOWLEDGE SBOM ENGINE

Hermes SBOM Risk Analyzer

Evaluate CycloneDX & SPDX manifests locally in your browser. Uncover real-world weaponization, MITRE attack paths, and certified safe target versions without transmitting a single byte to any server.

πŸ“‹

Drop your CycloneDX or SPDX JSON manifest here

or browse files from your computer (.json format supported)


πŸ” Why Legacy Scanners Fail and How Hermes Delivers

Section titled β€œπŸ” Why Legacy Scanners Fail and How Hermes Delivers”

Conventional software composition analysis (SCA) tools generate hundreds of alerts based purely on theoretical CVSS base scores. This creates alarm fatigue and burns critical engineering capacity. Hermes Codex correlates your inventory against:

  1. Active Exploitation (CISA KEV): Prioritizes vulnerabilities actively weaponized in the wild by ransomware and state-sponsored threat groups.
  2. First Exploit Prediction (EPSS): Measures real-time weaponization velocity and statistical likelihood of weaponization over 30 days.
  3. Attack Path Trajectories: Maps whether a vulnerable component is located on your perimeter, intermediate middleware, or secrets/backup layers.
  4. Hermes Threat Score (HTS): Synthesizes exposure, maturity, and blast radius into an authoritative operational risk rating.

Need an official audit deliverable for your board, compliance auditors, or enterprise clients?

Pack Audit SBOM & Supply-Chain

990 € HT

Comprehensive supply-chain risk evaluation covering up to 10 application repositories, perimeter-to-secrets attack graphs, and certified clean remediation target versions. Delivered with an official executive PDF dossier signed and stamped by Hermes Codex.

Order SBOM Audit Pack β†’

πŸ”’ Data Provenance & Verification ● VERIFIED ARTIFACT
Authoritative Source Hermes SBOM Analysis Engine & Software Intelligence Catalog
Harvested Date 2026-09-14
Certified Confidence High
Extraction Method Deterministic client-side parsing, CISA KEV correlation, and Attack Path modeling