# Best Software Bill of Materials (SBOM) Software - Page 2

## How Many Software Bill of Materials (SBOM) Software Products Does G2 Track?

**Total Products under this Category:** 33

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+1.29%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: August 01, 2026_

## How Does G2 Rank Software Bill of Materials (SBOM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 900+ Authentic Reviews
- 33+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

**Sponsored**

### LiveChat

LiveChat is a comprehensive customer communication platform that enables businesses to connect with their website visitors and customers in real-time, driving sales, delivering support, and enhancing customer satisfaction. Designed for ecommerce teams, the platform boosts AOV, upsell, and overall ROI by engaging shoppers at the right moment and converting more traffic into revenue. AI and advanced analytics surface sales opportunities, automate routine conversations, and give clear visibility into performance. All essential tools - including AI automation, analytics, a customizable chat widget, and agent apps - come together in one easy-to-deploy, no-code platform that delivers value quickly. ✅ Benefits • Higher conversions by capturing visitor attention at key moments through proactive, real-time engagement. • Lower operational overhead and greater agent productivity thanks to managing all communication channels in one unified workspace. • Better business decisions and clearer performance insights driven by transparent reporting on conversions, lead quality, and sales opportunities. • Faster responses and more time for high-value conversations enabled by AI that automates routine work and supports agents with smart assistance. • Stronger customer engagement and higher average order value through chat experiences tailored to your brand and optimized for upsell. 💬 Key features • Chat tools and widget: Real-time, two-way conversations with visitors, supported by file sharing, chat archives, automated greetings (like sneak-peek and inactivity prompts), seamless chat transfer, and post-chat ratings. • Multi-channel messaging: Manage all conversations from a single workspace - one license covers unlimited websites and apps, plus Facebook Messenger, WhatsApp Business, and email. • AI and automation: Leverage built-in AI features, including Copilot, reply suggestions, chat summaries, and insights extracted from high-volume conversations to boost efficiency and speed. • Analytics and reporting: Access intuitive dashboards that track agent performance, conversions, customer behavior, and more, with robust filtering and easy data export. • Customization and integrations: Tailor the widget’s appearance, language, and brand voice, and extend capabilities with 200+ integrations across CRMs, ecommerce platforms, help desks, and automation tools. • Easy implementation: Add LiveChat to your site with a simple code snippet-no heavy development or complex setup required. • Security and support: Benefit from enterprise-grade security, reliable infrastructure, and 24/7/365 customer support to keep your communication running flawlessly. 🌎 Trusted by teams worldwide to drive growth Thousands of companies worldwide utilize LiveChat to deliver fast and personalized customer interactions. Over 40% of customers prefer brands that offer live chat, and businesses that consistently use it see higher conversion rates and stronger engagement. LiveChat helps teams work more efficiently, improve satisfaction, and drive measurable growth. Adding specific customer results - like increases in conversions or agent productivity - can further highlight its impact. About Us LiveChat was created by Text S.A., a global software company headquartered in Wrocław, Poland. For over two decades, we’ve been dedicated to building tools that help businesses communicate better with their customers. LiveChat serves companies in more than 150 countries - from growing ecommerce stores to established B2B SaaS organizations - empowering them to deliver fast, personal, and effective customer service.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1008169&secure%5Bchosen_at%5D=2026-08-02T05%3A02%3A25Z&secure%5Bdisplayable_resource_id%5D=191&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=1856&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1856&secure%5Bresource_id%5D=1008169&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-bill-of-materials-sbom%3Fpage%3D2&secure%5Btoken%5D=8276594e5c159342c7eabe239290946abd694d7b3dce3c128017383b44930632&secure%5Burl%5D=https%3A%2F%2Fwww.livechat.com%2F&secure%5Burl_type%5D=free_trial)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube Makes Code Quality Clear with Strong Quality Gates and CI/CD Integration"](https://www.g2.com/survey_responses/sonarqube-review-13142666)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13142666)

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

### [Xygeni](https://www.g2.com/products/xygeni/reviews)

Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage security risks while minimizing noise and overwhelming alerts. Our innovative technologies automatically detect malicious code in real-time upon new and updated components publication, immediately notifying customers and quarantining affected components to prevent potential breaches. With extensive coverage spanning the entire Software Supply Chain—including Open Source components, CI/CD processes and infrastructure, Anomaly detection, Secret leakage, Infrastructure as Code (IaC), and Container security—Xygeni ensures robust protection for your software applications. Trust Xygeni to protect your operations and empower your team to build and deliver with integrity and security.

**Average Rating:** 4.6/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Xygeni?

- **Seller:** [Xygeni Security](https://www.g2.com/sellers/xygeni-security)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **Twitter:** @xygeni  
178 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0302db05d62f71019af9c96a9c2a81cfa4c370ac1ddef2c863b931a5bb7be15a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fxygeni%2F&secure%5Burl_type%5D=linkedin_company_website)  
30 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 60% Small, 40% Medium

#### What Do G2 Reviewers Say About Xygeni?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Xygeni for its **comprehensive security features** , enhancing protection while maintaining efficient software development processes.
- Users value the **contextual risk prioritization** of Xygeni, enabling focus on the most critical security issues efficiently.
- Users value the **effective risk management** of Xygeni, ensuring security without hindering development speed.
- Users praise the **robust security features** of Xygeni, ensuring efficient vulnerability management and compliance throughout development.
- Users value the **seamless CI/CD integration** of Xygeni, enhancing security without hindering development speed.

##### Cons

- Users experience **difficult setup** with Xygeni due to manual adjustments needed for specific CI/CD configurations.
- Users find the **learning curve for first-time users** challenging, needing familiarity with AppSec best practices for deeper insights.

#### What Are Recent G2 Reviews of Xygeni?

**["The essential tool for proactive security and confident development"](https://www.g2.com/survey_responses/xygeni-review-11393516)**

**Rating:** 4.5/5.0 stars

_— Marcos C._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11393516)

**["Revolutionized Our Security Workflow with Unified, AI-Driven Efficiency"](https://www.g2.com/survey_responses/xygeni-review-11998435)**

**Rating:** 5.0/5.0 stars

_— Yerassyl K._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11998435)

### [BINARLY](https://www.g2.com/products/binarly/reviews)

Binarly is an AI-powered platform dedicated to protecting devices from emerging firmware and hardware threats. Founded in 2021 and headquartered in Pasadena, California, Binarly leverages advanced machine learning and deep code inspection at the binary level to provide comprehensive visibility into hardware and firmware vulnerabilities. This approach enables security teams to detect and respond to sophisticated attacks below the operating system, ensuring robust protection for enterprise device infrastructures.

#### Who Is the Company Behind BINARLY?

- **Seller:** [BINARLY](https://www.g2.com/sellers/binarly)
- **Year Founded:** 2021
- **HQ Location:** Santa Monica, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=39af51e1893105779ac55a8fa419bb924356c7fc07f03cac45d384721ed5de9b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbinarlyinc&secure%5Burl_type%5D=linkedin_company_website)  
48 employees on LinkedIn®

### [CAST SBOM Manager](https://www.g2.com/products/cast-sbom-manager/reviews)

CAST SBOM Manager enables users to automatically create, customize, and maintain Software Bill of Materials (SBOMs) with the ultimate level of control and flexibility. It detects open source dependencies and related risks (vulnerabilities and security advisories, licenses, obsolescence) directly from scanning source code, and allows you to create and maintain SBOM metadata over time (proprietary components, custom licenses, vulnerabilities) and much more.

#### Who Is the Company Behind CAST SBOM Manager?

- **Seller:** [CAST](https://www.g2.com/sellers/cast)
- **Year Founded:** 1990
- **HQ Location:** New York
- **Twitter:** @SW\_Intelligence  
1,887 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 employees on LinkedIn®
- **Ownership:** Bridgepoint

### [CBOM Secure](https://www.g2.com/products/cbom-secure/reviews)

CBOM Secure is a machine-readable Cryptographic Bill of Materials (CBOM) platform that delivers continuous visibility and control over cryptography across source code, binaries, containers, and runtime environments. It automatically discovers and inventories algorithms, keys, certificates, protocols, and libraries, creating a centralized, normalized system of record. By mapping cryptographic assets to real execution paths, CBOM helps organizations distinguish dormant components from active usage, prioritize risk, and accelerate incident response. The platform supports compliance with standards such as NIST, FIPS 140-3, CMMC 2.0, and ISO 27001 while identifying legacy and quantum-vulnerable cryptography to enable structured post-quantum migration. Available on-premises, in the cloud, SaaS, or hybrid, CBOM transforms undocumented cryptography into a governed, audit-ready security control.

#### Who Is the Company Behind CBOM Secure?

- **Seller:** [Encryption Consulting](https://www.g2.com/sellers/encryption-consulting)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1d654ade21ce2eb9ddbaad24f7ea185be39146c33ee0a0785f0245a9416b8338&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fencryptionconsulting%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [Enso Security](https://www.g2.com/products/enso-security/reviews)

Enso Application Security Posture is a platform for AppSec teams to manage their day-to-day work, implement their security strategy into an AppSec organizational program, enforce it and automate it. And all of that in a scalable rapidly changing environment. AppSec teams struggle with prioritization - they may have a vision and concept of how to handle AppSec, but they don’t know where to invest and what actions to take. To keep up with R&D velocity and scale, Enso provides full visibility on the application inventory, focuses the AppSec teams on the most important tasks and insights, and takes a policy-based “call to action” approach so that the AppSec professionals won’t waste their time looking for application changes, prioritizing, or doing manual work.

#### Who Is the Company Behind Enso Security?

- **Seller:** [Enso Security](https://www.g2.com/sellers/enso-security)
- **HQ Location:** Boston, Massachusetts, United States
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=45fc4b87f2801662fd8218d907d0fb3e5470d80ca99df2f38b47aa42e4a8c865&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fenso-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,331 employees on LinkedIn®

### [Eracent SBOM-HQ](https://www.g2.com/products/eracent-sbom-hq/reviews)

SBOM-HQ™ - from Eracent SBOM-HQ™ provides a well-rounded set of data, reporting and analysis features that help organizations minimize risks and comply with cyber mandates and directives. While SBOM-HQ™ provides value to in-house and commercial application development teams, it is also unique in its approach to meeting the requirements of organizations that purchase or subscribe to software from numerous publishers. These “software consumers” will have to manage dozens, hundreds, or even thousands of SBOMs for products that they use, and this is impractical or impossible to do one SBOM at a time. SBOM-HQ™ is based around a centralized, single-source repository of libraries, components, and other related data from SBOMs. It dramatically reduces response time when a vulnerability is reported since it eliminates the need to review SBOMs individually. How does SBOM-HQ™ work? Customers upload their SBOM files via the user interface. During this straightforward process, users can assign related information that can be used to support reporting, filters, data access, and more. This information includes Publisher, Line of Business, Application Component, and more. SBOM-HQ™ “deconstructs” each uploaded SBOM and records the software product to which the SBOM belongs and all the SBOM’s content. This results in an index of components and libraries mapped to products. If a vulnerability is reported by NIST or another organization, customers get an immediate report of every product in use in their organization that includes the affected component or library. SBOM-HQ™ is continuously monitored and updated, and it leverages vulnerability data from NIST and other trusted global sources. It uses this data to display risk scores, levels of criticality, and more. SBOM-HQ™ also provides visibility into license types for each component and library, reducing the risk of unknowingly using a library that has excessive restrictions when less risky options are available. The system offers version tracking – the version in use, newer available versions, and version history – as well as lifecycle dates that support obsolescence management. The dedicated open source library within Eracent’s IT-Pedia® product data library provides a solid foundation for SBOM-HQ™’s analysis and reporting. Who can benefit from using SBOM-HQ? SBOM-HQ is designed to support all teams engaged in the use and operation of software. DevOps – SBOM-HQ integrates into CI/CD to generate and enrich SBOMs with real time risk data, ensuring secure and compliant releases. Procurement – SBOM-HQ equips procurement teams with SBOM-driven insights into software quality and licensing risks, enabling smarter vendor selection and safer software purchases. CyberSec teams – SBOM-HQ evaluates cyber security aspects of purchased software and monitors new vulnerabilities that appear. ITOps – SBOM-HQ exposes software weaknesses and helps mitigate the risks. Legal and Licensing teams – SBOM-HQ delivers clear visibility into open source licenses, flags conflicts early, and provides audit-ready compliance reports. Why SBOM-HQ? SBOM-HQ is designed to support software buyers and users, not just software publishers. While most SBOM solutions stop at the software development life cycle, SBOM-HQ goes further. It empowers software consumers to continuously monitor not only what they build, but also what they buy - from design and procurement, through integration, all the way to production in their own data centers. With SBOM-HQ, transparency extends beyond development, delivering visibility and control across the entire software supply chain. To learn more about SBOM-HQ™, register for a free trial at sbomhq.com or contact Eracent today!

#### Who Is the Company Behind Eracent SBOM-HQ?

- **Seller:** [Eracent](https://www.g2.com/sellers/eracent)
- **Year Founded:** 2000
- **HQ Location:** Riegelsville, Pennsylvania
- **Twitter:** @eracent  
141 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=061a86884957635bea8a86590cc6a3e69ada768cfe44044151ae7d03f750a122&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F15155&secure%5Burl_type%5D=linkedin_company_website)  
70 employees on LinkedIn®

### [FOSSA](https://www.g2.com/products/fossa/reviews)

Open source is a critical part of your software. In the average modern software product, over 80% of the source code shipped is derived from open source. Each component can have cascading legal, security, and quality implications for your customers, making it one of the most important things to manage correctly. FOSSA helps you manage your open source components. We plug into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use to: - Stay compliant with software licenses and generate required attribution documents - Enforce usage and licensing policies throughout your CI/CD workflow - Monitor and remediate security vulnerabilities - Flag code quality issues and outdated components proactively By enabling open source, we help development teams increase development velocity and decrease risk.

**Average Rating:** 4.2/5.0

**Total Reviews:** 15

#### Who Is the Company Behind FOSSA?

- **Seller:** [FOSSA](https://www.g2.com/sellers/fossa)
- **Year Founded:** 2015
- **HQ Location:** San Francisco, California
- **Twitter:** @getfossa  
774 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=00194647467978e04baaa89e8e6cbe7c0e0a4d673296571deb5ed1510ffbe675&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ffossa%2F&secure%5Burl_type%5D=linkedin_company_website)  
59 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 47% Small, 33% Medium

#### What Do G2 Reviewers Say About FOSSA?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **easy integrations** of FOSSA, seamlessly working with Maven and Gardle in their pipelines.
- Users benefit from Fossa's **effective issue resolution** , identifying vulnerabilities and recommending fixes for library dependencies.
- Users value the **effective remediation solutions** of FOSSA, which identify and suggest fixes for vulnerabilities in applications.
- Users value FOSSA for its **effective risk management** , identifying library issues and recommending fixes swiftly.
- Users value FOSSA's **security insights** that identify vulnerabilities and recommend fixes for their applications.

#### What Are Recent G2 Reviews of FOSSA?

**["Fossa for enterprise applications"](https://www.g2.com/survey_responses/fossa-review-10931000)**

**Rating:** 4.0/5.0 stars

_— Pavan Kumar G._

[Read full review](https://www.g2.com/survey_responses/fossa-review-10931000)

**[""The FOSSA Experience""](https://www.g2.com/survey_responses/fossa-review-8576931)**

**Rating:** 5.0/5.0 stars

_— Elvis M._

[Read full review](https://www.g2.com/survey_responses/fossa-review-8576931)

### [Heeler](https://www.g2.com/products/heeler/reviews)

Heeler empowers application security teams to shift left with the context they need to reduce noise, accelerate remediation, and move beyond traditional vulnerability management. By combining ASPM, SCA with static and runtime context, and runtime threat modeling, Heeler transforms AppSec programs from reactive firefighting to proactive, scalable security. How Heeler Helps AppSec Teams • Reduce Noise: AppSec teams and developers are drowning in findings. Heeler delivers unified code, runtime, business and security context, reducing alert noise by up to 95%, so teams can focus on critical issues and fix what matters most. • Fix Remediation: Remediation is broken. Most effort is spent reaching a fix—not implementing it. Heeler automates the remediation lifecycle, cutting effort and time, enabling AppSec teams to scale alongside engineering. • Move Beyond Vulnerabilities: With Heeler, continuous runtime threat modeling becomes a reality. Decompose running applications, track changes, compare deployments, and stop risks in real time—all before they reach production. Why Heeler is Essential Modern applications are more complex and dynamic than ever, expanding attack surfaces and making end-to-end security modeling nearly impossible without the right tools. Heeler bridges this gap, addressing the root causes of unscalable AppSec programs: • Lack of Context: Disparate data silos make understanding application behavior and identifying risks challenging. • Labor-Intensive Processes: Without unified context, security efforts are manual, unscalable, and push risk identification too far right. • Firefighting Mode: Security and engineering teams are trapped addressing too many findings and often focus their time on the wrong threats, leaving no bandwidth for secure-by-design initiatives. Key Capabilities • ProductDNA (Unified Context): Automates a real-time service catalog, mapping changesets to deployments and modeling every service with integrated code, runtime, business, and security context. • Runtime Threat Modeling: Enables continuous threat modeling with tools to decompose applications, track changes, compare deployments, and uncover risks in real time. • ASPM: Heeler reduces alert noise by up to 95% and automates remediation workflows, scaling security seamlessly with engineering demands. • SCA with Static and Runtime Context: Combines static and runtime data with business and deployment context, delivering next-gen SCA that prioritizes what matters, strengthens security, and simplifies AppSec workflows. Heeler ensures AppSec teams and developers have the context they need to shift left and build secure-by-design applications—effortlessly.

#### Who Is the Company Behind Heeler?

- **Seller:** [Heeler Security](https://www.g2.com/sellers/heeler-security)
- **Year Founded:** 2023
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a1a68756cf4887b6fb99c645e3d205020401407b871bdb78a3753c9ca3752015&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fheeler-security&secure%5Burl_type%5D=linkedin_company_website)  
20 employees on LinkedIn®

### [Hilt](https://www.g2.com/products/hilt/reviews)

Hilt monitors how data actually moves across your environment, not just whether policies are followed. Using proprietary eBPF kernel probes, Hilt captures every data movement event at the base level across cloud workloads, endpoints, and network boundaries. A three-tier behavioral detection engine (deterministic rules, behavioral ML, and model inference) identifies anomalous data movement in real time including transfers where permissions were valid and no policy was violated, but the behavior was wrong. Automated containment blocks exfiltration in under one second. Deployed in minutes with one command, no code changes, and no SDK. Built for latency-sensitive environments including financial services, hedge funds, and law firms.

#### Who Is the Company Behind Hilt?

- **Seller:** [Hilt AI](https://www.g2.com/sellers/hilt-ai)
- **HQ Location:** Milton Keynes, GB
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8c5ec45d8068b9366441dc4d2be35aa75125f947ca7e31ff2ce02f5c0122cecc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fhilt-ai%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [MergeBase](https://www.g2.com/products/mergebase/reviews)

MergeBase is revolutionizing software supply chain protection with a full-featured, developer-oriented SCA solution that brings the lowest false positives in the industry and complete DevOps coverage from coding/building to deployment and run-time. MergeBase’s SCA tool analyzes the open-source/third-party libraries for vulnerabilities. Our mission is to protect the software supply chain. We provide a full-featured, developer-oriented solution that has the industry’s lowest false positive rates and complete coverage of the DevOps process.

**Average Rating:** 4.5/5.0

**Total Reviews:** 20

#### Who Is the Company Behind MergeBase?

- **Seller:** [MergeBase Software](https://www.g2.com/sellers/mergebase-software)
- **Year Founded:** 2018
- **HQ Location:** Coquitlam, British Columbia
- **Twitter:** @mergebasesecure  
86 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=69ee19fad389ad4f98212a51bf0a5efb0b41c459dc4f4e8ece60f23d0d5ab74b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmergebase%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 40% Small, 35% Medium

#### What Are Recent G2 Reviews of MergeBase?

**["MergeBase Detector of risk and vulnerabilities"](https://www.g2.com/survey_responses/mergebase-review-7833957)**

**Rating:** 4.5/5.0 stars

_— Prashant S._

[Read full review](https://www.g2.com/survey_responses/mergebase-review-7833957)

**["Revolutionizing Software Supply Chain Protection with MergeBase's SCA Platform"](https://www.g2.com/survey_responses/mergebase-review-7670163)**

**Rating:** 5.0/5.0 stars

_— Disha K._

[Read full review](https://www.g2.com/survey_responses/mergebase-review-7670163)

### [Qwiet AI](https://www.g2.com/products/qwiet-ai/reviews)

Qwiet AI delivers comprehensive application security by combining agentic AI with advanced code analysis. In a single scan, the platform provides uniquely accurate SAST, SCA, SBOM, secrets detection, and container analysis that helps dev and security teams find and fix vulnerabilities faster. With its proprietary Code Property Graph (CPG) technology and AI/ML models, Qwiet AI achieves up to 95% reduction in false positives compared to traditional tools, while offering contextual AutoFix that understands the unique context of your code, even across complex enterprise applications. Q: What makes Qwiet AI different from other AppSec solutions? A: Qwiet AI stands out through its agentic AI approach, which enables autonomous vulnerability detection and remediation. The platform's Code Property Graph technology allows for deeper code analysis and more accurate vulnerability detection, resulting in dramatically fewer false positives than traditional tools. This advanced technology enables the platform to understand code relationships and context at a deeper level, leading to precise vuln detection and contextually appropriate fixes. Q: What security capabilities does the platform include? A: The platform provides comprehensive security coverage including: - Static Application Security Testing (SAST) using a patented CPG-based approach, for vuln detection that is objectively the fastest and most accurate available per the OWASP benchmark - Software Composition Analysis (SCA) for third-party dependency scanning and vulnerability detection in open source components - Automated SBOM generation for supply chain transparency and compliance requirements - Advanced secrets detection to prevent credential exposure and secure sensitive information - Container security analysis built in - AI-powered AutoFix for automated vulnerability remediation with contextually aware patches, powered by the CPG and a custom AI/ML engine with its own LLM - Custom rule creation capabilities for organization-specific security requirements Q: How does Qwiet AI improve development workflows? A: Qwiet AI integrates seamlessly into existing CI/CD pipelines and developer workflows. The platform's speed (up to 40x faster than traditional scanners) and accuracy mean developers spend less time investigating false positives and more time coding. The AutoFix capability helps developers resolve issues quickly with AI-generated patches that are contextually aware and tailored to your codebase. Additionally, the platform provides IDE integrations and pull request analysis to catch vulnerabilities early in the development process. Q: What do customers think? A: Qwiet AI provides enterprise-grade support with dedicated customer success representatives and technical account managers. The platform consistently receives high marks for customer support, with a 97% "would recommend" rate in Gartner's Voice of the Customer. Customers receive comprehensive onboarding assistance, ongoing technical support, and regular check-ins to ensure successful implementation and adoption. Q: How can I get started with Qwiet AI? A: Qwiet AI offers self-service access, self-guided demos, and AE-guided demos, depending on your needs. You can request a personalized demo through the company website at qwiet.ai to see how the platform addresses their specific security challenges. You can also sign up for self-service access through the web site, or access documentation and integration guides there.

**Average Rating:** 4.8/5.0

**Total Reviews:** 3

#### Who Is the Company Behind Qwiet AI?

- **Seller:** [Qwiet AI](https://www.g2.com/sellers/qwiet-ai)
- **HQ Location:** San Jose, California, United States
- **Twitter:** @ShiftLeftInc  
1,164 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=dbca0b84e2c33a23f09717f495d5c8693d9858bba84b3152d5262dae9d5bc5e0&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fqwiet&secure%5Burl_type%5D=linkedin_company_website)  
45 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Large, 33% Small

#### What Do G2 Reviewers Say About Qwiet AI?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **responsive and collaborative support** from Qwiet AI, enhancing integration into their CI/CD pipelines.
- Users value the **highly responsive customer support** of Qwiet AI, which facilitates seamless integration processes.
- Users value the **easy integrations** of Qwiet AI, appreciating its thorough documentation for seamless CI/CD pipeline incorporation.
- Users value the **comprehensive documentation** from Qwiet AI, facilitating seamless integration into CI/CD pipelines.
- Users value the **effective team collaboration** fostered by Qwiet AI’s responsive support and thorough integration documentation.

##### Cons

- Users find the lack of a graphical interface for policies frustrating, relying solely on the **command line interface**.
- Users find the **limited customization options** frustrating, as policy creation relies solely on the CLI without a user interface.
- Users find the **limited features** of Qwiet AI frustrating, lacking a user-friendly interface for policy creation.
- Users find the lack of a user interface for creating policies a significant **UX improvement** concern for Qwiet AI.

#### What Are Recent G2 Reviews of Qwiet AI?

**["Seamless Integration with Responsive Support"](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)**

**Rating:** 5.0/5.0 stars

_— Brooks S._

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)

**["A great easy-to-use SAST Scanner"](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)**

**Rating:** 5.0/5.0 stars

_— Verified User in Retail_

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)

### [rezilion](https://www.g2.com/products/rezilion/reviews)

Rezilion's software attack surface management platform automatically secures the software you deliver to customers, giving teams time back to build. Rezilion works across your stack, helping you to know what software is in your environment, what is vulnerable, and what is actually exploitable, so you can focus on what matters and remediate automatically. KEY FEATURES: - Dynamic SBOM Create an instant inventory of all the software components in your environment - Vulnerability Validation Know which of your software vulnerabilities are exploitable, and which are not, through runtime analysis - Vulnerability Remediation Cluster vulnerabilities to eliminate multiple problems at once and automatically execute remediation work to save teams time. WITH REZILION, ACHIEVE: - 85% reduction in patching work after filtering out unexplainable vulnerabilities - 24/7 Continuous monitoring of your software attack surface -600% Faster time to remediate when you focus on what matters and patch automatically - 360-degree visibility across your entire DevSecOps stack -- not just in silos

**Average Rating:** 4.4/5.0

**Total Reviews:** 11

#### Who Is the Company Behind rezilion?

- **Seller:** [rezilion](https://www.g2.com/sellers/rezilion)
- **Year Founded:** 2018
- **HQ Location:** Be'er Sheva, Israel
- **Twitter:** @rezilion\_  
198 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b8dfa9915fe9aa05122fd1eceb40d06bb86b4b13a0a47b85d93cfb44a4099477&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F18716043&secure%5Burl_type%5D=linkedin_company_website)  
5 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 45% Medium, 36% Large

#### What Are Recent G2 Reviews of rezilion?

**["Platform for Automated Software Supply Chain Security"](https://www.g2.com/survey_responses/rezilion-review-8137689)**

**Rating:** 4.0/5.0 stars

_— Dr. Rajesh V._

[Read full review](https://www.g2.com/survey_responses/rezilion-review-8137689)

**["A New Era of Software Supply Chain Security"](https://www.g2.com/survey_responses/rezilion-review-8402929)**

**Rating:** 5.0/5.0 stars

_— Jawahar A._

[Read full review](https://www.g2.com/survey_responses/rezilion-review-8402929)

### [SCANOSS](https://www.g2.com/products/scanoss/reviews)

SCANOSS is the industry-leading open source software intelligence provider, offering the largest database of open source information available. SCANOSS delivers cutting-edge tools and services that help businesses and developers detect, manage, and secure their open source components. By identifying license obligations, security vulnerabilities, and other risk concerns, SCANOSS ensures that organisations can harness the power of open source safely and securely throughout the development pipeline.

**Average Rating:** 4.3/5.0

**Total Reviews:** 2

#### Who Is the Company Behind SCANOSS?

- **Seller:** [SCANOSS](https://www.g2.com/sellers/scanoss)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e9ad0cb5bc7f8eadedb40833e1d3b44ede507c82f885c3670c1ad7ffe0761d1f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fscanoss&secure%5Burl_type%5D=linkedin_company_website)  
24 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of SCANOSS?

**["SCANOSS Open Source Inventorying Engine"](https://www.g2.com/survey_responses/scanoss-review-7288704)**

**Rating:** 4.5/5.0 stars

_— Joe H._

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7288704)

**["Great product with a valuable solution but the paid SaaS Tier might be a bit expensive for some"](https://www.g2.com/survey_responses/scanoss-review-7283528)**

**Rating:** 4.0/5.0 stars

_— Joe H._

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7283528)

### [Scribe Security Trust Hub](https://www.g2.com/products/scribe-security-scribe-security-trust-hub/reviews)

Scribe is a SaaS solution that provides continuous assurance for the security and trust worthiness of software artifacts, acting as a trust hub between software producers and consumers. Scribe centralized SBOM management system allows to effortlessly manage and share products SBOMs along with all their associated security aspects in a controlled and automated manner.

#### Who Is the Company Behind Scribe Security Trust Hub?

- **Seller:** [Scribe Security](https://www.g2.com/sellers/scribe-security)
- **HQ Location:** Tel Aviv, IL
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=718bb1ea51037d10be729e699b2f2a28dd8deb3cb4cf065a8d45fcc053ea7231&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fscribe-security&secure%5Burl_type%5D=linkedin_company_website)  
25 employees on LinkedIn®

- [&lsaquo; Prev‹ Prev](/categories/software-bill-of-materials-sbom?order=popular#product-list)
- [1](/categories/software-bill-of-materials-sbom?order=popular#product-list)
- 2
- [3](/categories/software-bill-of-materials-sbom?order=popular&page=3#product-list)
- [Next &rsaquo;Next ›](/categories/software-bill-of-materials-sbom?order=popular&page=3#product-list)

Spotlight Categories

[Security Awareness Training Software](https://www.g2.com/categories/security-awareness-training)

[Project Management Software](https://www.g2.com/categories/project-management)

[Customer Service Automation Software](https://www.g2.com/categories/customer-service-automation)

[Robotic Process Automation (RPA) Software](https://www.g2.com/categories/robotic-process-automation-rpa)

[Customer Success Software](https://www.g2.com/categories/customer-success)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Software Bill of Materials (SBOM) Themes](/categories/software-bill-of-materials-sbom/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Software bill of materials (SBOM) solutions generate, ingest, manage, and monitor a machine-readable inventory of the components within software supply chains. The components covered include libraries, packages, modules, associated licenses, and more. Companies and developers use SBOM software to deliver and annotate comprehensive SBOMs for their software’s third party and open source components .

These solutions allow users to comply with government mandates that require the provision of a minimum SBOM. Maintaining and monitoring SBOMs also helps companies perform continuous risk assessments, though vulnerability remediation is not the primary focus of such tools. [software composition analysis (SCA) tools](https://www.g2.com/categories/software-composition-analysis) scan software supply chains’ components and dependencies at the code level to identify and remediate security vulnerabilities, whereas SBOM software automates the standardized presentation of those elements for transparency, observability, and compliance.

To qualify for inclusion in the Software Bill of Materials (SBOM) category, a product must:

- Automatically ingest and generate SBOMs in standard formats like CycloneDX and SPDX
- Continuously monitor and update SBOMs based on component versions, associated licenses, dependencies, and more
- Alert users of non-compliant elements in their software supply chain
- Allow users to annotate SBOMs
- Facilitate compliance with government regulations

Show More