saascode

Sbomrelay

An SBOM operations service for defense subcontractors that generates standard inventories in CI, routes jurisdiction-specific evidence, and preserves a verifiable submission history.

Genesis score7.93/10
Make Sbomrelay real.0/500
500 more votes and Sbomrelay is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The opportunity
24 hoursEU CRA active-vulnerability window
30 scan unitsKeysight minimum order
The case

Small defense suppliers face software-component requests from federal buyers, European obligations, and other jurisdictions without the compliance staff or enterprise tooling of a prime contractor. Generating an SBOM is the easy part; knowing which artifact, attestation, deadline, and destination apply to each release is the recurring burden. The opening is a release-linked relay that turns standard inventories into a maintained evidence and submission workflow.

Who pays — and why

The security, compliance, or engineering owner at a defense subcontractor that must satisfy SBOM and vulnerability-disclosure demands across buyers and jurisdictions.

What it unlocks
Release-linked CycloneDX and SPDX evidence generated through the delivery workflow
A maintained routing map for buyer, jurisdiction, attestation, and deadline differences
A verifiable history of what was generated, approved, submitted, and changed
How Genesis scored it
7.93across seven criteria
tension 8temporal 9blindspot 6buyer 8leverage 9convergence 5why-not 8
9
Temporal window

A 2026 enterprise launch and active EU CRA pressure create current demand.

9
Asymmetric leverage

Generation, routing, and verification can scale through reusable software and jurisdiction rules.

5
Convergence

Cross-references and inbound links support the direction, while the stored score remains moderate.

Why it scored well

Current federal and European SBOM pressure meets mature open generation and transparency primitives, a narrow defense-supplier buyer, and an unserved multi-jurisdiction SMB tier.

What's holding it back

Convergence is moderate, the exact submission endpoints and obligations need primary-source validation, and enterprise vendors can package lower-cost tiers.

Signals detected4 sources crossed
SignalAnchore Syft repository

SignalKeysight

Signalrekor.sigstore.dev and timestamp.sigstore.dev

SignalGenesis market scan

Direction briefsbomrelay.md
sbomrelay.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.