Correlens

SBOM & Asset Management

One input that feeds everything.

Your software bill of materials is not the product; it is the shared inventory the product runs on. Correlens keeps it clean and current, then feeds it to vulnerability management and threat correlation, so a component is never just a line in a file.

IVI Head Unit · ComponentsCycloneDX 1.6enrichedsample data
ComponentVersionOriginProviderLicenceEOLVulns
gstreamer1.14.4OSSupstreamLGPL-2.12027-0129
Adaptive AUTOSARR23-11proprietaryTier-1 IVICommercial18
wolfSSL5.6.3OSSwolfSSL Inc.GPL-2.06
bluez5.66OSSupstreamGPL-2.02027-039
u-boot2021.10OSSupstreamGPL-2.02026-124
libexpat2.2.6OSSupstreamMIT2
312 components · 41 proprietary · 271 OSS · 729 vulnerabilities · sha256 verified

Validate & gate

A clean SBOM, or you find out why.

Every import is graded against NTIA minimum elements and EU CRA fields. A stale or incomplete bill of materials is caught at the gate, not months later in an audit.

  • Graded on import with a pass threshold, per format.
  • Field by field against the NTIA minimum elements.
  • Exportable as a SARIF report for NTIA and quality.
Import · Validation gatesample data
B
Gate passed · score 84 / 100NTIA minimum elements · CycloneDX 1.6
312 components · threshold 30
Component name and version312/312pass
Supplier name312/312pass
Unique identifier (CPE / purl)308/3124 gaps
Dependency relationships312/312pass

Map the product

One row per node, the way the product is built.

Import builds the node topology: the controllers and compute units, each with components, open vulnerabilities and enrichment status. The same model holds a drone flight controller or an ITS roadside unit.

  • Nodes are the compute units: gateways, domain controllers, IVI, telematics, zonal.
  • Beyond cars: a flight controller or a charge controller maps the same way.
  • Live counts of components and vulnerabilities per node.
EV Platform E-3 · Nodessample data
Central GatewayAdaptive AUTOSAR · safety MCU
128 comp
21
IVI Head UnitAndroid Automotive
312 comp
47
ADAS ControllerQNX Neutrino
204 comp
12
Telematics (TCU)Automotive Grade Linux
156 comp
18
Zonal Controller (front)Classic AUTOSAR
64 comp
3

Enrich continuously

Every component watched. Every vulnerability enriched.

Components are correlated to vulnerabilities continuously, not once at import. Each finding is enriched from correlated threat intelligence, so you see not just the CVE but whether it is exploited in the wild.

IVI Head Unit · Vulnerabilitiessample data
VulnerabilityComponentCVSSEPSSExploitationReachabilityState
CVE-2026-4187gstreamer 1.14.49.80.89confirmed exploited (KEV)reachableunder review
CVE-2026-3350wolfSSL 5.6.38.40.42exploit availablereachableto validate
CVE-2026-0915bluez 5.667.50.18PoC publishedadjacentto validate
CVE-2026-2044u-boot 2021.106.20.05no known exploitnot reachablesuppressed (VEX)
exploitation enriched from correlated CTI · CISA KEV (confirmed) · exploit availability · EPSS (predictive)

Diff releases

What changed between releases?

A software-defined product ships new software all the time. Compare any two releases and see exactly what was added, removed and changed, and how the vulnerability count moved, before it reaches the field. This is your R156 software-update trail.

Compare releases · 0061 → 0062sample data
+505
added
−86
removed
14
changed
−62
vuln Δ
0
licence Δ
ChangeComponentVersionIdentifier
addedopenssl3.0.14pkg:generic/[email protected]
changedwolfSSL5.6.0 → 5.6.3pkg:generic/[email protected]
removedopenssl1.1.1wpkg:generic/[email protected]
changedbluez5.64 → 5.66pkg:generic/[email protected]
every release compared at its authoritative import · exported as evidence for R156

Transportability

Your bill of materials is never trapped.

The SBOM is an exchange format before it is anything else. What you import here comes back richer, and what the platform learns about it ships in the formats your other tools already speak.

Your SBOM, enriched and returned

Import a bill of materials from any build. Take it back with vulnerabilities and VEX exploitability applied to every component, ready for the next tool in your chain.

import CycloneDX / SPDXexport enriched + VEX

e.g. a drone flight-controller SBOM in, an enriched bill with reachable CVEs out.

Intelligence your SOC can consume

A confirmed incident or a watchlist leaves the platform as a portable object, so the team that runs your security operations picks it up without re-keying anything.

watchlists in / outexport STIX 2.1

e.g. an ITS roadside-unit incident exported to your SOC and PSIRT.

Bring a bill of materials to the demo.

Book a demo