toolspool
Trace-AI logo

Trace-AI

verifiedFreemiumAPItrace-ai.dev

Developer tool generating real-time SBOMs and exploit-aware vulnerability scans for teams managing open-source dependency risk.

What it does

Trace-AI, built on the open-source ZSBOM engine, connects to GitHub or GitLab repos to automatically generate real-time software bills of materials, scan dependencies for exploitable vulnerabilities rather than raw CVE counts, and track license compliance and third-party vendor risk.

Core features

Real-time SBOM generation in CycloneDX and SPDX formats
Exploit-aware vulnerability prioritization beyond raw CVE lists
License compliance detection for copyleft and other licenses
Vendor and SDK/API risk tracking including SLA and breach history
Audit-ready evidence export mapped to ISO 27001 and SOC 2 controls
Open, auditable scoring and policy logic via ZSBOM

Best for

Generating SBOMs for security and compliance audits
Prioritizing which vulnerabilities to fix first based on real exploitability
Tracking license risk across a codebase's dependencies
Monitoring third-party vendor and API risk alongside code dependencies

Pricing

Free
Toolspool rankingby monthly traffic

Tutorials

Step-by-step: exactly how to get things done with it.