Trace-AI
Developer tool generating real-time SBOMs and exploit-aware vulnerability scans for teams managing open-source dependency risk.
What it does
Trace-AI, built on the open-source ZSBOM engine, connects to GitHub or GitLab repos to automatically generate real-time software bills of materials, scan dependencies for exploitable vulnerabilities rather than raw CVE counts, and track license compliance and third-party vendor risk.
Core features
Real-time SBOM generation in CycloneDX and SPDX formats
Exploit-aware vulnerability prioritization beyond raw CVE lists
License compliance detection for copyleft and other licenses
Vendor and SDK/API risk tracking including SLA and breach history
Audit-ready evidence export mapped to ISO 27001 and SOC 2 controls
Open, auditable scoring and policy logic via ZSBOM
Best for
→Generating SBOMs for security and compliance audits
→Prioritizing which vulnerabilities to fix first based on real exploitability
→Tracking license risk across a codebase's dependencies
→Monitoring third-party vendor and API risk alongside code dependencies
Pricing
Free
Toolspool rankingby monthly traffic
Tutorials
Step-by-step: exactly how to get things done with it.