Products

One family, one workflow

From scanner to platform — every client-side component is open source and integrable through a documented API.

ts-scan
CLI Scanner

ts-scan

The open-source scanner for all common build tools. Detects dependencies directly in your CI/CD pipeline — also available as a GitHub Action. Maven, npm, PyPI, NuGet, Gradle and many more.

Learn more about ts-scan →
DeepScan
Source Code Analysis

DeepScan

Determines effective licenses from the actual source code - not just package metadata. Detects embedded code, copy-paste fragments and license anomalies.

Learn more about DeepScan →
ts-legalcheck
License Compliance

ts-legalcheck

Evaluates license obligations in the project context and automatically detects conflicts. Supports individual license policies and generates compliance evidence.

Learn more about LegalCheck →
VulnerabilityLake
Vulnerabilities

VulnerabilityLake

Consolidated vulnerability data from NVD, GitHub Advisories, OSV and more. Prioritised by relevance to your specific dependencies with context-aware risk scoring.

Learn more about VulnerabilityLake →
Threat Modelling
Threat Analysis

Threat Modelling

Systematic identification and assessment of threats in your software architecture. Model attack vectors, prioritise risks and derive targeted countermeasures.

Learn more about Threat Modelling →
Risk Management
Risk Management

Risk Management

Holistic risk management for your software supply chain. Aggregates vulnerabilities, license risks and compliance gaps into a consolidated risk picture with prioritized recommendations.

Learn more about Risk Management →
CSAF — Vulnerability Communication
CSAF / ts-mCTP

CSAF — Vulnerability Communication

Automated creation and distribution of security advisories in the CSAF standard. Structures vulnerability communication between vendors, CERTs and users — machine-readable and CRA-compliant.

Learn more about CSAF →
Coordinated Vulnerability Disclosure
CVD

Coordinated Vulnerability Disclosure

A structured process for responsible vulnerability disclosure. Coordinates communication between discoverers, vendors and the public — CRA-compliant.

Learn more about CVD →
SSCS Platform
Platform

SSCS Platform

The integrated platform for the entire software supply chain. Unites all tools in a single dashboard - SBOM management, vulnerabilities, licenses, regulatory compliance and reporting. Powered by AI agents for intelligent automation.

Learn more about the platform →