Live

Continuous visibility across
software, AI tools, hardware,
and dependencies.

iStreet’s Unified BOM creates a connected inventory of software components, AI models, hardware, firmware, and dependencies.

It continuously discovers and maintains component intelligence across enterprise environments, helping security, risk, governance, and technology teams understand what is deployed, where it operates, how components are connected, and which exposures require attention.

Built within iStreet’s Sovereign AI Enterprise Platform, Unified BOM moves component management beyond static inventories toward continuous visibility, risk intelligence, traceability, and governed action.

  • SBOM – Software components, libraries, packages, versions, and dependencies.
  • QBOM / CBOM – Cryptographic algorithms, keys, certificates, protocols, and dependencies.
  • AIBOM – AI models, datasets, frameworks, software dependencies, and related AI components
  • HBOM – Hardware components, devices, chips, firmware, and supply-chain details.

The platform integrates component intelligence into existing security, vulnerability, risk, and governance workflows, enabling teams to make decisions from current component context

Unified BOM Platform (UBP), The Inventory Layer

  • Generates and maintains SBOM, QBOM/CBOM, AIBOM, and HBOM using open standards
  • Centralises BOM artefacts within a Unified BOM Repository
  • Maintains version-controlled, tamper-evident, traceable component records
Arrow

RBVM Platform — The Risk Brain

  • Uses BOM data as contextual input for component-level risk assessment
  • Correlates vulnerabilities with exact components, exploit likelihood and business impact
  • Prioritizes remediation and connects identified risks to existing workflows

Result: Unified component visibility, risk intelligence, and prioritized remediation within one connected framework.

Key capabilities

Unified Multi-BOM Visibility

  • Unifies BOM into a connected component inventory
  • Provides visibility across software, AI models, cryptographic assets, hardware, firmware, and dependencies
  • Maintains traceability from individual components to systems and enterprise services

Continuous Discovery and BOM Generation

  • Continuously discovers components across connected enterprise environments
  • Generates and maintains BOM records as systems, deployments, and dependencies change
  • Supports standardized, machine-readable BOM formats for interoperability and portability

Component & Dependency Traceability

  • Maps relationships between components, systems, services, and dependencies
  • Tracks direct and transitive dependencies across technology layers
  • Provides visibility into where components are used and what they support

Risk-Driven Component Intelligence

  • Correlates components with vulnerability, exploitability, exposure, and asset context
  • Prioritizes component risk based on technical and business relevance
  • Connects BOM intelligence with risk-based vulnerability management and remediation workflows

Automated BOM Generation & Updates

  • Generates machine-readable BOMs using open standards
  • Updates component records as builds, deployments, versions, and dependencies change
  • Reduces reliance on manually maintained component inventories

Component Lifecycle & Version Management

  • Tracks component versions and changes throughout their lifecycle
  • Maintains historical BOM records for comparison and traceability
  • Identifies additions, removals, and dependency changes over time

Cryptographic Asset Inventory — CBOM

  • Inventories cryptographic algorithms, keys, certificates, protocols, and libraries
  • Maps cryptographic dependencies across systems and applications
  • Provides the inventory foundation required for crypto-agility and migration planning

AI Component Inventory — AIBOM

  • Catalogues AI models, datasets, frameworks, libraries, and dependencies
  • Maps relationships across AI system components
  • Maintains traceability across the AI component lifecycle

Hardware & Firmware Inventory — HBOM

  • Catalogues hardware components, devices, firmware, and associated dependencies
  • Connects hardware information with the systems in which components operate
  • Maintains component-level visibility across physical technology environments

Use cases

Supply-Chain Risk Management

Maintains visibility across software components, packages, versions, and dependencies, helping teams identify vulnerable or exposed components and understand their impact across enterprise systems.

AI Model and Governance

Inventories AI models, frameworks, datasets, libraries, and supporting dependencies to improve visibility and governance across the enterprise AI estate.

Cryptographic and Quantum Readiness

Discovers cryptographic assets, algorithms, keys, certificates, and cipher dependencies, helping enterprises understand cryptographic exposure and prioritise future crypto-agility initiatives.

Vulnerability and Incident Impact Analysis

Maps newly identified vulnerabilities and security issues to affected components, systems, and dependencies, helping teams understand potential impact and prioritise investigation and remediation.

Enterprise Asset Governance

One view across software, AI, crypto,
hardware

Why us

Sovereign

Designed to keep component inventories, dependency intelligence, and associated enterprise risk data within defined enterprise-controlled environments and deployment boundaries.

Governed

Access controls, traceability, version history, evidence, and defined workflows support governed component intelligence across the enterprise.

Production-Ready

Designed for continuous discovery and component intelligence across complex cloud, on-premise, hybrid, and enterprise technology environments.

Unified

Connects component intelligence with iStreet’s broader vulnerability management, security operations, GRC, resiliency, and observability capabilities within a unified enterprise architecture.

Component Visibility Into Actionable Risk Intelligence

Build a continuously updated view of the components your enterprise depends on — connected to risk, exposure, governance, and action.

Question Mark