Skip to content

Business solution

SBOM & software-composition evidence

Turn software composition and provenance into evidence a buyer can actually review.

The SBOM solution organises software-component, dependency and provenance evidence around the digital product being supplied, so reviewers can understand what is in scope and what changed.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.

For agent operators

Why it matters when the subject is an AI agent.

An agent is software, and a buyer's supply-chain review will reach it. Where a customer asks what an agent is built from and what changed between releases, this solution ties that evidence to the agent's enduring identity instead of to a file that goes stale.

The questions it helps answer

  • What is this agent built from, and what changed in this release?
  • Can composition evidence follow the agent across versions without a new identity each time?

Fit

Who it is for, and what changes.

Best for

  • Software publishers facing enterprise supply-chain review.
  • Agent, SDK, plugin, API and service teams managing third-party components.
  • Organisations that want SBOM evidence tied to an enduring product identity rather than an isolated file.

Outcomes

  • More reviewable software-composition evidence.
  • A clearer link between a release, its product identity and its supporting provenance.
  • Less manual reconstruction of component evidence during customer or regulatory review.

Inside

What is included, and how it works.

What is included

  • Structured software-composition evidence around the relevant ECZ-ID subject.
  • Release and provenance context where supplied by the customer workflow.
  • Support for buyer-facing evidence packaging.
  • Managed and enterprise depth for larger programmes.

How it works

  1. Identify the software product or service whose composition must be evidenced.
  2. Collect the relevant composition and provenance inputs.
  3. Organise them against the enduring ECZ-ID identity and release context.
  4. Re-use and update the evidence as dependencies and releases change.

Boundaries

What the FREE Passport already gives you, and what this never does.

Already included free

Versions of an agent are never separate Passports, so composition evidence can follow one identity across releases.

£0 · No card required · Permanent, not a trial.

What it never does

  • An SBOM describes composition and evidence; it is not a declaration that software is secure.
  • ECZ-ID does not turn missing source evidence into verified facts.
  • Identifying an agent is not controlling it. ECZ-ID does not authorise, restrict, supervise, pause or stop what an agent does — its operator and the party relying on it stay responsible for that.

Related

Read next.

Every Agent product

Start with the identity. Add SBOM & software-composition evidence when it earns its place.

£0 · No card required · Permanent, not a trial.