Skip to content
EN
English 简体中文 soon 日本語 soon

Trace-AI

SBOMs and exploit-aware risk

Visit official site

What Trace-AI is

Trace-AI is a supply chain security tool. It produces real-time SBOMs from your repositories, scores risk with exploit awareness rather than raw CVE counts, checks licence compliance and tracks vendor context such as APIs, SDKs and SLA status.

The site states the first repositories are free.

What you can do with it

  • Generate CycloneDX or SPDX SBOMs
  • Prioritise vulnerabilities by exploitability
  • Check dependency licences
  • Watch third-party vendor exposure

Who it is for

  • Development and security teams
  • Organisations needing SBOM evidence
  • Teams managing supply chain compliance

What to watch out for

  • SBOM output is evidence, not a guarantee that dependencies are safe
  • Exploitability scoring should be checked against your own context and threat model
  • Repository scanning means granting code access; scope it
  • Confirm current free limits and pricing

Pros & cons

✓ What we like

  • SBOM generation tied to CI
  • Exploit-aware prioritisation
  • Licence compliance included

! What to watch out for

  • Not a security guarantee
  • Repository access to scope
  • Scoring needs context

FAQ

What does it produce?

Real-time SBOMs with risk scoring, licence checks and vendor visibility.

Does it replace manual security work?

No. It organises evidence; decisions remain with your team.

Is there a free tier?

The site states the first repositories are free.

Last reviewed: 2026-09-17

More AI coding tools tools

View all →

How we review