Scan the PLC project and get your SBOM
The first SBOM scanner for machines. It adapts to whatever you run. Point it at your project and get a CRA-ready bill of materials. B&R, Siemens, Rockwell and 40+ more vendors.
Automatic vendor detection
Point at a project folder. The scanner figures out whether it's B&R, Siemens, Rockwell or another vendor on its own.


40+ vendor plugins
From the major PLC market leaders to EU machine-building specialists. And if yours isn't there? We build the plugin for you.
CycloneDX & SPDX
Standards-compliant SBOMs in CycloneDX 1.5 and SPDX 2.3, compatible with your existing toolchain.
CRA-ready
Built for the EU Cyber Resilience Act. The generated bill of materials is the evidence you need.
Lean binary
No runtime dependencies, runs offline right on the engineering workstation, even with no internet on site.
Straight into Complioty
The finished SBOM lands seamlessly in the Complioty platform. CVE monitoring takes over from there.
How it works
Three steps to your bill of materials.
01
Point it at your project
You tell the Scanner where your machine project lives. It runs right on the computer you code on.
02
It spots the vendor itself
B&R, Siemens, Rockwell or another one: the Scanner sees it in the project files. Nothing to configure.
03
Your bill of materials is ready
Every component with its version, as a CycloneDX or SPDX file. From now on each one is checked for new vulnerabilities.
supported by Observer
The difference
Count for a week.
Or just point at it.
Open the project, walk through it component by component, dig out versions from libraries nobody remembers. And you still do not know whether the list is complete.
One command on the project folder, no internet needed. 42 components listed cleanly, three flagged for review. Ready to export.
