New: the first SBOM scanner for machines.Take a look
Tracer

Assess suppliers on real data

Automatic analysis of your suppliers' security maturity, based on publicly available signals, not questionnaires.

SSupplier · siemens.comSiemens Aktiengesellschaft
ComponentVulnerabilities
SCALANCE M874-2942617
SCALANCE M826-2942617
RUGGEDCOM RM1224941577

Automatic Supplier Detection

Tracer automatically detects suppliers from your product data and component lists, no manual table maintenance.

security.txt
Advisory page

RFC 9116 · found

security.txt Detection

Tracer automatically checks whether your suppliers have published a security.txt according to RFC 9116, the first indicator of security maturity.

CVD-Policy
PGP key

CVD Policy Detection

Does the supplier have a Coordinated Vulnerability Disclosure Policy? Tracer finds out and evaluates the quality.

CSAF-Feed
Advisory page

CSAF Feed Detection

Tracer detects whether suppliers publish CSAF advisories, machine-readable security notices according to international standards.

PSIRT

productcert@siemens.com

Hall of Fame
Advisory page

PSIRT Analysis

Does the supplier have a Product Security Incident Response Team? Tracer analyzes the publicly available information.

Properties

AMatureproductcert@siemens.com
Maturity (0–5)4
Security Score (0–100)82

Maturity Level (0-5)

The maturity level shows at a glance how far a supplier is in their security maturity, from "no signals" to "best practice".

How it works

Three steps to the full picture.

01

Suppliers are detected

Tracer pulls your suppliers from your product data. You can add more at any time.

supported by Scanner

02

Tracer checks what is actually there

security.txt, CVD policy, CSAF feed, PSIRT: Tracer checks what the supplier has really published. No questionnaire, no self assessment.

03

You see who you can trust

A score from 0 to 100 and a maturity level from 0 to 5, per supplier. If something changes you notice right away.

The difference

Wait eight weeks for answers.
Or simply look it up.

By hand8 weeks

Send out a questionnaire with 47 questions, follow up, wait. Back comes three times yes and a checkmark. Nobody ever checked whether the security.txt really exists.

With Tracer5 minutes

Tracer looks at what the supplier has actually published and turns it into a score from 0 to 100. If the security.txt disappears again, you see it right away.

Cyber Resilience Act

December 11, 2027.

From then on, product security is a legal obligation. No evidence, no CE marking.

486
Days
:
11
Hrs
:
19
Min
:
36
Sec

Measure supplier security, don't estimate it.

Automatic analysis of your suppliers' security maturity, without questionnaires.