Bill of materials
Provenance
BetaHardware and software bills of materials, and the evidence packs produced from them.
Provenance records every device the company holds, who holds it and its state, and every component each release ships, deduplicated by package URL across the estate. Security findings are joined to both, so checking whether an advisory affects us is a lookup. Exports are control-tagged: organised by control reference, with each section stating what the register does and does not evidence. Every export is recorded in a hash-chained audit log.
Who it is for. RODMENA keeps its own asset register and SBOM here, and it is free for personal projects. Ask us about commercial use.
- Status
- Beta
- Part of
- Offerings
- Licence
- Free for personal use
- Product site
- provenance.rodmena.co.uk
- Tags
- SBOMCycloneDXSPDXVEXAsset registerFree for personal use
What it does
-
Asset register
Each device is listed with its custodian, state, encryption status and classification. Offboarding and incident response start here.
-
Components, deduplicated
Components are deduplicated by package URL across the estate, so thirty products sharing a base image make one row and thirty occurrences.
-
Control-tagged exports
Exports are organised by control reference and state their own limits. The audit log records a digest of the bytes produced.
Documentation and access details are on the product site, provenance.rodmena.co.uk. For a pilot, an integration or procurement questions, contact us.
Screens
All 9 screens of Provenance
Register an asset Provenance screenshot
Register a product Provenance screenshot
Licence policy Full page Provenance screenshot
SBOM estate export Provenance screenshot
Evidence export Full page Provenance screenshot
Audit trail Full page Provenance screenshot
Access model Provenance screenshot
Security alerts Provenance screenshot
Pipelines Provenance screenshot