Your software has dependencies. You can list them — or you can prove them. A CBOM is the cryptographic proof that your software supply chain was in a known state at a specific point in time. An SBOM tells you what's there. A CBOM proves it.
Every CBOM receipt issued by CBOMcompliance.com contains the following fields, encoded in a signed JWS token. This is a real receipt structure from a live issuance during the Mini Shai-Hulud supply chain attack on May 12, 2026.
"An SBOM tells you what's in your software.
A CBOM proves what was there — and when."
Submit any CycloneDX or SPDX manifest. Receive a SHA-384 Merkle-committed, RS256-signed JWS receipt in seconds. Independently verifiable offline — forever.
Get a Signed Receipt →