Project-based inventory
Link each component to a project to structure monitoring by scope. See each project’s status at a glance to prioritize the most exposed scopes.
See project and component posture at a glance while building a reliable inventory of your stack.
Link each component to a project to structure monitoring by scope. See each project’s status at a glance to prioritize the most exposed scopes.
See each component’s risk level at a glance to prioritize action on the most exposed components (upcoming or past end of support, vulnerabilities).
Daily sync from NVD/NIST: new CVEs, CVSS and EPSS scores, and CISA KEV catalog. Your statuses and inventory reflect the latest threats.
Import application manifests to detect components, versions, and dependencies from day one.
Manually add any component type to your inventory, especially useful for out-of-repository items (middleware, databases, internal tools) not found in dependency files.
Import SPDX or CycloneDX SBOMs to bootstrap or resync an existing inventory.
Sync GitHub, GitLab, and Bitbucket to keep inventory up to date automatically on a schedule you choose.
Missing from our catalog? Suggest a product from any project (name, vendor, comment) for our team to review and add.
On dependency import, SBOM import, or Git sync, unrecognized components are flagged in your inventory and escalated to our admin team to be added to the catalog within 7 business days.
Versions, patches, licenses, vendor references, official documentation, past/active/resolved CVEs, and per-component status.
Manage multiple isolated organizations from one account. Each organization is isolated, with its own projects, users, and data.
Define per-project rules: monitored events, channels, frequency, and optional ticket creation.
Critical, high, and medium CVEs, CISA KEV catalog presence, and EPSS threshold crossed. Configure a rule per type and severity level.
End of support in 12 months, 6 months, 30 days, or already reached. Anticipate migrations before your components become obsolete.
New patch or version, license change (Business and up), and unrecognized component detected in the project.
Receive alerts directly by email, on all plans.
Enable or disable automatic remediation ticket creation for each alert. Without a ticket, only the notification is sent.
Immediate notification, daily summary, or weekly summary, based on severity and how your team works.
Coordinate remediation and track actions.
Assignment, statuses, and comments to track each risk through resolution.
Assign an owner to each project and component for clear accountability.
Keep a trace of changes on each component.
Visualize your posture and export summaries per project or across the entire organization.
Report tab in each project: summary, 12-month trends, components, vulnerabilities, tickets, and team. Project-scope PDF export.
Consolidated multi-project view: summary, projects, components, vulnerabilities, licenses, vendors, and tickets.
Filter from 7 days to 12 months, or a custom range, to track CVEs, tickets, EOL components, and health indicators over time.
Customizable PDF (tabs and FR/EN language) at organization and project level. Tables exportable as CSV. Audit log in CSV and JSON.
Immutable log of all platform actions, viewable in the global report and exportable for audits.
SBOMs and evidence packages for regulatory audits, built on your monitoring reports.
Unlimited SBOMs in SPDX and CycloneDX for customers, auditors, and regulators.
Exportable inventory, CVEs, EOL components, SBOMs, and remediation actions, with reports and evidence mapped to NIS 2 Article 21.
Inventory, vulnerabilities, EOL components, tickets, and audit trail, with evidence aligned with controls A.5.9 and A.8.8.
ICT component inventory, vulnerabilities, EOL/EOS tracking, and remediation, with evidence for DORA Article 8.
Share an SBOM via a secure public link without an ObsoWatch account for the reader.
EU hosting, strong authentication, and access governance.
Data hosted in the EU to meet your sovereignty and compliance requirements.
Two-factor authentication via authenticator app to protect account access.
Projects, users, and data strictly isolated between each organization.
Manager, contributor, and reader: define who can administer, edit, or view each project.
Administrator, user, and guest, with fine-grained rights and permissions configurable per role.
Single sign-on through your SAML or OAuth identity provider.
Guides to get started and a team ready to help when you need it.
Guides, tutorials, and FAQs to onboard your teams, configure projects, and answer common questions.
Open a ticket (bug, question, technical issue, billing) and track your requests. Response times: 48 business hours (Starter), 24 business hours (Business), 4 business hours (Enterprise).
Your components, their CVEs, and their end-of-support dates-visible at a glance.
30 days freeNo credit cardNo commitment