Your whole software estate under control, in one interface.

Inventory & visibility

See project and component posture at a glance while building a reliable inventory of your stack.

Project-based inventory

Link each component to a project to structure monitoring by scope. See each project’s status at a glance to prioritize the most exposed scopes.

Component status

See each component’s risk level at a glance to prioritize action on the most exposed components (upcoming or past end of support, vulnerabilities).

Daily CVE monitoring

Daily sync from NVD/NIST: new CVEs, CVSS and EPSS scores, and CISA KEV catalog. Your statuses and inventory reflect the latest threats.

Dependency file import

Import application manifests to detect components, versions, and dependencies from day one.

Manual component entry

Manually add any component type to your inventory, especially useful for out-of-repository items (middleware, databases, internal tools) not found in dependency files.

SBOM import

Import SPDX or CycloneDX SBOMs to bootstrap or resync an existing inventory.

Git repository sync

Sync GitHub, GitLab, and Bitbucket to keep inventory up to date automatically on a schedule you choose.

Product suggestions

Missing from our catalog? Suggest a product from any project (name, vendor, comment) for our team to review and add.

Unknown components escalated automatically

On dependency import, SBOM import, or Git sync, unrecognized components are flagged in your inventory and escalated to our admin team to be added to the catalog within 7 business days.

Detailed component record

Versions, patches, licenses, vendor references, official documentation, past/active/resolved CVEs, and per-component status.

Partner offer

Multi-organization management

Manage multiple isolated organizations from one account. Each organization is isolated, with its own projects, users, and data.

Alerts

Define per-project rules: monitored events, channels, frequency, and optional ticket creation.

Vulnerability alerts

Critical, high, and medium CVEs, CISA KEV catalog presence, and EPSS threshold crossed. Configure a rule per type and severity level.

End-of-life alerts

End of support in 12 months, 6 months, 30 days, or already reached. Anticipate migrations before your components become obsolete.

Update and inventory alerts

New patch or version, license change (Business and up), and unrecognized component detected in the project.

Email notifications

Receive alerts directly by email, on all plans.

Ticket creation

Enable or disable automatic remediation ticket creation for each alert. Without a ticket, only the notification is sent.

Delivery frequency

Immediate notification, daily summary, or weekly summary, based on severity and how your team works.

Workflow & collaboration

Coordinate remediation and track actions.

Remediation tickets

Assignment, statuses, and comments to track each risk through resolution.

Project and component owners

Assign an owner to each project and component for clear accountability.

Per-component action history

Keep a trace of changes on each component.

Reports & oversight

Visualize your posture and export summaries per project or across the entire organization.

Project report

Report tab in each project: summary, 12-month trends, components, vulnerabilities, tickets, and team. Project-scope PDF export.

Business and up

Global report

Consolidated multi-project view: summary, projects, components, vulnerabilities, licenses, vendors, and tickets.

Business and up

Period-based analysis

Filter from 7 days to 12 months, or a custom range, to track CVEs, tickets, EOL components, and health indicators over time.

Business and up

PDF, CSV, and JSON exports

Customizable PDF (tabs and FR/EN language) at organization and project level. Tables exportable as CSV. Audit log in CSV and JSON.

Business and up

Full audit trail

Immutable log of all platform actions, viewable in the global report and exportable for audits.

Compliance & evidence

SBOMs and evidence packages for regulatory audits, built on your monitoring reports.

SBOM generation and export

Unlimited SBOMs in SPDX and CycloneDX for customers, auditors, and regulators.

Business and up

NIS 2 evidence

Exportable inventory, CVEs, EOL components, SBOMs, and remediation actions, with reports and evidence mapped to NIS 2 Article 21.

Business and up

ISO 27001 evidence

Inventory, vulnerabilities, EOL components, tickets, and audit trail, with evidence aligned with controls A.5.9 and A.8.8.

Business and up

DORA evidence

ICT component inventory, vulnerabilities, EOL/EOS tracking, and remediation, with evidence for DORA Article 8.

Business and up

Secure SBOM sharing link

Share an SBOM via a secure public link without an ObsoWatch account for the reader.

Security

EU hosting, strong authentication, and access governance.

Hosting in the European Union

Data hosted in the EU to meet your sovereignty and compliance requirements.

MFA (TOTP)

Two-factor authentication via authenticator app to protect account access.

Per-organization isolation

Projects, users, and data strictly isolated between each organization.

Project roles

Manager, contributor, and reader: define who can administer, edit, or view each project.

Organization roles

Administrator, user, and guest, with fine-grained rights and permissions configurable per role.

Enterprise

SAML & OAuth SSO

Single sign-on through your SAML or OAuth identity provider.

Support & documentation

Guides to get started and a team ready to help when you need it.

Documentation

Guides, tutorials, and FAQs to onboard your teams, configure projects, and answer common questions.

Client support

Open a ticket (bug, question, technical issue, billing) and track your requests. Response times: 48 business hours (Starter), 24 business hours (Business), 4 business hours (Enterprise).

Your first scan in 15 minutes

Your components, their CVEs, and their end-of-support dates-visible at a glance.

30 days freeNo credit cardNo commitment