Confidential SBOMs.
Address regulatory and contractual obligations without publishing your internal software details, while still letting customers react quickly to new threats.
What We Build
Software Bills of Materials (SBOMs) between companies face slow adoption, as suppliers are hesitant to share their dependency details due to concerns over liability, IP, and business models.
With Confidential SBOMs, the SBOM is never handed over at all. It stays private, processed only inside hardware-protected environments. In high-risk scenarios, a customer can ask one specific question, e.g., does the product contain component-xyz in versions 2.1 through 3.4? They then receive a yes-or-no answer backed by a hardware attestation, so they can verify the answer is true without ever seeing the full SBOM. Every query is auditable and tied to a known vulnerability, making exhaustive enumeration impractical.
Confidential SBOMs complements our supply-chain evidence story: where Dependency Canary and Attestable Builds generate attested evidence about your dependencies, Confidential SBOMs lets customers verify specific facts about that inventory, without you handing it over. SBOMs can also be made verifiable using our Attestable Builds product, giving strong provenance guarantees.
Confidential SBOMs is in development. If SBOM obligations are on your roadmap, talk to us. Design partners shape what we build.
- Private by Default
- SBOMs are committed but their contents remain private, protected by TEEs.
- Attested Answers
- Queries are permitted only in high-risk events, and every answer carries a hardware attestation, so customers can verify it's true without seeing the SBOM.
- React Fast to Threats
- When a new vulnerability drops, your customers can check right away whether they are affected, without waiting on the notification chain.
- CRA Ready
- The EU Cyber Resilience Act (CRA) requires you to maintain an SBOM, but not to publish it. Answer customer requests without handing the full SBOM over.
What This Means For Your Team
Software Supplier
- Keep your software dependencies private. No need to expose internal architecture, IP, or business-sensitive details.
- Offer customers extra trust and transparency without giving up control over what they see.
Software Consumer
- React to new vulnerabilities without waiting for supplier involvement.
- Improve inventory insights and identify affected components across your stack.
Ready to Get Started?
Book a call with our founders to see how Light Squares can help secure your software supply chain.

