This site has limited support for your browser. We recommend switching to Edge, Chrome, Safari, or Firefox.

Cart 0

No more products available for purchase

Products
Pair with
Add order notes
Subtotal Free
Shipping, taxes, and discount codes are calculated at checkout

Your Cart is Empty

SOFTWARE SUPPLY CHAIN SECURITY & COMPLIANCE

Gain Control of Your Software Supply Chain

Understand what's in your software, manage open source risks, and meet growing security and compliance requirements. Nohau provides solutions for SBOM management, vulnerability management, and open source license compliance – powered by FOSSA.

KEY FEATURES

Manage Risks Across the Software Supply Chain

Automated SBOM generation

Produce, ingest, analyze, and manage accurate, machine-readable SBOMs in CycloneDX and SPDX at the product level, not just per repository, and keep them current automatically as your code changes.

Open source license compliance

Identify every license and its obligations, generate complete attribution notices, and enforce policy automatically before risky components reach a release.

Vulnerability management

Continuously find and prioritize software vulnerabilities. Easily triage issues with advanced filters and actionable remediation guidance, plus automated VEX statement generation. 


EU CYBER RESILIENCE ACT

Solutions for the Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) introduces requirements for manufacturers to understand and document the software components in their products and manage vulnerabilities throughout the product lifecycle.

Nohau helps organizations address these requirements through solutions for SBOM management and vulnerability management. Using FOSSA's platform, software components can be identified and documented at the product level, enriched with vulnerability data, and maintained as products evolve.


Product-level SBOMs: consolidate repositories into a single release

Machine-readable formats: CycloneDX and SPDX out of the box

✓ Vulnerability documentation: components and known CVEs together

✓ Retained & versioned: evidence kept across the support period


SUPPORTED LANGUAGES & ECOSYSTEMS

Coverage for Every Type of Software Artifact

FOSSA's platform provides security and compliance coverage for every type of software artifact – packages, containers, binaries, code snippets (including those produced by AI assistants), and more.

Packages

Direct and transitive dependencies across every major package manager.

Containers

Analyze container images to inventory what actually ships inside them.

Binaries

Inspect firmware and binaries where source code isn't available.

Snippets & AI Code

Detect copied and AI-assistant-generated code, plus its license and origin.


CASES AND RESOURCES

Explore Software Supply Chain Security and Compliance

CASE STUDY

How SEW-EURODRIVE built scalable open source license compliance with FOSSA.

CASE STUDY

"Night and day difference" - How Milliman uses automation to reduce open source risk.

WEBINAR

Managing security and regulatory compliance for C/C++: A pragmatic approach.


Need help with software supply chain security and compliance?