# SBOM Observer

The SBOM management tool from Bytesafe, which runs the SBOM Guide

> SBOM Observer collects SBOMs from build pipelines and suppliers, monitors the components against vulnerability and licence data and checks every release against your rules.

Updated: 5 October 2026  
URL: https://sbom.se/en/resources/sbom-observer

[SBOM Observer](https://bytesafe.dev/observer) is a product from Bytesafe, which also runs the [SBOM Guide](https://sbom.se/en). It collects SBOMs from build pipelines and suppliers, monitors the components against vulnerability and licence data and checks every release against rules that you decide.

## Documentation

The documentation is at docs.bytesafe.dev:

* **[Getting started](https://docs.bytesafe.dev/observer/getting-started).** How to start using SBOM Observer and upload a first SBOM.
* **[How-to guides](https://docs.bytesafe.dev/observer/how-to).** Step by step for common tasks, such as CI/CD integration.
* **[Concepts](https://docs.bytesafe.dev/observer/concepts).** Background on the data model, attestations and policies.
* **[References](https://docs.bytesafe.dev/observer/references).** Supported formats, commands and API.

## Free tools

[SBOM Analyzer](https://bytesafe.dev/observer/sbom-analyzer) is a web tool where you can upload an SBOM and see the number of components, known vulnerabilities and licences, without an account.

[Observer CLI](https://github.com/sbom-observer/observer-cli) is an open-source command-line tool that creates SBOMs from directories and container images.

## Other products from Bytesafe

* [Trust Repository](https://bytesafe.dev/trust) collects SBOMs, VEX and support dates from suppliers and publishes your own to customers.
* [Dependency Firewall](https://bytesafe.dev/firewall) checks packages against your rules before they are installed.
