010-68421378
sales@cogitosoft.com
Categories
AddFlow  AmCharts JavaScript Stock Chart AmCharts 4: Charts Aspose.Total for Java Altova SchemaAgent Altova DatabaseSpy Altova MobileTogether Altova UModel  Altova MapForce Altova MapForce Server Altova Authentic Aspose.Total for .NET Altova RaptorXML Server ComponentOne Ultimate Chart FX for SharePoint Chart FX CodeCharge Studio ComponentOne Enterprise combit Report Server Controls for Visual C++ MFC Chart Pro for Visual C ++ MFC DbVisualizer version 12.1 DemoCharge DXperience Subscription .NET DevExpress Universal Subscription Essential Studio for ASP.NET MVC FusionCharts Suite XT FusionCharts for Flex  FusionExport V2.0 GrapeCity TX Text Control .NET for WPF GrapeCity Spread Studio Highcharts Gantt Highcharts 10.0 版 HelpNDoc Infragistics Ultimate  ImageKit9 ActiveX ImageKit.NET JetBrains--Fleet JetBrains-DataSpell JetBrains--DataGrip jQuery EasyUI jChart FX Plus OPC DA .NET Server Toolkit  OSS ASN.1/C Oxygen XML Author  OSS 4G NAS/C, C++ Encoder Decoder Library OSS ASN.1 Tools for C with 4G S1/X2 OSS ASN.1/C# OSS ASN.1/C++ OPC HDA .NET Server Toolkit OPC DA .Net Client Development Component PowerBuilder redgate NET Developer Bundle Report Control for Visual C++ MFC  Sencha Test SPC Control Chart Tools for .Net Stimulsoft Reports.PHP Stimulsoft Reports.JS Stimulsoft Reports.Java Stimulsoft Reports. Ultimate Stimulsoft Reports.Wpf Stimulsoft Reports.Silverlight SlickEdit Source Insight Software Verify .Net Coverage Validator Toolkit Pro for VisualC++MFC TeeChart .NET Telerik DevCraft Complete Altova XMLSpy Zend Server

Software Security - SCA Product Introduction

Software Security SCA is a Software Composition Analysis (SCA) tool powered by a proprietary analysis engine and a world-class knowledge base. It delivers capabilities such as SBOM generation, security risk analysis, open source compliance detection, vulnerability alerting, and security management. By minimizing risks associated with uncontrolled third-party software in the supply chain, it helps enterprises build a robust software supply chain security assurance system.

 

Even More Comprehensive: World-Class Knowledge Base Scale

  • Over 11 million component entries (including extensive long-tail components)
  • Over 262 million component version entries
  • Over 600,000 vulnerability entries and 2,600+ licenses

 

More Precise: Leading Detection Depth

Through high-quality data selection, AI-powered intelligent cleansing, and precise algorithm matching, the detection accuracy for mainstream languages and their binaries is on par with — or even exceeds — that of world-class tools.

 

Faster: Leading Detection Speed

Through industry-leading identification and detection technologies and a domestically pioneering directory analysis algorithm, the average detection time per component is 200ms.

 

Identify Software Assets

 

Software Asset Elements → Comprehensive Analysis Technology → Accurate & Rich SBOM

 

  • Software Asset Elements
  • 30+ development languages and code snippets
  • 20+ package managers
  • 100+ binary types (common development languages, archive/compressed files, installation files, file system/operating system images, etc.)

 

  • Comprehensive Analysis Technology
  • Components: Thousands of data sources, 300M+ components, 10B+ files
  • Vulnerabilities: Hundreds of data sources, 270K+ CVEs, 100K+ RASA, 150K+ patch links, domestic industry vulnerability database sources
  • Licenses: 2,600+ licenses, dozens of historical cases

 

  • Accurate & Rich SBOM
  • Security: Known vulnerability list, CVE false positives/negatives, vulnerability reachability, POC, remediation suggestions, mitigation measures, vulnerability remediation priority
  • Compliance: Multi-license multi-clause, deep license analysis, license exemption, code-level restrictions, license conflicts, cryptographic algorithms
  • Operations: Component maturity, health trend, community maturity, end-of-maintenance status

 

Manage Security Threats

 

Data Collection → Vulnerability Discovery → Vulnerability Remediation → Threat Intelligence

 

Ensure Open Source Compliance

 

  • Authoritative Data Collection
  • Accurate Risk Discovery
  • Pioneering Compliance Handling
  • Comprehensive Reports & Declarations
  • Detailed Compliance Knowledge Base

 

Flexible Application Modes

 

  • On-Premises Deployment

Deploy the Software Security Gene Database, Scanner, and Platform locally within the user's environment. All detection and processing operations are performed within the user's controlled environment. The Gene Database is updated monthly, while vulnerability data can be updated as frequently as daily, with incremental update support.

  • Cloud-Based Gene Database Application

Deploy the Scanner and Platform on-premises while the Gene Database is deployed on the public cloud. The detection process remains consistent with offline deployment. The project characteristics generated by the Scanner are irreversible, protecting the privacy of the user's source code. This mode offers lower deployment costs, and the Gene Database data is updated daily.

 

  • SaaS Application

Deploy the Software Security Gene Database and Platform on the public cloud. Users can either upload test artifacts directly via the public cloud web interface or download the Scanner client to collect project characteristics locally before uploading for detection. All communication data is bidirectionally encrypted to protect user privacy.

This mode offers flexible usage and pricing, making it suitable for pay-per-detection scenarios, addressing temporary audits, irregular spot checks, evaluation toolkits, and similar use cases. The Gene Database is updated daily.

 

Seamless Integration Solution is also provided.

Product Advantages

 

  • Component Asset Analysis
  • Supports more formats and covers more scenarios
  • Delivers more accurate detection

 

  • Risk Analysis and Remediation
  • More accurate and actionable vulnerability alerts
  • More practical open source compliance detection

 

  • Efficient and Sustainable Governance
  • Engineering-driven efficient governance and operational support

 

  • External Reports
  • More professional and feature-rich supply chain SBOM
  • One-click compliance declaration Notice
  • More complete business remediation reports

 

Beyond the advantages listed above, additional offerings include indigenous innovation support, premium services, and others.

Quick Navigation;

© Copyright 2000-2026  COGITO SOFTWARE CO.,LTD. All rights reserved