One shared CVE/SBOM spine
Dependency intelligence and gate findings live on one canonical data model. The gate inherits the enrichment automatically — no bolt-on integration.

Log4Shell scored a perfect 10. SolarWinds reached roughly 18,000 organizations. ZTI Secure Scan puts dependency risk and the cross-domain transfer gate on one shared CVE and SBOM layer — so the officer at the boundary decides on evidence, not a raw severity score.
Log4Shell scored a perfect ten — and sat inside dependencies almost nobody had inventoried.
Organizations reached by the SolarWinds supply-chain compromise through a trusted update.
The pre-build scanner and the transfer gate never talk, so the officer works out the risk by hand.
One login, one UI, one shared intelligence layer — from the first dependency to the cross-domain gate.
DepShield scores every dependency and SBOM before the build.
Risk context is written to the shared CVE/SBOM spine.
Pluggable scanners inspect the artifact at the transfer gate.
The IA officer accepts or rejects on enriched, ranked evidence.
The artifact crosses the boundary with a full audit trail.

Every dependency scored before you build.
Shift-left analysis for manifests and SBOMs. DepShield reads CISA KEV status, EPSS exploit probability, project health scoring, and maintainer provenance and bus-factor, then rolls them into a single composite risk score on every open-source package, back at the manifest, before a build ever runs.

Every artifact inspected at the gate.
Cross-domain transfer inspection for files and container images. Pluggable vulnerability, malware, and SBOM scanners run at the boundary; the IA officer reviews findings, accepts or rejects the transfer, and every decision lands in a tamper-evident audit record ready for the RMF package. Malware scanning fails closed — a scanner error never masquerades as “clean.”
Each scanner finding at the gate already carries its DepShield context. Instead of a raw “High CVE,” the officer sees “High CVE · on CISA KEV · 99th-percentile EPSS · single-maintainer package flagged in 3 projects” — ranked evidence, decided in one pass.
Raw scanner output: "High severity CVE-XXXX-XXXXX." The officer correlates KEV, EPSS, and maintainer health by hand across two disconnected tools while the transfer queue backs up.
One ranked line: severity, KEV status, exploit probability, maintainer health, and every project where the same component was already flagged — accept or reject with one auditable click.
Dependency intelligence and gate findings live on one canonical data model. The gate inherits the enrichment automatically — no bolt-on integration.
Findings are ranked by exploitability and reachability, not just CVSS. The most decision-relevant risk rises to the top.
Malware and vulnerability scanning fail closed. A scanner error is never reported as a clean result.
Offline vuln mirrors and side-loaded scanner signatures ship from the same codebase. Offline-degraded signals are clearly flagged.
Every accept/reject records the deciding user, rationale, and timestamp into a single tamper-evident decision history.
A portfolio heatmap and cross-domain risk view give leadership supply-chain posture at a glance.
“Who wrote your code — and where.” Contributor geography and real-maintainer signal drawn from public commit history, with a NATO-view lens for regions of concern.
A vulnerability at the gate traces back to the same dependency already flagged upstream — and feeds the portfolio heatmap.
Jira finding export, S3 artifact and report export, and Excel export drop into the pipelines teams already run.
The same codebase ships two deployment profiles. Enrichment degrades gracefully against mirrored feeds; scanner signatures are side-loaded. The platform deploys where the authorization decision matters most — including closed enclaves with zero outbound network.
Live enrichment from vulnerability databases, CISA KEV, EPSS, project health scoring, and package registries, with auto-updating scanner signatures. Deploys with a single command.
Zero outbound network. Pre-loaded vulnerability mirrors and side-loaded scanner signatures from an offline bundle. Runs where the decision matters most.
Licensing. Fixed-price annual subscription — Individual, Site, Enterprise, FTE, and Per-Git-Instance. TRL 6 — production-ready.
Vehicles. SBIR Phase III · GSA MAS · OTA · CDAO Tradewinds — Awardable.
ZTI Secure Scan has been assessed awardable through the CDAO Tradewinds Solutions Marketplace as an awardable solution. Innovative per DFARS 212.7001 — both new technology and new application. Only ZTI Secure Scan covers the whole lifecycle, from the first dependency to the cross-domain gate.
Jared Johnson leads product and business development for ZTI Solutions.