ZTI Solutions ZTI SOLUTIONS
Building & Securing IT Visions
A security analyst at a laptop and monitors facing a software supply-chain inspection gate
HomeProducts › Secure Scan
CDAO Tradewinds — Awardable
Zero Trust Software Supply-Chain Security

Inspect what your software is built on — at build and at the cross-domain gate.

One platform. One shared CVE & SBOM layer. Networked or air-gapped.

The problem

Supply-chain security is split across two moments that never talk.

Log4Shell scored a perfect 10. SolarWinds reached roughly 18,000 organizations. ZTI Secure Scan puts dependency risk and the cross-domain transfer gate on one shared CVE and SBOM layer — so the officer at the boundary decides on evidence, not a raw severity score.

CVSS 10.0

Log4Shell scored a perfect ten — and sat inside dependencies almost nobody had inventoried.

~18,000

Organizations reached by the SolarWinds supply-chain compromise through a trusted update.

2 tools

The pre-build scanner and the transfer gate never talk, so the officer works out the risk by hand.

The lifecycle spine

Know the risk before you build it, and inspect it before it crosses the line.

One login, one UI, one shared intelligence layer — from the first dependency to the cross-domain gate.

STEP 1

Analyze

DepShield scores every dependency and SBOM before the build.

STEP 2

Build

Risk context is written to the shared CVE/SBOM spine.

STEP 3

Inspect

Pluggable scanners inspect the artifact at the transfer gate.

STEP 4

Authorize

The IA officer accepts or rejects on enriched, ranked evidence.

STEP 5

Transfer

The artifact crosses the boundary with a full audit trail.

Two modules, one platform

Shift-left and shift-right, in one tool.

Dependency Intelligence — Every dependency scored before you build.
DepShield · analyze

Dependency Intelligence

Every dependency scored before you build.

Shift-left analysis for manifests and SBOMs. DepShield reads CISA KEV status, EPSS exploit probability, project health scoring, and maintainer provenance and bus-factor, then rolls them into a single composite risk score on every open-source package, back at the manifest, before a build ever runs.

  • Composite risk score per package, not a raw CVE list
  • CISA KEV, EPSS, project health scoring, maintainer bus-factor
  • Portfolio heatmap and supply-chain alerts across projects
  • SBOM ingestion and CVE/SBOM spine that the gate inherits
Artifact Inspection — Every artifact inspected at the gate.
SecureScan · inspect

Artifact Inspection

Every artifact inspected at the gate.

Cross-domain transfer inspection for files and container images. Pluggable vulnerability, malware, and SBOM scanners run at the boundary; the IA officer reviews findings, accepts or rejects the transfer, and every decision lands in a tamper-evident audit record ready for the RMF package. Malware scanning fails closed — a scanner error never masquerades as “clean.”

  • Vulnerability, malware, and SBOM scanning at the cross-domain boundary
  • IA accept / reject workflow with required rationale
  • Tamper-evident audit record per artifact for RMF
  • Fail-closed malware scanning — no false “clean”
The unification payoff

A two-to-four hour manual review, done in under a minute.

Each scanner finding at the gate already carries its DepShield context. Instead of a raw “High CVE,” the officer sees “High CVE · on CISA KEV · 99th-percentile EPSS · single-maintainer package flagged in 3 projects” — ranked evidence, decided in one pass.

Before · two silos

Raw scanner output: "High severity CVE-XXXX-XXXXX." The officer correlates KEV, EPSS, and maintainer health by hand across two disconnected tools while the transfer queue backs up.

High CVE
With Secure Scan · one spine

One ranked line: severity, KEV status, exploit probability, maintainer health, and every project where the same component was already flagged — accept or reject with one auditable click.

High CVEon CISA KEVEPSS 99th pctsingle maintainerflagged in 3 projects
Capabilities

Everything the authorization decision needs.

One shared CVE/SBOM spine

Dependency intelligence and gate findings live on one canonical data model. The gate inherits the enrichment automatically — no bolt-on integration.

Evidence-ranked findings

Findings are ranked by exploitability and reachability, not just CVSS. The most decision-relevant risk rises to the top.

Fail-closed inspection

Malware and vulnerability scanning fail closed. A scanner error is never reported as a clean result.

First-class air-gap

Offline vuln mirrors and side-loaded scanner signatures ship from the same codebase. Offline-degraded signals are clearly flagged.

Auditable authorization

Every accept/reject records the deciding user, rationale, and timestamp into a single tamper-evident decision history.

Mission Control dashboard

A portfolio heatmap and cross-domain risk view give leadership supply-chain posture at a glance.

Maintainer provenance

“Who wrote your code — and where.” Contributor geography and real-maintainer signal drawn from public commit history, with a NATO-view lens for regions of concern.

Closed-loop traceability

A vulnerability at the gate traces back to the same dependency already flagged upstream — and feeds the portfolio heatmap.

Fits existing workflows

Jira finding export, S3 artifact and report export, and Excel export drop into the pipelines teams already run.

Anywhere it has to run

Networked or fully air-gapped. IL4 to IL6.

The same codebase ships two deployment profiles. Enrichment degrades gracefully against mirrored feeds; scanner signatures are side-loaded. The platform deploys where the authorization decision matters most — including closed enclaves with zero outbound network.

API-driven backendRelational data storeAsync task workersPluggable scanner integrationsModern web consoleContainerized deployment

Networked

Live enrichment from vulnerability databases, CISA KEV, EPSS, project health scoring, and package registries, with auto-updating scanner signatures. Deploys with a single command.

Air-gapped (IL4–IL6)

Zero outbound network. Pre-loaded vulnerability mirrors and side-loaded scanner signatures from an offline bundle. Runs where the decision matters most.

Where it fits

Representative use cases.

  • Cross-domain transfer authorization — an IA officer inspects a container image before it moves between security domains and accepts or rejects on enriched, auditable evidence.
  • Shift-left dependency governance — a security team analyzes project SBOMs, watches supply-chain alerts, and tracks portfolio risk before code ever ships.
  • Air-gapped enclave deployment — the full platform runs disconnected against mirrored feeds and side-loaded signatures, with offline signals clearly flagged.
  • Closed-loop traceability — a vulnerability found at the gate is traced back to a dependency already flagged in three projects, feeding the portfolio heatmap.
Why it wins

Aligned to the frameworks you're accredited against.

  • NIST SP 800-218 (SSDF)
  • NIST SP 800-161 R2 (C-SCRM)
  • DoW Zero Trust Reference Architecture v2

Licensing. Fixed-price annual subscription — Individual, Site, Enterprise, FTE, and Per-Git-Instance. TRL 6 — production-ready.

Vehicles. SBIR Phase III · GSA MAS · OTA · CDAO Tradewinds — Awardable.

Available now to government customers

ZTI Secure Scan has been assessed awardable through the CDAO Tradewinds Solutions Marketplace as an awardable solution. Innovative per DFARS 212.7001 — both new technology and new application. Only ZTI Secure Scan covers the whole lifecycle, from the first dependency to the cross-domain gate.

Search “ZTI Secure Scan” in the Tradewinds Solutions Marketplace

Talk to the Secure Scan team

See Secure Scan run.

Jared Johnson leads product and business development for ZTI Solutions.