Security

Software Bill of Materials

Railguard publishes a signed Software Bill of Materials for every production build. Use the resources below to review our dependency inventory and request the latest signed export.

Current Snapshot

Last updated: 2025-12-13

  • ✔ Full inventory of runtime and build-time dependencies
  • ✔ Vulnerability posture broken out by criticality
  • ✔ Signed digest aligned with build attestation metadata
Download latest SBOM JSON

Looking for older versions? Email security@railguard.ai with your release requirements.

Request a Signed Export

Enterprise prospects can obtain the complete SBOM package, including signature manifest, vulnerability diff, and reconciliation log. We turn around most requests within one business day.

1. Email security@railguard.ai with your company name, use case, and the release channel you're assessing.

2. Our security team will share a time-bound download link plus the verification instructions that align with our verification guide.

3. Validate the JSON and signatures against the corresponding build attestation located at /.well-known/build-attestation.json.

Vulnerability Disclosure

If you believe you've discovered an issue with one of the dependencies listed in our SBOM, please report it through our coordinated disclosure channel. We collaborate with maintainers and upstream vendors to remediate and release patched builds quickly.

Software Bill of Materials | Railguard AI | Railguard AI