ReARM
The Evidence Store for Your Entire Supply Chain
SBOMs, xBOMs and every other artifact - stored per release for 10+ years, versioned and audit-ready
Supports
OWASP Transparency Exchange API

Integrates
with your favorite tools


















Trusted By



Asset Management & Evidence Store
ReARM is a system of record that collects, stores for 10+ years, versions, and traces all digital artifacts required to prove the integrity, safety, and compliance of software, firmware, and hardware throughout their lifecycle. This includes SBOMs, HBOMs, other xBOMs, VEX, VDR, BOV, SARIF, attestations, build metadata, and more.

Regulatory Compliance
ReARM acts as a central SBOM/xBOM and security artifact repository and digital evidence store for all your releases and ensures supply chain security compliance with various regulations, including EU CRA, NIS2, DORA, US Executive Orders 14028, 14144, Section 524B of the FD&C Act, India's RBI and SEBI.

Track Vulnerabilities and Violations across your Supply Chain
ReARM integrates with various cyber security tools to present real-time security posture of your component and product releases.

Automated Versioning and Change Logs for your Releases
Choose desired versioning schema, connect to your CI and let ReARM do the rest!

Automated Bundling into Products
ReARM automatically bundles your Components into Products and supports multi-level nesting.

Approval and Lifecycle Management
ReARM Pro provides rich capabilities for managing approvals and lifecycles of your releases. Both manual and automated approvals are supported.

Pricing & Plans
Fixed predictable rates for any team
ReARM CE
- FOSS ReARM Community Edition
- Self-Hosted
- Single Organization
- Community support
- All Core SBOM/xBOM Storage & Retrieval Functionality
- Vulnerabilities and Violations via self-managed Dependency-Track Integration
ReARM Pro - Starter
- Priority Support (response within 8 hours)
- Managed Dependency-Track
- Managed Single Organization Service
- Approvals & Triggers
- Marketing Releases
- Free 90-day trial
ReARM Pro - Standard
- Premium support (24x7)
- Managed Dependency-Track
- Private Managed Service with SSO
- Approvals & Triggers
- Marketing Releases
- Support for Multi-Organization Workflow
- Free 90-day trial
ReARM Pro - Enterprise
- Premium support (24x7)
- Managed Dependency-Track
- Private Managed Service with SSO, or on‑prem deployment (air-gap ready)
- Approvals & Triggers
- Marketing Releases
- Support for Multi-Organization Workflow
- Free 90-day trial