Scribe Hub: Specs and Core Capabilities

Comprehensive security monitoring, SBOM management, and compliance automation for your entire software development lifecycle

Secure your software development, using Scribe Hub

A SaaS platform serving as an admin panel and user portal for SBOM management, ASPM, SDLC risk analytics, security evidence graph, and compliance reporting.

Scribe Hub's Specs and Core Capabilities:

Scribe Security | Continuous code integrity

Discovery and Mapping of the Software Factory

A user-controlled development platform scanner deployed on customer premises, performing periodic scans to facilitate:

  • Development asset mapping
  • Security posture evaluation
  • Security controls’ coverage gap analysis
  • Continuous API scanning
  • Log collection and analysis
  • Queryable Evidence Graph
  • Lineage Visualization

Software Security Attestation, Signing and Verification

Scribe collects, signs, and verifies evidence for each software build and periodic scans to enable:

  • Automatic collection of security evidence
  • Attesting by signing evidence
  • Automated software signing and verification
Secure development processes and delivery pipelines

SDLC Security Monitoring and Gating

  • Pre-built frameworks and controls catalog
  • Customizable policy-as-code public repo
  • Policy Gates:  SCM, Build, Admission Control, Out-of-band
  • Security control adoption reports
diagram

Automated SBOM Management

  • Comprehensive SBOM Inventory with granular search capabilities
  • Automated SBOM generation from multiple sources
  • OSS library data enrichment and base image detection
  • Export and sharing in CycloneDX, SPDX, and CSV formats
diagram

Vulnerability Management

  • Known vulnerability detection near real-time and ongoing
  • Risk analysis through severity and exploitability
  • Cross-inventory risk analysis
  • VEX Advisories importing and authoring
  • Export VDR and VEX records
  • Integrating 180+ scanners
  • Gate SDLC with vulnerability risk policies
diagram

Compliance and Governance

  • Automated checks against NIST SSDF, SLSA, and CIS 
  • Automated checks against relevant parts in cyber security frameworks
  • Automated checks, utilizing policy-as-code and Gitops
  • Audit-ready reports

Integrations

  • API integration with SCMs, Container Registries, and Kubernetes clusters
  • Plugins or a CLI tool for CI/CD platforms evidence collection and gating
  • Kubernetes Admission Controller
  • REST API upload

Unified Dashboard

Centralized monitoring and analytics for security and compliance insights.