Skip to content
EcoCitizenZ
HomeCatalogPackagesSBOM Essentials
Core Package

SBOM Essentials

SBOM Essentials baseline credentialing. Software supply chain, product, cyber resilience, and IoT device.

Who it is for: Software vendors, IoT manufacturers, regulated buyers, and platform operators that need verifiable software-supply-chain, product, cyber-resilience, and IoT-device evidence before procurement, certification, or vulnerability response.

In plain terms

SBOM Essentials makes software supply chain provenance resolver-verifiable for buyers and regulators that ask about SBOM scope.

The real-world problem

What this removes

Buyers and regulated counterparties increasingly require independently-verifiable SBOM evidence before accepting software supply.

Ambiguity removed

Removes ambiguity about which operator publishes the SBOM and whether the declared scope is currently in good standing.

What it binds / includes

Scope of accountability

Binds declared SBOM posture to the parent operator passport and the Software Supply Chain Passport™.

Parent requirement: Requires an active ECZ-ID Business Passport™ at Verified or Assured tier (per TrustOps).

  • · SOFTWARE-SUPPLY-CHAIN
  • · PRODUCT
  • · CYBER-RESILIENCE
  • · IOT-DEVICE

Stack contributions

What PulseGuard™, LedgerCore™, and Resolver contribute

PulseGuard™

PulseGuard™ contributes present-state monitoring such as liveness, freshness, revocation or suspension state, and posture changes where supported by the activated passport/package.

LedgerCore™

LedgerCore™ records decisive lifecycle and evidence events where supported, such as issuance, activation, authority changes, child passport creation, revocation, bundle activation, badge state changes, or receipt references.

Resolver

Resolver shows current state for this product where supported — including active/suspended status, parent linkage, attached child passports/packages/add-ons, and the most recent receipt references. Current proof must be checked in Resolver.

Badge / mandate plate

Where this product has an ECZ-ID badge or mandate plate, the badge is an embeddable visual pointer to the Resolver state. The badge is not proof by itself; the Resolver check is the proof surface.

Insurability Readiness™ impact

Insurability Readiness™ is derived, free, non-sellable, and not manually editable. It is earned from the active passport stack, PulseGuard state, and LedgerCore evidence where supported. You do not buy readiness; you earn it.

Boundary of claim

What this product does not claim

  • · Does not certify the software is free of vulnerabilities.
  • · Does not constitute regulator approval.

Guided flow

Six steps from need to resolved state

  1. 01

    Understand the need

    Decide what commercial friction you are trying to remove. Developer Gateway documents the model. It does not determine eligibility, issue credentials, or create entitlements.

  2. 02

    Confirm parent requirement

    Every child passport, package, and add-on attaches to an active ECZ-ID Business Passport™. Verified or Assured may be required (per TrustOps).

  3. 03

    Review what this product does

    Check what is bound, what is included, and what it does not claim. No safety, certification, approval, or partnership claim is made on this page.

  4. 04

    Continue to TrustOps

    Acquisition, activation, payment, and lifecycle happen in TrustOps. Developer Gateway only routes the handoff.

  5. 05

    Return to Developer Gateway

    After TrustOps, return here for next-step docs and related guidance. Developer Gateway still does not prove current state.

  6. 06

    Check current proof in Resolver

    Current proof must be checked in the public Resolver. Copied metadata, screenshots, or website claims do not replace Resolver.

TrustOps midpoint

Acquisition, setup, payment, and lifecycle happen in TrustOps

Developer Gateway only routes. It does not host checkout, change canonical state, issue credentials, or replace Resolver proof. TrustOps owns the operational state for this product.

Browse packages in TrustOps

TrustOps URL: https://trustops.ecocitizenz.com/start

Return path

Come back here for next-step docs

After TrustOps completes acquisition or activation, return to Developer Gateway for related docs and guided next steps. Developer Gateway still does not prove current state. Current proof remains in Resolver.

Resolver proof

Current proof must be checked in Resolver

Copied metadata, screenshots, badges on third-party websites, or any claim made on Developer Gateway do not replace Resolver. The Resolver is the sole public proof surface for ECZ-ID.

Open Resolver ↗

Resolver URL: https://resolver.ecocitizenz.org

Recommendation

Find your recommended starting point

Enter your website URL. TrustOps will use it to recommend a starting point. Developer Gateway sends the URL only; TrustOps handles the recommendation, setup, payment, and lifecycle controls.

Developer Gateway does not host checkout, change canonical state, issue credentials, or replace Resolver proof. Current proof must be checked in Resolver.

ECZ-ID separates setup, verification state, and public proof. Developer Gateway documents setup paths and verifier guidance. TrustOps handles setup. Resolver remains the public proof surface. Re-check before reliance. Local policy decides.