Risk Cyber & SBOM

Software Supply Chain & SBOM Risk Intelligence Solution

Software supply chains have corporate owners.

Software Bill of Materials requirements now include the corporate identity and ownership of software component vendors – not just the package names. Sayari resolves the corporate network behind every component in your SBOM, identifying foreign state-linked ownership before it becomes an Executive Order compliance issue.

THE EXECUTIVE ORDER REALITY

68%

of software components in U.S. federal agency SBOMs in 2024 had at least one upstream maintainer or vendor with beneficial ownership in China, Russia, or other adversary-designated states – per CISA SBOM pilot analysis.

CISA SBOM Pilot Program · Sayari Research · 2024

THE PROBLEM

Why SBOM compliance misses ownership risk

The structural gaps that point solutions can’t close.

01

Foreign state-linked maintainers

Executive Order 14028 and OMB M-22-18 require agencies to assess software supply chain risk – including the corporate identity of software vendors and maintainers. Most SBOM tools track package names, not the beneficial owners of the companies behind them.

02

Open-source corporate opacity

Major open-source projects receive significant contributions from developers employed by foreign state-linked corporations. Without corporate ownership data, SBOM reviewers can’t assess the national security implications of component dependencies.

03

Acquisition-driven exposure change

A software vendor that was benign at initial procurement may now be owned by a foreign state-linked acquirer. Software supply chain risk changes continuously – SBOM programs built on static data at procurement time miss this dynamic exposure.

THE SAYARI APPROACH

Corporate intelligence for software supply chains.

Sayari Graph provides financial crime investigators with instant access to beneficial ownership data, corporate network maps, and trade flow intelligence – dramatically accelerating the corporate structure research phase of every investigation.

SBOM Vendor Ownership Resolution

Submit your full software component list and Sayari resolves the corporate identity and beneficial ownership of every vendor and maintainer across 250+ jurisdictions.

Foreign State Ownership Detection

Trace software vendor ownership chains to identify Chinese, Russian, or other foreign state-linked beneficial owners – including ownership through holding companies, state investment vehicles, and nominally private entities.

Acquisition Alert Monitoring

Sayari Signal monitors your approved software vendor list for corporate ownership changes – alerting when a previously cleared vendor is acquired by a foreign state-linked entity.

EO 14028 Compliance Documentation

Sayari produces source-cited vendor ownership reports formatted for SBOM attestation documentation under Executive Order 14028 and OMB M-22-18 requirements.

aml_analysis.log

> Transaction Pattern Analysis

entity: “Novus Capital Holdings (UAE)”
✓ Resolved to canonical entity record
✓ 12 related payment entities identified
⚠ Circular transaction pattern detected

> Shell Company Chain

depth: 6 intermediaries · 4 jurisdictions
⚠ Panama → BVI → UAE → end beneficiary
✗ Beneficiary: OFAC SDN match (sanctioned)

sar.trigger(case=”NVS-0219″, typology=”layering”) → filed
Sayari Graph – AML transaction & network analysis

On this page

Get a demo

Se this live on your data

Request a Demo

WHY SAYARI

Legacy tools vs Sayari

SAYARI

  • Full corporate identity and beneficial ownership resolution for every software vendor in your SBOM
  • Foreign state ownership detection across 250+ jurisdictions – including holding company and investment vehicle structures
  • Continuous monitoring – Sayari Signal alerts when vendor ownership changes to a foreign state-linked entity
  • Integrated sanctions and enforcement screening – flags vendors with designations or enforcement history

LEGACY TOOLS

  • Package and dependency tracking only – no corporate identity or ownership data for vendors
  • No beneficial ownership resolution – can’t identify foreign state-linked ownership through holding structures
  • Static at procurement time – doesn’t detect post-acquisition foreign ownership changes
  • No EO 14028 or sanctions database integration for vendor risk assessment

RESULTS

Measured outcomes from SBOM compliance deployments

COVERAGE

250+

Jurisdictions with corporate registry data for software vendor ownership resolution

SPEED

24hr

Typical turnaround for full SBOM vendor ownership resolution via Sayari API for 1,000+ component lists

DOCUMENTATION

EO-ready

Source-cited vendor ownership reports formatted for EO 14028 and OMB M-22-18 attestation requirements

FREQUENTLY ASKED QUESTIONS

Common questions about software supply chain risk

What is a Software Bill of Materials (SBOM) and why does it matter for enterprise risk?
How does foreign corporate ownership of software vendors create security risk?
What regulations require SBOM disclosure or software supply chain vetting?
How does Sayari help identify FOCI risk in software procurement?

Resources & Insights

Recommended Resources

Investigation Brief

Starlink Terminal Diversion to Sanctioned Jurisdictions

Starlink terminals illegally diverted to Russian military through transnational facilitation networks spanning the U.S., Germany, …
Read Brief
Investigation Brief

Left of Launch: Mapping Adversary UAS Supply Chains

Exposing dual-use component networks supplying Russian military UAS programs through analysis of TSMD Global and TSK Vektor. Trade…
Read Brief
Investigation Brief

Talent Recruitment

A British AI researcher identified as a Thousand Talents Program beneficiary maintains undisclosed directorships of CCP-connected …
Read Brief