Each BOM snapshot records the models, datasets, tools, MCP servers, and vendors bound to an asset at a point in time. Exports follow CycloneDX 1.5 and SPDX 2.3 from stored components. A BOM is evidence of composition — not a certified CVE feed.
Outcomes
- Point-in-time composition of an AI system
- Exportable SBOM-class artifacts
- Supply-chain dimension on the assurance score
