Supply-chain risk

Know and control your third-party risk

Qualimetry brings dependency vulnerabilities, known-exploited exposure, suppression management, licensing compliance and technology end-of-life into one view, so you can see and act on the risk your dependencies carry.

Vulnerabilities

See the vulnerabilities that matter, with the fix

Dependencies are ranked by risk using severity and reach, each with a next-safe version and an upgrade-risk rating, and exposure to CISA known-exploited vulnerabilities is flagged first.

  • Ranked by risk using CVSS severity and reach.
  • Next-safe and latest versions with an upgrade-risk rating.
  • Known-exploited vulnerabilities surfaced first.
Suppression management

Accepting a risk is a decision, not a mute button

Every scanner produces false positives, and the exception path is where governance usually quietly fails. A suppression here carries everything you would need to defend it to an auditor a year later.

  • Request, then approve or reject, with the requester and the decision both recorded.
  • An AI assessment recorded against the decision, so the reviewer has an argued position rather than a bare severity number.
  • The next compliant upgrade checked first, because an available fix beats an accepted risk.
  • A scope and an expiry, from a single analysis up to the whole estate, so acceptance is bounded and revisited.
  • An email to the requester on approval or rejection, editable before it goes.
See how exceptions are governed
Licensing

License compliance across your components

From a software bill of materials, Qualimetry classifies every component's license as allowed, notify, denied or undetermined, and tracks obligations, outbound compatibility, policy drift and license groups.

Policy outcomes

Every license classified as allowed, notify, denied or undetermined.

Obligations

Obligations tracked per component so nothing slips through unseen.

Outbound compatibility

Component licenses checked against how you distribute your software.

Policy drift

Changes away from your license policy surfaced as they happen.

End of life

Get ahead of end-of-life technology

Runtimes and frameworks are checked against a lifecycle catalogue and flagged as supported, past long-term support, due within twelve months or end of life, with a recommended upgrade and a priority of now, plan, review or monitor.

  • Lifecycle status from supported to end of life.
  • Recommended upgrade target for each technology.
  • Priority of now, plan, review or monitor to guide the work.
Trusted sources

Backed by recognised catalogues

Exposure draws on recognised public sources for vulnerabilities, known-exploited lists and lifecycle data, and the product shows when a source is unavailable rather than reporting a false all-clear.

CVE + KEV
exposure
Suppressions
governed
Licensing
classified
End of life
tracked
Questions

Supply chain, answered

What is known-exploited exposure?
It flags dependencies that appear on the CISA known-exploited vulnerabilities list, meaning they have been seen exploited in the wild. Those are surfaced ahead of vulnerabilities that are only theoretical, so remediation goes where the real-world risk is.
How do suppressions work?
A false positive moves through a workflow: request, then approve or reject, then expire. Before a decision is taken, Qualimetry checks whether a compliant upgrade is already available and records an AI assessment against the decision. Each suppression carries a scope, from a single analysis up to everything, a required note and an expiry, and the requester is emailed the outcome. The result is an accepted risk you can defend rather than a silenced finding.
What licensing outcomes are there?
From a software bill of materials, every component's license is classified as allowed, notify, denied or undetermined. Alongside the outcome, Qualimetry tracks obligations, outbound compatibility and drift away from your policy.
How is end of life determined?
Runtimes and frameworks are checked against a lifecycle catalogue and flagged as supported, past long-term support, due within twelve months or end of life, each with a recommended upgrade target and a priority to guide the work.

See your supply-chain risk

Book a demo to see CVE, licensing and end-of-life exposure on a real dependency graph.

Book a Demo