| Primary category | Software composition analysis (SCA) | Release-evidence verification |
| Core workflow | Identify open-source vulnerabilities, license risk, and supply chain exposure | Qualify evidence and evaluate against versioned policy |
| Evidence model | Dependency inventory, CVE data, and license findings | Corroboration, freshness, policy-version binding |
| Release-decision support | Informs dependency remediation and license compliance before release | Determines whether evidence satisfies policy |
| AI/coding-agent governance | May scan AI-generated code dependencies with existing SCA rules | Agent-neutral governance across IDEs, MCP servers, repos, CI, cloud, and runtime |
| Runtime context | Primarily static; may integrate runtime dependency signals | Runtime-correlated prioritization with evidence that risk was retired |
| Remediation proof | Tracks dependency updates and ticket closure | Validated fixes, not just ticket closure |