Who it's for
- Consultants reviewing client SBOMs or supported dependency manifests.
- Small consultancies preparing branded findings and follow-up reports.
- Practitioners comparing successive inventories and documenting their own assessment.
Getting started
Runs on your machine, used in your browser.
RiskSnap runs locally with Docker, and you use it through your browser. Follow the getting-started guide to launch it and try an example inventory.
What leaves your machine. The inventory file you open stays on it. To find vulnerabilities, RiskSnap sends the package names, ecosystems and versions it contains to OSV. It downloads CISA’s KEV catalog rather than sending your inventory to CISA, and optional NVD enrichment — off by default — sends CVE identifiers only.
Supported input formats
CycloneDX JSON
SBOM standard
SPDX JSON
SBOM standard
requirements.txt
Python
package-lock.json
Node.js
Current offer
Try RiskSnap during early access.
All features in the current release are available without a licence key. Future pricing has not been finalized.
What you get
See the reports RiskSnap produces.
The second scan of a synthetic project, “Northwind Avionics”. Every component is ranked and accounted for — including the one RiskSnap could not check, which is marked SKIPPED rather than passed. The next panel is the review of this same scan. Synthetic example; the project is fictional. View full size ↗
The same scan, now compared against the previous one in that project. The conclusion and next steps are typed by the practitioner — RiskSnap does not write them. Above them sit the figures it does supply, including what changed since the earlier scan. Synthetic example; the reviewer and their words are invented. View full size ↗
A separate synthetic report example — not generated from the review shown above. It comes from its own RiskSnap 0.8.0 run, so its figures and commentary are its own, and it shows what the exported deliverable looks like under a consultancy’s branding. Read the whole sample report, including the PDF. The client and the commentary are fictional, and every page of it says so. View full size ↗
Privacy & security
Your files stay on your machine.
- All processing happens inside the Docker container on your machine
- Dependency files are never uploaded to any external server
- Vulnerability lookups send package names, ecosystems and versions to OSV — not the file itself
- RiskSnap downloads CISA’s KEV catalog; your inventory is never sent to CISA
- Optional NVD enrichment, off by default, sends CVE identifiers only
- License validation runs only when a license key is provided, cached 24 hours locally
- Security contact: security@wynn-systems.com
Compliance note
RiskSnap is not "CMMC certified." There is no DoD or Cyber AB certification for vulnerability scanning tools. RiskSnap produces documentation that can support a contractor's CMMC Level 2 audit, but final compliance determination is the responsibility of the assessing C3PAO. Always verify with your CMMC consultant or assessor that the evidence RiskSnap produces meets the requirements of your specific engagement.
FAQ
Do I need a Docker Hub account to use RiskSnap?
No account needed.
docker pull swynnjr/risksnap works with just Docker installed on your machine — no sign-in required.Does RiskSnap upload my dependency files?
No. The file itself stays on your machine. To look up vulnerabilities RiskSnap sends the package names, ecosystems and versions it found to OSV, and downloads CISA’s KEV catalog without sending anything to CISA. Optional NVD enrichment, off by default, sends CVE identifiers only. License validation, when a key is present, never includes dependency data.
Which ecosystems does RiskSnap cover?
Natively: Python (
requirements.txt) and Node.js (package-lock.json). Via SBOM: any ecosystem your CycloneDX or SPDX SBOM describes — including Java/Maven, Go, Rust, and more. Bring a pre-generated SBOM from tools like the CycloneDX Maven plugin or Syft.Is RiskSnap only for CMMC contractors?
It's designed with CMMC Level 2 audit workflows in mind, but it's useful for any team that needs structured vulnerability evidence and POA&M documentation without a SaaS dependency.