For consultants

Software vulnerability reviews under your consultancy’s brand.

Turn a supported dependency inventory into vulnerability findings, a comparison with a previous scan, and a client report with your assessment and tracked follow-up.

RiskSnap runs locally. Package names, ecosystems and versions are sent to OSV for vulnerability lookups; the uploaded file itself stays on your machine.

Who it's for
  • Consultants reviewing client SBOMs or supported dependency manifests.
  • Small consultancies preparing branded findings and follow-up reports.
  • Practitioners comparing successive inventories and documenting their own assessment.
Getting started

Runs on your machine, used in your browser.

RiskSnap runs locally with Docker, and you use it through your browser. Follow the getting-started guide to launch it and try an example inventory.

What leaves your machine. The inventory file you open stays on it. To find vulnerabilities, RiskSnap sends the package names, ecosystems and versions it contains to OSV. It downloads CISA’s KEV catalog rather than sending your inventory to CISA, and optional NVD enrichment — off by default — sends CVE identifiers only.
Supported input formats
CycloneDX JSON
SBOM standard
SPDX JSON
SBOM standard
requirements.txt
Python
package-lock.json
Node.js
Current offer

Try RiskSnap during early access.

All features in the current release are available without a licence key. Future pricing has not been finalized.

What you get

See the reports RiskSnap produces.

Privacy & security

Your files stay on your machine.

  • All processing happens inside the Docker container on your machine
  • Dependency files are never uploaded to any external server
  • Vulnerability lookups send package names, ecosystems and versions to OSV — not the file itself
  • RiskSnap downloads CISA’s KEV catalog; your inventory is never sent to CISA
  • Optional NVD enrichment, off by default, sends CVE identifiers only
  • License validation runs only when a license key is provided, cached 24 hours locally
  • Security contact: security@wynn-systems.com
Compliance note
RiskSnap is not "CMMC certified." There is no DoD or Cyber AB certification for vulnerability scanning tools. RiskSnap produces documentation that can support a contractor's CMMC Level 2 audit, but final compliance determination is the responsibility of the assessing C3PAO. Always verify with your CMMC consultant or assessor that the evidence RiskSnap produces meets the requirements of your specific engagement.
FAQ
Do I need a Docker Hub account to use RiskSnap?
No account needed. docker pull swynnjr/risksnap works with just Docker installed on your machine — no sign-in required.
Does RiskSnap upload my dependency files?
No. The file itself stays on your machine. To look up vulnerabilities RiskSnap sends the package names, ecosystems and versions it found to OSV, and downloads CISA’s KEV catalog without sending anything to CISA. Optional NVD enrichment, off by default, sends CVE identifiers only. License validation, when a key is present, never includes dependency data.
Which ecosystems does RiskSnap cover?
Natively: Python (requirements.txt) and Node.js (package-lock.json). Via SBOM: any ecosystem your CycloneDX or SPDX SBOM describes — including Java/Maven, Go, Rust, and more. Bring a pre-generated SBOM from tools like the CycloneDX Maven plugin or Syft.
Is RiskSnap only for CMMC contractors?
It's designed with CMMC Level 2 audit workflows in mind, but it's useful for any team that needs structured vulnerability evidence and POA&M documentation without a SaaS dependency.