
CSOAI
Initializing...
Free forever ยท No credit card

CSOAI
Initializing...
Your AI supply chain is a black box. Generate audit-grade AI-BOMs in CycloneDX ML-BOM 1.6 + SPDX 3.0 format. Cover model provenance, training data sources, dependency trees, EU AI Act Annex IV compliance, and NIST AI RMF alignment โ all from your MCP client.
pip install ai-bom-mcpDocument the full lineage of your AI models โ base model, fine-tuning runs, quantisation steps, RLHF iterations, and deployment versions.
Catalogue all training data sources with licensing status, data cards, consent records, and GDPR Art 30 processing activity alignment.
Map the complete software supply chain โ frameworks, libraries, hardware accelerators, cloud services, and third-party API dependencies.
Ensure your technical documentation meets Annex IV requirements: training methodologies, data governance, validation procedures, and performance metrics.
Map your AI-BOM components against NIST AI Risk Management Framework categories โ Govern, Map, Measure, Manage.
pip install ai-bom-mcp โ one command, zero config.
Point it at your model registry, training scripts, or deployment config. It discovers components automatically.
Get a CycloneDX ML-BOM 1.6 or SPDX 3.0 JSON โ drop it straight into your compliance pack.
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"serialNumber": "urn:uuid:ai-bom-2026-05-c8f2a1",
"version": 1,
"metadata": {
"component": {
"type": "machine-learning-model",
"name": "customer-intent-classifier-v2.1",
"version": "2.1.0"
}
},
"components": [
{
"type": "machine-learning-model",
"name": "bert-base-uncased",
"version": "1.0",
"purl": "pkg:huggingface/google-bert/bert-base-uncased"
},
{
"type": "data",
"name": "intent-training-set-v3",
"description": "12,847 labelled utterances, CC-BY-4.0"
}
],
"dependencies": [
{ "ref": "customer-intent-classifier-v2.1", "dependsOn": ["bert-base-uncased", "intent-training-set-v3"] }
]
}ยฃ0/mo
3 BOMs/month. Community support. No signed attestations.
ยฃ149/mo
Unlimited BOMs + HMAC-signed attestations + SPDX 3.0 export + priority support.
ยฃ999/mo
Dedicated signing keys, custom verify domain, CI/CD integration, SLA, onboarding call.
EU AI Act Annex IV requires detailed technical documentation. CycloneDX ML-BOM is the emerging standard. Get ahead now.
Get Pro โ ยฃ149/mo โMEOK AI Labs ยท CSOAI LTD ยท UK Companies House 16939677 ยท 3rd Floor, 86-90 Paul Street, London EC2A 4NE ยท meok.ai