07 / In your browser / VERSION 0.4.0

SBOM & Data-Flow Triage

Turn software-component metadata into better questions for system owners.

LOCAL INSTRUMENT / SYNTHETIC EXAMPLE INCLUDED

Method

Traverses nested CycloneDX JSON iteratively, validates SPDX JSON records and parses bounded CycloneDX XML or SPDX tag-value before applying transparent category-name heuristics.

Use it safely

Begin with the synthetic example in the toolbench, then minimise any real-world input. Inspect each finding, its source/status note and the facts behind it before exporting a result.

What it cannot determine

An SBOM cannot reveal actual personal-data processing, system behaviour or compliance. Every heuristic match needs manual confirmation.

Processing boundary. This preview processes current input in browser memory. No input is submitted or stored by dpdp.store. Results are evidence-building aids, not legal approval, certification or an official schema.

9 minute working guide / SYNTHETIC WALKTHROUGH

From input to a reviewable handoff.

GUIDE 0.5
Reviewed
2026-08-26
Legal status
editorial analysis
Source/method records
dpdp-store-method-0.2
Changelog
0.5.0 — first public static working guide.

What this produces: A parser record and bounded interview questions derived from transparent package-name and reference heuristics.

FICTIONAL PRACTICE SCENARIO

A fictional application SBOM includes identity, logging, storage and network-related package names that need confirmation by its system owner.

Before you begin

  • Export a supported CycloneDX or SPDX document from a trusted build process and remove non-essential internal references if needed.
  • Do not run package scripts or open an SBOM in an execution environment merely to inspect it; this tool treats supported content as inert data.
  • Identify the application owner and a current inventory row before interpreting matches.

Walk the evidence sequence

  1. Select and parse one supported format

    Use a synthetic CycloneDX JSON/XML or SPDX JSON/tag-value example first, then load the bounded local document and run triage.

    Evidence to inspect
    The result identifies format, specification version, parser mode, safeguards, component count and finding count.
    Human review
    A parse failure should be fixed at the trusted SBOM source; do not weaken DTD, entity, token, depth, line or component controls.
  2. Read each match as a question

    Inspect the matched component reference, category and confidence, then read the generated owner question.

    Evidence to inspect
    The table shows the name/reference pattern behind analytics, identity, storage, network, logging, messaging, payment, advertising or cryptography cues.
    Human review
    Names can be misleading, unused, transitive or present only for build-time work. No match proves personal-data processing.
  3. Interview the system owner outside the tool

    Ask where the component runs, which configuration is active, what data reaches it, where output goes and what evidence supports the answer.

    Evidence to inspect
    The export becomes a bounded question list; the factual answers belong in controlled system documentation.
    Human review
    Use runtime, configuration, architecture and contract evidence rather than package-name intuition.
  4. Update the data-flow map

    Add confirmed systems, data categories, recipients, processors, regions and evidence links to the inventory; mark rejected hypotheses as reviewed rather than silently deleting them.

    Evidence to inspect
    The handoff connects software evidence to an inspectable inventory update without automating a compliance conclusion.
    Human review
    Re-run when the application or SBOM changes and reconcile version provenance.

Handoff check

  • Is the SBOM tied to the actual application version under review?
  • Were heuristic matches confirmed with runtime or configuration evidence?
  • Did confirmed facts update the inventory rather than remain in a disconnected report?
STOP / REVIEW BOUNDARY

An SBOM lists software metadata, not actual data flows. The triage does not execute components, crawl a system, inspect configuration or establish compliance.

Security and parsing

  • Inputs have byte, row or component limits appropriate to the parser.
  • Imported content is treated as text or data and is never executed.
  • Spreadsheet exports neutralise formula-leading cells.
  • Use the per-tool reset or “Clear current toolbench state” to remove current in-tab input and results. Downloaded files remain under your control.

Version record

0.4.0 · 26 August 2026: deterministic public static implementation, synthetic fixture and bounded local parser. Guide record 0.5 · 26 August 2026.