Skip to content
Interlynk

Interlynk

Category: SCA
License: Freemium (free Community Tier; paid Enterprise; Apache-2.0 CLI tools)
Suphi Cankurt
Suphi Cankurt
+8 Years in AppSec
Updated October 5, 2026
13 min read
Key Takeaways
  • Founded in 2022 by Surendra Pathak and Ritesh Noronha, headquartered in Menlo Park; the vendor says 100+ regulated companies use the platform
  • 308 GitHub stars on sbomqs (Apache-2.0, Go), which scores any CycloneDX or SPDX SBOM on a 0-10 scale and checks NTIA, BSI TR-03183-2, FSCT v3, and OpenChain Telco
  • 3 vulnerability sources (NVD, GitHub Security Advisories, OSV) enriched with EPSS, CISA KEV, and CWE, with VEX disposition tracking per finding
  • 5 products with 5 versions each, unlimited users, and one compliance standard on the free tier; a 15-day Enterprise trial unlocks the rest, and paid prices are quote-only
  • lynk-mcp lets Claude, Cursor, VS Code Copilot, and Zed query and update SBOM data, including VEX status and security incidents

Interlynk is an SBOM management platform in the SCA category for companies shipping regulated software and devices. It collects, scores, and monitors SBOMs and tracks the VEX decision on each finding.

Surendra Pathak and Ritesh Noronha founded it in 2022, and it is headquartered in Menlo Park, California. Interlynk says more than 100 regulated companies in medical devices, energy, and financial services use it.

Interlynk free SBOM compliance checker at demo.interlynk.io with NTIA Minimum Elements, BSI TR-03183 (EU CRA), FSCT, OpenChain Telco, and Interlynk Quality Profile options
Interlynk's browser-based compliance checker, which scores an uploaded SBOM without an account.

That customer figure deserves context. A May 2025 Interlynk announcement put 100 organizations on its free Community Tier, four of them Fortune 500. Logos on the site include BIOTRONIK, STERIS, ServiceNow, and Progressive.

I evaluated Interlynk against its product pages, documentation, press releases, and public GitHub repositories. This review did not include a regulatory submission or a firmware build run through lynkctl.

What is Interlynk?

Interlynk treats the SBOM as the central record for supply chain risk. You upload or generate an SBOM, and the platform runs quality checks, vulnerability matching, and policy evaluation on every version.

The documentation describes a fixed hierarchy: Organization, Product, Environment, Version (one SBOM), Components, and Vulnerabilities. Branches map to environments through rules, so production and development SBOMs stay separate.

The product splits into a hosted platform and a set of command-line tools. Most of the CLI tools are open source; the embedded C/C++ generator, lynkctl, is commercial.

ComponentWhat it doesLicense
Interlynk platformIngests, scores, monitors, and reports on SBOMs and VEXCommercial SaaS with a free tier
lynkctlGenerates CycloneDX SBOMs from C/C++ builds and package manifestsCommercial, distributed by Interlynk
sbomqsScores SBOM quality 0-10 and checks compliance profilesApache-2.0
sbomasmMerges, edits, enriches, and signs SBOMsApache-2.0
sbommvTransfers SBOMs from GitHub or folders to Interlynk, Dependency-Track, or foldersApache-2.0
bomtiqueBuilds SBOMs from a hand-authored component manifestApache-2.0
pylynkPython CLI for the platform APIApache-2.0
lynk-mcpMCP server exposing the platform to AI assistantsApache-2.0

What are Interlynk’s key features?

FeatureDetails
SBOM formatsCycloneDX and SPDX, JSON and XML
IngestionGitHub, GitLab, and Bitbucket push and pull request events; pylynk; GraphQL API; supplier upload links
Vulnerability sourcesNVD, GitHub Security Advisories, OSV
EnrichmentEPSS, CISA KEV, CWE
Quality checksSBOM Doctor plus sbomqs scoring against NTIA minimum elements
VEXDisposition per finding, editable in the UI, CLI, or MCP
TicketingJira and Linear, both bidirectional
NotificationsSlack, Microsoft Teams, email
IdentitySSO, role management, API keys

SBOM ingestion and repair

Push events from GitHub, GitLab, and Bitbucket trigger ingestion on every commit and pull request. CI pipelines can also upload through pylynk or the GraphQL API.

Automation Rules repair SBOMs on import, for example by setting missing supplier fields or applying license expressions. SBOM Doctor flags malformed PURLs, version mismatches, and missing licenses before they break vulnerability matching.

That repair step matters more than it sounds. Matching runs on PURLs and CPEs, so a component with malformed identifiers can miss advisories and show zero findings.

Vulnerability monitoring and VEX

Every component is matched against NVD, GitHub Security Advisories, and OSV. Findings are enriched with EPSS scores, CISA KEV status, and CWE identifiers.

New CVEs map back to versions you already shipped. That is the main difference from a scanner that runs once at release and never looks at the build again.

Each finding carries a VEX disposition. The documentation treats Affected and Not Affected as incomplete until a justification or notes are attached, which is the information an auditor checks.

Note
No documented reachability analysis
Interlynk prioritizes with EPSS, KEV, and recorded VEX decisions. I found no function-level or binary reachability analysis in its documentation, so exploitability calls stay with your team.

Supplier SBOM collection

You send a request from the dashboard with the vendor’s email address and the product it covers. The vendor gets a secure upload link and needs no Interlynk account.

The link is valid for 24 hours and auto-renews if clicked after it expires. Uploads must be CycloneDX or SPDX and are validated for format and completeness.

Once accepted, supplier components go through the same pipeline and monitoring as first-party SBOMs. For device makers that buy firmware from contract manufacturers, this replaces email threads and attachment folders.

Open-source license and maintenance governance

License expressions are parsed against the SPDX catalog and pass through an approval workflow with Approved, Rejected, and Unreviewed states. Custom, non-SPDX licenses sit in the same inventory.

Obligations attach to each license, so a component’s duties follow it into every product that uses it. The vendor lists five obligation types.

ObligationExample licensesWhat it requires
AttributionMIT, BSD, Apache-2.0Include copyright notice and license text
Source disclosureGPL-3.0, LGPLMake corresponding source available
CopyleftGPL-2.0, GPL-3.0Release derivative works under the same license
Patent grantApache-2.0Explicit grant of patent rights
Network copyleftAGPL-3.0Offer source to users interacting over a network

Support Analysis grades each component’s maintenance status from Actively Maintained down to Abandoned. It reads registry deprecation flags, repository activity, and OpenSSF Scorecard results.

sbomqs: open-source SBOM quality scoring

sbomqs is the most-starred of Interlynk’s public repositories. It is written in Go, licensed Apache-2.0, has 308 GitHub stars, and reached v2.1.2 in September 2026.

It grades any CycloneDX or SPDX SBOM on a 0-10 scale. Compliance checks cover NTIA minimum elements, BSI TR-03183-2 (v2.1.0, v2.0, and v1.1), FSCT v3, and OpenChain Telco.

Install and score commands from the project README:

brew tap interlynk-io/interlynk
brew install sbomqs

sbomqs score your-sbom.json
sbomqs compliance --bsi-v2 samples/photon.spdx.json
sbomqs list samples/photon.spdx.json --feature comp_with_supplier --missing

The list --missing form is the practical one. It names the components missing a version, supplier, or other field, which tells you what to fix rather than only lowering a score.

sbomqs also integrates with Dependency-Track. The dtrackScore command downloads a project’s SBOM, scores it, and can write the score back as a project label.

Dependency-Track project list with sbomqs quality scores written back as tags such as sbomqs=8.5 and sbomqs=6.3
sbomqs scores written back as Dependency-Track project tags, from the sbomqs repository.

The README lists Harness SSCA, sbom.sh, sbombenchmark.dev, and SBOMly as platforms using its scoring engine. It also cites a 2025 MSR paper that used sbomqs to score more than 78,000 SBOMs.

lynkctl: embedded C/C++ SBOM generation

The lynkctl documentation notes that most compiled C and C++ projects have no dependency manifest. Components are vendored into the source tree or pulled in through git submodules, which manifest-only analysis can miss.

lynkctl reads build files and build metadata to work out which sources get compiled and which libraries get linked. The documentation is explicit that the build is never executed.

The coverage table below follows the product page. The current provider docs list only Make, CMake, and IAR, so confirm TI support before evaluating it.

LayerSupported todayIn the works
Build systemsGNU Make, CMake, IAR Embedded Workbench for Arm; TI Code Composer Studio on the product page onlyEclipse CDT, Keil µVision
Compilers and linkersgcc, clang, LLVM, ld, iccarm, ilinkNone listed
Source controlGit, Git submodulesSVN
Microcontroller familiesSTM32, Infineon, NXPNordic, Renesas, Silicon Labs
Package managers (C/C++)None listedvcpkg, Conan
Manifest ecosystemsnpm, yarn, Python, Go, Rust, Ruby, PHP, .NET, Maven, GradleNone listed

With the --evidence flag, lynkctl adds CycloneDX evidence such as identity methods, occurrences, licenses, and confidence values. Conclusions CycloneDX cannot model go to diagnostics instead.

Interlynk says the same source tree produces a byte-identical SBOM. Vendored code is fingerprinted against an open-source index that the product page says is refreshed weekly.

The documentation describes that index as a local cache of roughly 300 MB. lynkctl db download and db check need network access, while generation itself runs offline once the cache is in place.

The documentation’s own examples write the SBOM to stdout, or to a file with evidence included:

lynkctl generate ./myproject > sbom.cdx.json
lynkctl generate ./myproject --evidence -o sbom.cdx.json

Exit codes are 0 for success, 1 for runtime or diagnostic errors, and 2 for usage errors. The --strict flag turns any warning into a non-zero exit.

One inconsistency to check during evaluation: the product page lists CycloneDX 1.6+ and SPDX 3.0+ output, while the lynkctl documentation describes CycloneDX 1.6 only.

lynk-mcp for AI assistants

lynk-mcp connects Claude, Cursor, VS Code Copilot, and Zed to the Interlynk API. Read tools cover products, versions, components, vulnerabilities, policies, licenses, and ticketing status.

Write tools cover component and supplier updates, single and bulk VEX updates, and security-incident actions. Each one requires a confirm=true parameter before it changes data.

It works on the Free and Enterprise tiers. The README’s macOS install command is brew install --cask interlynk-io/interlynk/lynk-mcp.

What does Interlynk integrate with?

Source control, ticketing, and messaging
GitHub GitHub
GitLab GitLab
Bitbucket Bitbucket
Jira Jira
Linear Linear
Slack Slack
Microsoft Teams Microsoft Teams
Dependency-Track Dependency-Track

For CI, pylynk handles uploads, VEX updates, attribution reports, and policy gating. The gate command waits for the policy scan, then returns 0 for pass, 3 for failure, or 4 for indeterminate.

python3 pylynk.py upload --prod 'my-product' --sbom my-sbom.json
python3 pylynk.py gate --prod 'my-product' --env 'default' --ver 'v1.0.0'

sbommv transfers SBOMs from GitHub or local folders into Interlynk, Dependency-Track, or folders. The README lists AWS S3 as new in one place and coming soon in another, so check your version.

How does Interlynk support FDA 524B and EU CRA?

Section 524B has required a machine-readable SBOM in cyber device premarket submissions since March 2023. Interlynk’s FDA page notes the agency can refuse a submission without one from October 2023.

The EU Cyber Resilience Act’s vulnerability reporting obligations apply from 11 September 2026, with the bulk of obligations from 11 December 2027. Both regimes expect an SBOM that stays current after release.

RegimeWhat it asks forInterlynk’s artifact
FDA 524BMachine-readable SBOM in the submission, plus postmarket vulnerability handlingCycloneDX or SPDX export per device version, with VEX status and monitoring history
EU CRASBOM maintained across the supported lifecycle, vulnerability handling and reportingContinuous component inventory and vulnerability monitoring per product
NTIA minimum elementsBaseline SBOM fieldsAutomated quality scoring per SBOM

Interlynk’s FDA page also covers the QMSR, in effect since 2 February 2026. Its argument: an SBOM generated on every build comes from controlled design processes, not last-minute assembly.

None of this makes a product compliant on its own. It produces the evidence an assessor asks for. My EU Cyber Resilience Act guide covers what the regulation requires before you shortlist tools.

Interlynk vs Dependency-Track

Dependency-Track is a free, self-hosted OWASP Flagship project. It ingests CycloneDX SBOMs and monitors them against NVD, GitHub Advisories, and OSS Index.

Interlynk covers the same continuous-monitoring job as a managed service. It adds supplier SBOM collection, quality scoring, license approval with obligations, and compliance reporting aimed at FDA and CRA reviewers.

The two also work together. sbomqs can score Dependency-Track projects, and sbommv can push SBOMs into a Dependency-Track instance.

Pick Dependency-Track if you want a free, self-hosted tool for CVE alerts on existing SBOMs. Consider Interlynk for a managed service with supplier collection and packaged compliance reports.

Interlynk vs Finite State

Finite State builds its inventory from shipped firmware and compiled binaries, across 50+ instruction set architectures by its own count. It needs no source code, which suits firmware inherited from contract manufacturers.

Interlynk takes the opposite route for embedded code. lynkctl reads the build you control and records evidence for each component, without analyzing the compiled image.

Interlynk’s own comparison says binary analysis suits unknown firmware, while post-build generation suits products you build. Finite State has no free tier; Interlynk has a limited one.

Pick Finite State if you need to inventory firmware you have no source for. Pick Interlynk if you build the firmware yourself and want SBOM management with a free starting point.

Interlynk vs Syft

Syft is Anchore’s free, Apache-2.0 generator for container images, filesystems, and archives. It writes SPDX or CycloneDX and runs offline, but it stops at generation.

Interlynk is mostly what happens after generation: storage, scoring, monitoring, VEX, and reporting. The platform accepts Syft output like any other CycloneDX or SPDX file.

Interlynk’s own generators are lynkctl, for build metadata and package manifests, and bomtique, for hand-written component manifests. The embedded C/C++ build support is the more distinctive overlap.

Pick Syft for free SBOM generation from containers. Pick Interlynk when you need to manage those SBOMs across products and versions, or generate them from embedded builds.

How much does Interlynk cost?

Interlynk publishes its free tier limits but not its paid prices. The pricing page is a lead form that asks for company size and compliance driver.

PlanWhat the vendor documents
Free tierOne compliance standard, up to 5 products with 5 versions each, unlimited users
Free tier extrasVulnerability detection, API access, weekly compliance digests, ShareLynk public posture link
Enterprise trial15 days; unlocks unlimited products, SBOM automation, RBAC, analytics, license management, workflow integrations
EnterpriseNot published; demo and quote
lynkctlCommercial; binary obtained by contacting Interlynk
Open-source CLIssbomqs, sbomasm, sbommv, bomtique, pylynk, lynk-mcp under Apache-2.0 at no cost

Five products with five versions is enough to evaluate on real SBOMs. Check whether that covers your evaluation, since a full portfolio will need a quote.

How do you get started with Interlynk?

  1. Score an SBOM you already have. Upload one to the browser checker at demo.interlynk.io, or run sbomqs score locally if the file cannot leave your network.
  2. Create a free account at app.interlynk.io and pick the compliance standard you are measured against.
  3. Create a product and upload a version. Use the web UI, pylynk upload, or connect GitHub, GitLab, or Bitbucket for automatic ingestion.
  4. Send one supplier SBOM request to see what the collection workflow returns from a real vendor.
  5. Add pylynk gate to CI once policies are set, so a failing policy blocks the pull request.

If your code is embedded C/C++, ask for a lynkctl trial and run it on one real firmware project before committing.

When should you use Interlynk?

Interlynk fits teams whose SBOM is a deliverable to a regulator or customer. Medical device makers preparing 524B submissions and manufacturers selling into the EU are the obvious buyers.

It also fits teams that receive SBOMs from many suppliers. The no-account upload link and shared monitoring pipeline handle the collection problem directly.

Embedded teams with Make, CMake, or IAR builds should look at lynkctl. Teams on Keil, Eclipse, or Conan should confirm the support status first, since those are still listed as in the works.

It is a weaker fit for pure application teams that want developer-side fixes. I found no documented function-level reachability analysis or automated dependency-fix pull requests.

If you are still working out what an SBOM must contain, start with my guide on what an SBOM is .

Tip
Best for
Product security and regulatory teams at medical device, industrial, and fintech companies that manage SBOMs, vulnerability responses, and supporting evidence for FDA 524B submissions or EU CRA obligations.

What are the alternatives to Interlynk?

For self-hosted SBOM monitoring, Dependency-Track is the free OWASP option. Anchore offers a commercial SBOM platform built on Syft and Grype, centered on containers.

For firmware you did not build, Finite State analyzes compiled binaries directly. For license-heavy programs, FOSSA focuses on license compliance and attribution.

For free generation, Syft covers containers and filesystems, and cdxgen generates CycloneDX across many languages.

My SBOM tools comparison lines up generators side by side, and the full roster is on the SCA tools page.

What are Interlynk’s strengths and limitations?

Where Interlynk is strong

The SBOM lifecycle is the whole product. Ingestion, repair, scoring, monitoring, VEX, supplier collection, and export live in one place instead of across scripts.

Supplier collection is practical. A no-account upload link with validation addresses the part of SBOM programs that usually stalls.

The open-source tooling is inspectable. sbomqs, sbomasm, and pylynk show how the scoring and API work before you talk to sales.

A free tier exists. Five products with five versions each is enough for a real evaluation before talking to sales.

Where Interlynk falls short

No published paid pricing. Anything beyond 5 products needs a quote, which makes budget comparison hard.

lynkctl coverage is still growing. Keil, Eclipse, vcpkg, Conan, and several microcontroller families are listed as in the works.

No documented reachability or dependency-fix PRs. Prioritization relies on EPSS, KEV, and VEX decisions you record yourself.

Small public footprint. Apart from sbomqs at 308 stars, the repositories have few stars, and most customer evidence comes from vendor press releases.

Frequently Asked Questions

What is Interlynk?
Interlynk is a SaaS SBOM management platform for teams shipping regulated software and devices. It ingests CycloneDX and SPDX SBOMs from CI pipelines and suppliers, scores their quality, monitors components against NVD, GitHub Security Advisories, and OSV, and tracks VEX decisions. The company was founded in 2022 and is headquartered in Menlo Park, California. It positions the platform around FDA 524B, EU CRA, NIS2, DORA, and PCI DSS 4.0.
Is Interlynk free?
The free tier covers one compliance standard, up to 5 products with 5 versions each, unlimited users, vulnerability detection, API access, and weekly compliance digests. A 15-day Enterprise trial unlocks unlimited products, SBOM automation, RBAC, analytics, license management, and workflow integrations. Paid prices are not published. The CLI tools sbomqs, sbomasm, sbommv, bomtique, pylynk, and lynk-mcp are Apache-2.0.
What is sbomqs?
sbomqs is Interlynk’s open-source SBOM quality scorer, written in Go under Apache-2.0 with 308 GitHub stars. It grades a CycloneDX or SPDX SBOM on a 0-10 scale and checks compliance with NTIA minimum elements, BSI TR-03183-2, FSCT v3, and OpenChain Telco. It runs offline, in Docker, and in CI. Its README lists Harness SSCA and sbom.sh among the platforms that use its scoring engine.
Does Interlynk generate SBOMs?
Yes, mainly through lynkctl, a commercial generator distributed by Interlynk on request. It reads GNU Make, CMake, and IAR Embedded Workbench projects without executing the build, plus package manifests for npm, Python, Go, Rust, Ruby, PHP, .NET, Maven, and Gradle. Its documentation describes CycloneDX 1.6 output, with component evidence added when you pass the –evidence flag. Interlynk’s open-source bomtique also generates SBOMs from a hand-written component manifest, and the platform accepts SBOMs from other generators.
How does Interlynk compare to Dependency-Track?
Dependency-Track is a free, self-hosted OWASP project that ingests SBOMs and monitors them for new vulnerabilities. Interlynk covers the same monitoring use case as a managed service and adds supplier SBOM collection, quality scoring, license approval workflows, and compliance reporting for FDA 524B and the EU CRA. Pick Dependency-Track if you want free and self-hosted; consider Interlynk if you want a managed service with supplier collection and packaged compliance reports.
Does Interlynk support VEX?
Yes. Every vulnerability finding carries a VEX disposition, and the documentation flags statuses that are missing required information such as a justification for Not Affected. VEX can be updated in the web app, from the command line with pylynk vex update, or through the update_component_vex tool in lynk-mcp. When Copy VEX Across Versions on Import is enabled and components match, earlier dispositions carry forward to new versions.
Which compliance frameworks does Interlynk target?
Interlynk markets the platform against FDA 524B, the EU Cyber Resilience Act, NIS2, DORA, and PCI DSS 4.0, and its intake form also lists NIST 800-171 and CSCRF. The free compliance checker scores SBOMs against NTIA minimum elements, BSI TR-03183 (used for EU CRA), FSCT v3, and OpenChain Telco. Generating these artifacts does not make you compliant; it produces the evidence an assessor asks for.