Interlynk is an SBOM management platform in the SCA category for companies shipping regulated software and devices. It collects, scores, and monitors SBOMs and tracks the VEX decision on each finding.
Surendra Pathak and Ritesh Noronha founded it in 2022, and it is headquartered in Menlo Park, California. Interlynk says more than 100 regulated companies in medical devices, energy, and financial services use it.

That customer figure deserves context. A May 2025 Interlynk announcement put 100 organizations on its free Community Tier, four of them Fortune 500. Logos on the site include BIOTRONIK, STERIS, ServiceNow, and Progressive.
I evaluated Interlynk against its product pages, documentation, press releases, and public GitHub repositories. This review did not include a regulatory submission or a firmware build run through lynkctl.
What is Interlynk?
Interlynk treats the SBOM as the central record for supply chain risk. You upload or generate an SBOM, and the platform runs quality checks, vulnerability matching, and policy evaluation on every version.
The documentation describes a fixed hierarchy: Organization, Product, Environment, Version (one SBOM), Components, and Vulnerabilities. Branches map to environments through rules, so production and development SBOMs stay separate.
The product splits into a hosted platform and a set of command-line tools. Most of the CLI tools are open source; the embedded C/C++ generator, lynkctl, is commercial.
| Component | What it does | License |
|---|---|---|
| Interlynk platform | Ingests, scores, monitors, and reports on SBOMs and VEX | Commercial SaaS with a free tier |
| lynkctl | Generates CycloneDX SBOMs from C/C++ builds and package manifests | Commercial, distributed by Interlynk |
| sbomqs | Scores SBOM quality 0-10 and checks compliance profiles | Apache-2.0 |
| sbomasm | Merges, edits, enriches, and signs SBOMs | Apache-2.0 |
| sbommv | Transfers SBOMs from GitHub or folders to Interlynk, Dependency-Track, or folders | Apache-2.0 |
| bomtique | Builds SBOMs from a hand-authored component manifest | Apache-2.0 |
| pylynk | Python CLI for the platform API | Apache-2.0 |
| lynk-mcp | MCP server exposing the platform to AI assistants | Apache-2.0 |
What are Interlynk’s key features?
| Feature | Details |
|---|---|
| SBOM formats | CycloneDX and SPDX, JSON and XML |
| Ingestion | GitHub, GitLab, and Bitbucket push and pull request events; pylynk; GraphQL API; supplier upload links |
| Vulnerability sources | NVD, GitHub Security Advisories, OSV |
| Enrichment | EPSS, CISA KEV, CWE |
| Quality checks | SBOM Doctor plus sbomqs scoring against NTIA minimum elements |
| VEX | Disposition per finding, editable in the UI, CLI, or MCP |
| Ticketing | Jira and Linear, both bidirectional |
| Notifications | Slack, Microsoft Teams, email |
| Identity | SSO, role management, API keys |
SBOM ingestion and repair
Push events from GitHub, GitLab, and Bitbucket trigger ingestion on every commit and pull request. CI pipelines can also upload through pylynk or the GraphQL API.
Automation Rules repair SBOMs on import, for example by setting missing supplier fields or applying license expressions. SBOM Doctor flags malformed PURLs, version mismatches, and missing licenses before they break vulnerability matching.
That repair step matters more than it sounds. Matching runs on PURLs and CPEs, so a component with malformed identifiers can miss advisories and show zero findings.
Vulnerability monitoring and VEX
Every component is matched against NVD, GitHub Security Advisories, and OSV. Findings are enriched with EPSS scores, CISA KEV status, and CWE identifiers.
New CVEs map back to versions you already shipped. That is the main difference from a scanner that runs once at release and never looks at the build again.
Each finding carries a VEX disposition. The documentation treats Affected and Not Affected as incomplete until a justification or notes are attached, which is the information an auditor checks.
Supplier SBOM collection
You send a request from the dashboard with the vendor’s email address and the product it covers. The vendor gets a secure upload link and needs no Interlynk account.
The link is valid for 24 hours and auto-renews if clicked after it expires. Uploads must be CycloneDX or SPDX and are validated for format and completeness.
Once accepted, supplier components go through the same pipeline and monitoring as first-party SBOMs. For device makers that buy firmware from contract manufacturers, this replaces email threads and attachment folders.
Open-source license and maintenance governance
License expressions are parsed against the SPDX catalog and pass through an approval workflow with Approved, Rejected, and Unreviewed states. Custom, non-SPDX licenses sit in the same inventory.
Obligations attach to each license, so a component’s duties follow it into every product that uses it. The vendor lists five obligation types.
| Obligation | Example licenses | What it requires |
|---|---|---|
| Attribution | MIT, BSD, Apache-2.0 | Include copyright notice and license text |
| Source disclosure | GPL-3.0, LGPL | Make corresponding source available |
| Copyleft | GPL-2.0, GPL-3.0 | Release derivative works under the same license |
| Patent grant | Apache-2.0 | Explicit grant of patent rights |
| Network copyleft | AGPL-3.0 | Offer source to users interacting over a network |
Support Analysis grades each component’s maintenance status from Actively Maintained down to Abandoned. It reads registry deprecation flags, repository activity, and OpenSSF Scorecard results.
sbomqs: open-source SBOM quality scoring
sbomqs is the most-starred of Interlynk’s public repositories. It is written in Go, licensed Apache-2.0, has 308 GitHub stars, and reached v2.1.2 in September 2026.
It grades any CycloneDX or SPDX SBOM on a 0-10 scale. Compliance checks cover NTIA minimum elements, BSI TR-03183-2 (v2.1.0, v2.0, and v1.1), FSCT v3, and OpenChain Telco.
Install and score commands from the project README:
brew tap interlynk-io/interlynk
brew install sbomqs
sbomqs score your-sbom.json
sbomqs compliance --bsi-v2 samples/photon.spdx.json
sbomqs list samples/photon.spdx.json --feature comp_with_supplier --missing
The list --missing form is the practical one. It names the components missing a version, supplier, or other field, which tells you what to fix rather than only lowering a score.
sbomqs also integrates with Dependency-Track. The dtrackScore command downloads a project’s SBOM, scores it, and can write the score back as a project label.

The README lists Harness SSCA, sbom.sh, sbombenchmark.dev, and SBOMly as platforms using its scoring engine. It also cites a 2025 MSR paper that used sbomqs to score more than 78,000 SBOMs.
lynkctl: embedded C/C++ SBOM generation
The lynkctl documentation notes that most compiled C and C++ projects have no dependency manifest. Components are vendored into the source tree or pulled in through git submodules, which manifest-only analysis can miss.
lynkctl reads build files and build metadata to work out which sources get compiled and which libraries get linked. The documentation is explicit that the build is never executed.
The coverage table below follows the product page. The current provider docs list only Make, CMake, and IAR, so confirm TI support before evaluating it.
| Layer | Supported today | In the works |
|---|---|---|
| Build systems | GNU Make, CMake, IAR Embedded Workbench for Arm; TI Code Composer Studio on the product page only | Eclipse CDT, Keil µVision |
| Compilers and linkers | gcc, clang, LLVM, ld, iccarm, ilink | None listed |
| Source control | Git, Git submodules | SVN |
| Microcontroller families | STM32, Infineon, NXP | Nordic, Renesas, Silicon Labs |
| Package managers (C/C++) | None listed | vcpkg, Conan |
| Manifest ecosystems | npm, yarn, Python, Go, Rust, Ruby, PHP, .NET, Maven, Gradle | None listed |
With the --evidence flag, lynkctl adds CycloneDX evidence such as identity methods, occurrences, licenses, and confidence values. Conclusions CycloneDX cannot model go to diagnostics instead.
Interlynk says the same source tree produces a byte-identical SBOM. Vendored code is fingerprinted against an open-source index that the product page says is refreshed weekly.
The documentation describes that index as a local cache of roughly 300 MB. lynkctl db download and db check need network access, while generation itself runs offline once the cache is in place.
The documentation’s own examples write the SBOM to stdout, or to a file with evidence included:
lynkctl generate ./myproject > sbom.cdx.json
lynkctl generate ./myproject --evidence -o sbom.cdx.json
Exit codes are 0 for success, 1 for runtime or diagnostic errors, and 2 for usage errors. The --strict flag turns any warning into a non-zero exit.
One inconsistency to check during evaluation: the product page lists CycloneDX 1.6+ and SPDX 3.0+ output, while the lynkctl documentation describes CycloneDX 1.6 only.
lynk-mcp for AI assistants
lynk-mcp connects Claude, Cursor, VS Code Copilot, and Zed to the Interlynk API. Read tools cover products, versions, components, vulnerabilities, policies, licenses, and ticketing status.
Write tools cover component and supplier updates, single and bulk VEX updates, and security-incident actions. Each one requires a confirm=true parameter before it changes data.
It works on the Free and Enterprise tiers. The README’s macOS install command is brew install --cask interlynk-io/interlynk/lynk-mcp.
What does Interlynk integrate with?
For CI, pylynk handles uploads, VEX updates, attribution reports, and policy gating. The gate command waits for the policy scan, then returns 0 for pass, 3 for failure, or 4 for indeterminate.
python3 pylynk.py upload --prod 'my-product' --sbom my-sbom.json
python3 pylynk.py gate --prod 'my-product' --env 'default' --ver 'v1.0.0'
sbommv transfers SBOMs from GitHub or local folders into Interlynk, Dependency-Track, or folders. The README lists AWS S3 as new in one place and coming soon in another, so check your version.
How does Interlynk support FDA 524B and EU CRA?
Section 524B has required a machine-readable SBOM in cyber device premarket submissions since March 2023. Interlynk’s FDA page notes the agency can refuse a submission without one from October 2023.
The EU Cyber Resilience Act’s vulnerability reporting obligations apply from 11 September 2026, with the bulk of obligations from 11 December 2027. Both regimes expect an SBOM that stays current after release.
| Regime | What it asks for | Interlynk’s artifact |
|---|---|---|
| FDA 524B | Machine-readable SBOM in the submission, plus postmarket vulnerability handling | CycloneDX or SPDX export per device version, with VEX status and monitoring history |
| EU CRA | SBOM maintained across the supported lifecycle, vulnerability handling and reporting | Continuous component inventory and vulnerability monitoring per product |
| NTIA minimum elements | Baseline SBOM fields | Automated quality scoring per SBOM |
Interlynk’s FDA page also covers the QMSR, in effect since 2 February 2026. Its argument: an SBOM generated on every build comes from controlled design processes, not last-minute assembly.
None of this makes a product compliant on its own. It produces the evidence an assessor asks for. My EU Cyber Resilience Act guide covers what the regulation requires before you shortlist tools.
Interlynk vs Dependency-Track
Dependency-Track is a free, self-hosted OWASP Flagship project. It ingests CycloneDX SBOMs and monitors them against NVD, GitHub Advisories, and OSS Index.
Interlynk covers the same continuous-monitoring job as a managed service. It adds supplier SBOM collection, quality scoring, license approval with obligations, and compliance reporting aimed at FDA and CRA reviewers.
The two also work together. sbomqs can score Dependency-Track projects, and sbommv can push SBOMs into a Dependency-Track instance.
Pick Dependency-Track if you want a free, self-hosted tool for CVE alerts on existing SBOMs. Consider Interlynk for a managed service with supplier collection and packaged compliance reports.
Interlynk vs Finite State
Finite State builds its inventory from shipped firmware and compiled binaries, across 50+ instruction set architectures by its own count. It needs no source code, which suits firmware inherited from contract manufacturers.
Interlynk takes the opposite route for embedded code. lynkctl reads the build you control and records evidence for each component, without analyzing the compiled image.
Interlynk’s own comparison says binary analysis suits unknown firmware, while post-build generation suits products you build. Finite State has no free tier; Interlynk has a limited one.
Pick Finite State if you need to inventory firmware you have no source for. Pick Interlynk if you build the firmware yourself and want SBOM management with a free starting point.
Interlynk vs Syft
Syft is Anchore’s free, Apache-2.0 generator for container images, filesystems, and archives. It writes SPDX or CycloneDX and runs offline, but it stops at generation.
Interlynk is mostly what happens after generation: storage, scoring, monitoring, VEX, and reporting. The platform accepts Syft output like any other CycloneDX or SPDX file.
Interlynk’s own generators are lynkctl, for build metadata and package manifests, and bomtique, for hand-written component manifests. The embedded C/C++ build support is the more distinctive overlap.
Pick Syft for free SBOM generation from containers. Pick Interlynk when you need to manage those SBOMs across products and versions, or generate them from embedded builds.
How much does Interlynk cost?
Interlynk publishes its free tier limits but not its paid prices. The pricing page is a lead form that asks for company size and compliance driver.
| Plan | What the vendor documents |
|---|---|
| Free tier | One compliance standard, up to 5 products with 5 versions each, unlimited users |
| Free tier extras | Vulnerability detection, API access, weekly compliance digests, ShareLynk public posture link |
| Enterprise trial | 15 days; unlocks unlimited products, SBOM automation, RBAC, analytics, license management, workflow integrations |
| Enterprise | Not published; demo and quote |
| lynkctl | Commercial; binary obtained by contacting Interlynk |
| Open-source CLIs | sbomqs, sbomasm, sbommv, bomtique, pylynk, lynk-mcp under Apache-2.0 at no cost |
Five products with five versions is enough to evaluate on real SBOMs. Check whether that covers your evaluation, since a full portfolio will need a quote.
How do you get started with Interlynk?
- Score an SBOM you already have. Upload one to the browser checker at demo.interlynk.io, or run
sbomqs scorelocally if the file cannot leave your network. - Create a free account at app.interlynk.io and pick the compliance standard you are measured against.
- Create a product and upload a version. Use the web UI,
pylynk upload, or connect GitHub, GitLab, or Bitbucket for automatic ingestion. - Send one supplier SBOM request to see what the collection workflow returns from a real vendor.
- Add
pylynk gateto CI once policies are set, so a failing policy blocks the pull request.
If your code is embedded C/C++, ask for a lynkctl trial and run it on one real firmware project before committing.
When should you use Interlynk?
Interlynk fits teams whose SBOM is a deliverable to a regulator or customer. Medical device makers preparing 524B submissions and manufacturers selling into the EU are the obvious buyers.
It also fits teams that receive SBOMs from many suppliers. The no-account upload link and shared monitoring pipeline handle the collection problem directly.
Embedded teams with Make, CMake, or IAR builds should look at lynkctl. Teams on Keil, Eclipse, or Conan should confirm the support status first, since those are still listed as in the works.
It is a weaker fit for pure application teams that want developer-side fixes. I found no documented function-level reachability analysis or automated dependency-fix pull requests.
If you are still working out what an SBOM must contain, start with my guide on what an SBOM is .
What are the alternatives to Interlynk?
For self-hosted SBOM monitoring, Dependency-Track is the free OWASP option. Anchore offers a commercial SBOM platform built on Syft and Grype, centered on containers.
For firmware you did not build, Finite State analyzes compiled binaries directly. For license-heavy programs, FOSSA focuses on license compliance and attribution.
For free generation, Syft covers containers and filesystems, and cdxgen generates CycloneDX across many languages.
My SBOM tools comparison lines up generators side by side, and the full roster is on the SCA tools page.
What are Interlynk’s strengths and limitations?
Where Interlynk is strong
The SBOM lifecycle is the whole product. Ingestion, repair, scoring, monitoring, VEX, supplier collection, and export live in one place instead of across scripts.
Supplier collection is practical. A no-account upload link with validation addresses the part of SBOM programs that usually stalls.
The open-source tooling is inspectable. sbomqs, sbomasm, and pylynk show how the scoring and API work before you talk to sales.
A free tier exists. Five products with five versions each is enough for a real evaluation before talking to sales.
Where Interlynk falls short
No published paid pricing. Anything beyond 5 products needs a quote, which makes budget comparison hard.
lynkctl coverage is still growing. Keil, Eclipse, vcpkg, Conan, and several microcontroller families are listed as in the works.
No documented reachability or dependency-fix PRs. Prioritization relies on EPSS, KEV, and VEX decisions you record yourself.
Small public footprint. Apart from sbomqs at 308 stars, the repositories have few stars, and most customer evidence comes from vendor press releases.
