Vendor Discovery
Every vendor, host, and service the app actually loads, resolved to real companies and products.
Illuminating the internet supply chain operating within your application.
Modern web apps assemble themselves at runtime from code, media, and data served by dozens of third-party vendors, almost none of it visible to the owner, and none of it to the user. SBOMs and vendor questionnaires describe what should load. SCVue™ shows you the facts: every vendor, every resource, every outbound payload, captured and analysed as evidence.
Modern web applications are commonly assembled from parts supplied by other people. A single page load can quietly reach out to dozens of other companies: an analytics provider, an advertising network, a font service, a video player, a chat widget, a payment processor, a content delivery network, a fraud detection service. Each of those is a supplier. Each is a place where data can leave, where code you did not write can run, and where a problem in someone else's business becomes a problem in yours.
That collection of suppliers is your digital supply chain, and for most organisations it is invisible. Your supply chain is not only the vendors you contracted. It is the code you maintain and the technology integration partners you build on, together with everything they load in turn.
SCVue™ is about knowing and identifying the technology dependencies inside your applications.
By examining their code, resources, data, and runtime network communication, you can see what your sites and apps really do, who they depend on from both a technology and a third-party integration standpoint, and where risk enters your supply chain.
Every vendor, host, and service the app actually loads, resolved to real companies and products.
What the code really does: scripting, tracking, fingerprinting, and outbound payloads.
Every resource content-addressed by SHA-256 and validated as known, trusted code.
Scheduled recaptures detect any change and raise alerts the moment behaviour shifts.
SCVue helps people and organisations run comprehensive, continuous monitoring across a wide range of specialties and industries. It is a robust tool for organisations managing their own applications and internal portals, and it supports integration providers just as fully, whether they rely partly or entirely on third-party vendors.
Vetting, risk assessment, background and screening, audit and review.
Across the technology and software products you depend on, and the people who impact them, through all five classes of supply chain: people, knowledge, financial, digital, and physical.
For possible partnership, acquisition, competitive analysis, vulnerabilities, or dependencies.
The measurement works from the outside, with no source code and nothing to install, whether the work is commissioned by the company or carried out independently.
Organisations managing or overseeing multiple sites that service the public domain.
Validating the trustworthiness of a web-based product.
Compliance with legal terms, GDPR, flow-down clauses, and jurisdictions.
Knowing and documenting your third-party dependencies, SBOM style work.
Validating that services and behaviour run as designed and developed.
Understanding third-party risk in technology supply chains.
It is built with intent, to confirm the application is performing as expected without a narrowed view. We have a ten analysis engine process, with comparison modeling, vendor discovery, continuous monitoring, and influence factor flagging. Performing only one or a couple of these processes can leave a blind spot in the future.
Reports what code and traffic are observed to do, never what a manifest declares.
Compare any report across time, capture context, and page.
Is the code risky? Are the parties behind it flagged?
A local, private workspace keeps all data in the browser. Cloud storage receives only data whose POST payloads have been scrubbed of PII.
Getting started with the Community edition is easy. When your needs develop further, or you have a harder problem to solve, or a big organisation to support, we have flexible options to help. Not only do we have advanced technology options, we also have reach-back support for your hardest challenges.
Import a HAR capture, or let SCVue capture remotely from real browsers on real devices in cities worldwide, with scripted interaction.
One deduplicated data model across apps, versions, collections, views, and calls.
Ten engines profile code, traffic, payloads, media, entities, and infrastructure.
Dashboards, baselines, deltas, and alerts in a comprehensive Analyst Toolkit.
Start free with Community, or ask us for a guided demo on your own portfolio.
SCVue is built by nDiligence, which uses it on its own investigations. SCVue puts the measurement in your hands; when a question outgrows a capture, Digital Supply Chain and Equity Chain Mapping take it further.