Entities & Vendors

Analyst Toolkit

Revealing who is behind every resource

Enrichment resolves observed domains to companies, software products and the individuals connected to them, then flags the parties themselves: ownership, control, sanctions, jurisdiction.

Every other section deals in domains, addresses and files. This one deals in organizations. Backed by nDiligence profiles, it cross-references everything observed in your traffic against SCVue's intelligence catalog and marks which entities are actually present in the traffic you are looking at, as opposed to merely existing in the catalog. The companies operating behind one application, by country and by role.

SCVue entities report resolving observed domains to the companies that operate them, with country, category and role for each.
Domains resolved to organizations, with home country, category, role, and presence in this capture.

Integrated Reports

  • Influence Factors

    The section's headline report: red flags about who has influence over your supply chain, grouped by type and severity. Jurisdictions that create exposure, dependencies with a compromise history, parties performing cross-site tracking, and concentration on a single vendor. Each states what was found and why it matters, and a factor whose entity appears in your current traffic is marked as active exposure rather than background information.

  • Companies / Organizations

    The corporate catalog: every company identified in the supply chain, its role in the chain, and the domains it operates, with the ones observed in your current traffic marked. A hostname in your traffic becomes a corporation with a name, a home country, and a data relationship with you.

  • Individuals

    Key people connected to the entities in the supply chain, their role and country, and the company they are linked to. An individual is flagged in scope when their company's infrastructure appears in your traffic, which supports beneficial ownership and PEP checks against the suppliers you actually use.

  • Software Products / Libraries

    The software catalog: the specific products, libraries, frameworks, development kits and services identified in the supply chain, with each one's vendor, versions and license. This is your software bill of materials for the browser-side supply chain, derived from what was actually loaded, not from what a build file claims.

  • Software Languages

    The programming languages represented across the software catalog, with the count of products in each. A quick read on the technology composition of your supply chain, and a useful input when deciding which vulnerability feeds and which skills apply to you.

  • Licenses

    The license posture of the supply chain: every software license found, and which products carry it. Open source obligations attach to organizations that redistribute software, and license categories differ substantially in what they demand. This report identifies what you are actually subject to.

  • Sanctions / Politically Exposed Persons (PEPs)

    Sanctions and PEP screening of the supply chain, with entities present in your current traffic flagged as active exposure and a plain count of how many sanctioned entities are in scope. For most organizations this is the highest-stakes report in the product. Sanctions exposure through a third-party script is exposure nonetheless, and it is not something a vendor questionnaire will surface.

One capture is enough to start

Capture a session in the browser, import it, and read what comes back. A free community account is available immediately.