At the Open Source Summit in Minneapolis, I sat down with Harry Zorn, co-founder of Exodos Labs, to talk about the growing SBOM deluge in software supply chain security and how Exodos is trying to address it. Spoiler alert: Instead of treating the SBOM as the end of the process, Exodos treats it as the starting point for software supply chain security.
What an SBOM brings
A software bill of materials, or SBOM, is typically generated as part of the build and release process and is essentially an inventory of the components inside a piece of software. It can help companies identify risks before software ships, as well as risks in software they purchase or use. But the SBOM itself is still largely an inventory. The real value comes from analyzing that information, keeping it current, and turning it into something a security or compliance team can act on.
The problem is…
That is where the challenge starts. Someone still has to review the SBOM, determine which vulnerabilities or licensing issues actually matter, and decide what to do about them. This is particularly difficult for security teams already struggling to keep up with the growing volume of code being shipped by developers, especially with the help of AI. That is the problem Exodos Labs is trying to address.

Harry’s background and where the idea came from
Harry has spent more than 35 years in cybersecurity, including building his own company and later taking on senior roles at Accellion, now Kiteworks, and JFrog. It was at JFrog that he kept hearing customers ask for better ways to ingest, analyze, manage, and securely share their SBOMs. That experience led him to start Exodos.
Exodos’s approach and how it’s different
What Exodos does differently is use SBOM generation as the starting point for a broader software supply chain security process. Exodos also doesn’t just take SBOMs from a company’s own builds; it can request them from suppliers and manage that flow. It analyzes what is in the software and tracks vulnerabilities, licenses, maintainers, and supplier risk. Rather than leaving that information in static reports, Exodos exposes it through an MCP server so an LLM can answer plain-language questions about the supply chain.
Harry gives the example of an automaker comparing several brake suppliers and asking which one creates the most security or compliance burden.
A broader pattern: automate the analysis, not the judgment
The broader idea is straightforward: let machines handle the volume and surface the issues while people make the decisions. As with AI more broadly, the goal is to automate the repetitive analysis while keeping judgment and decision-making with humans.
Chapters
- 0:00 Intro from the Open Source Summit in Minneapolis
- 0:30 Harry’s path: 35 years in cybersecurity, founding his first company at 25 and growing it to 90 people in 10 countries
- 1:15 After the acquisition: running Europe for Accellion (now Kiteworks), then an Israeli binary-analysis startup that JFrog acquired
- 2:30 The unmet need at JFrog: customers wanted to ingest, analyze, share, and secure their SBOMs
- 3:15 Why the name Exodos: the SBOM is generated at the exit of the SDLC, and Exodos makes it the starting point
- 3:55 Eight angel investors across the US, Israel, and Germany
- 4:15 Agents need solid data to make solid security decisions
- 4:45 Developers ship 10x faster, but security, legal, and compliance teams didn’t scale
- 5:05 The MCP server: point an LLM at Exodos and ask which brake vendor to buy from next
- 6:00 Where the company is headed
- 6:15 Software supply chain security as national security: 30+ regulations and the vision of SBOMs feeding a national SOC
- 8:00 Wrap
Pau for now…

Leave a Reply