Research protocol / version 1.0

Methodology

How five products were admitted, compared and described without converting public documentation into a performance benchmark.

Research question

Which documented AIBOM capabilities and operating boundaries should an enterprise team verify before selecting tools for source discovery, model-hub records, agent inventory, standards export, provenance, CI or policy?

Inclusion rule

A candidate had to generate, export or continuously manage an AI-aware bill of materials that includes at least models or AI service identities. A standard without an executable tool was excluded from the five alternatives. Traditional SBOM scanners without documented AI-aware inventory were also excluded.

Why these five tools

The set covers distinct, currently documented jobs: broad open-source discovery, Hugging Face record generation, completeness review, enterprise reporting and policy. The comparison is intentionally not a market census. Snyk, JFrog, Manifest, Wiz, Noma and other platforms may be relevant, but public evidence depth and the fixed five-tool scope required a bounded selection.

Evidence hierarchy

  1. Official product documentation and release notes.
  2. Official source repositories, tags and hosted tool metadata.
  3. Official CycloneDX and SPDX specifications.
  4. Publisher engineering material for operational context, not vendor capability claims.
  5. Competitor pages only for information-gap analysis, never as final product evidence.

Six comparison axes

Discovery
Where the tool looks: source, configuration, model hub, artifact, container, cloud or platform snapshot.
AI coverage
Which models, datasets, prompts, agents, tools, MCP components, services or framework artifacts it records.
Outputs
Machine-readable standards, versions, serialization, validation and merge behavior.
Provenance
Source evidence, hashes, lineage, completeness, claims, attestations and explicit unknowns.
CI/CD
First-party action, template, CLI or API path that can keep the artifact current.
Policy
Thresholds, authorization, triage, suppressions, audit trail or policy-as-code enforcement.

Evidence states

Documented means an official source explicitly establishes the capability at the cutoff. Partial means the capability is narrower than the full axis. Not publicly established means the reviewed sources did not prove it. None of these states measures quality, recall or operational maturity.

No score and no winner

Scores would imply that each axis has a universal weight and that each documentation statement is comparable. Neither is true. A model-hub intake team may value completeness and immutable identity above broad source discovery. A platform team may reverse that priority. The public data therefore preserves evidence states, scenario fit and disqualifiers rather than a composite score.

Verification date and versions

Official sources were checked on . Repository releases and last-update metadata were captured when available. Vendor documentation can change without a versioned URL, so each decision should recheck the cited page.

Context7 limitation

The project instruction requested Context7 for current library and CLI documentation. No Context7 tools were available in the execution environment. The research used the official repositories, release APIs, product documentation and standard specifications as the fallback. No claim is presented as Context7-verified.

Hands-on testing boundary

No candidate was installed or run against a shared fixture. No claim is made about detection recall, false positives, execution speed, scalability, support, pricing, data retention or security. The acceptance tests on the main page are a protocol for the buyer, not completed benchmark results.

Editorial process

AI-assisted drafting was used to organize evidence and prepare prose. The release process includes a claim register, source checks, deterministic content tests, an Ohvat GIST utility audit, an English AI-tells lint and a rendered semantic HTML audit. Independent technical review was not performed.

Conflict and corrections

The publisher provides software engineering and cybersecurity services. None of the five vendors paid for inclusion or reviewed the draft. Corrections require a specific statement, source URL and product version. Material changes are dated in the changelog and reflected in the machine-readable dataset.

Return to the comparison