# Sourcewheel

*/Startups/Sourcewheel*

## Startup Overview

Software engineering and security teams face persistent supply chain vulnerabilities due to opaque code dependencies. This system traces and verifies the exact lineage of every digital component entering a codebase. It builds a continuous map of software provenance, replacing manual audits with immediate visibility.

Legacy alternatives like Snyk and Black Duck rely on point-in-time scanning, while manual SBOM generation leaves dangerous gaps in active development cycles. This architecture operates entirely in real-time, instantly validating every pulled dependency and nested module. Every verified component is backed by deterministic cryptographic evidence, ensuring developers deploy only code with a mathematically proven, untampered origin.

## Startup Founding Hypothesis

**Approach**: that traces and verifies digital component lineage
**Competitors**:
- [Snyk](/Competitors/Snyk)
- [Black Duck](/Competitors/Black_Duck)
- [Manual SBOM generation](/Competitors/Manual_SBOM_generation)
**Differentiator2x2**: fully automated in real-time and backed by deterministic cryptographic evidence

## Startup Solution Coordinate

**Solution**: [Provenance Engine](/Software/Provenance_Engine)

## Startup Position2x2

```mermaid
quadrantChart
    title Component Lineage Verification
    x-axis Manual / Batch Scanning --> Automated Real-time
    y-axis Heuristic Analysis --> Deterministic / Cryptographic
    quadrant-1 Cryptographic Automation
    quadrant-2 Cryptographic Batch
    quadrant-3 Manual Heuristics
    quadrant-4 Automated Heuristics
    Manual SBOM generation: [0.15, 0.20]
    Black Duck: [0.45, 0.35]
    Snyk: [0.85, 0.45]
    Sourcewheel: [0.90, 0.90]
```

## Startup Offer

**Proof**:
- Aiming to reduce manual SBOM compilation time from days to seconds for security engineering teams.
- Targeting 100% deterministic traceability for standard npm, PyPI, and Maven component trees.
- Designed to automatically produce evidence that meets strict federal software supply chain audit standards.
**Tiers**:
- Name: Startup Core · Price: ~$100–$250/mo · Inclusions: Automated SBOM generation, public registry tracing, and deterministic cryptographic signing for up to 500 automated builds per month.
- Name: Platform Scale · Price: ~$800–$1,500/mo · Inclusions: Real-time lineage tracing, custom internal registry support, and continuous compliance reporting for up to 5,000 builds per month.
- Name: Enterprise Lineage · Price: ~$3,000–$6,000/mo · Inclusions: Dedicated tenant environments, intended SIEM integrations, and unbounded cryptographic verification for global engineering teams.
**Guarantee**: If a Sourcewheel-generated SBOM fails an external compliance audit due to missing or inaccurate cryptographic evidence, our team will manually map and verify the contested lineage at zero cost.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: We already rely on Snyk or Black Duck. Rebuttal: Sourcewheel complements vulnerability scanners by replacing probabilistic scanning with deterministic, cryptographically signed evidence for zero-ambiguity lineage.
- Objection: Adding another tool will slow down our CI/CD pipelines. Rebuttal: The tracing engine runs concurrently during the build phase and is designed to add sub-second overhead.
- Objection: How does this handle closed-source or internal packages? Rebuttal: Teams can configure internal namespaces that Sourcewheel signs and traces without exposing proprietary code to external registries.
**Pricing Architecture**: Tiered
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical and authoritative, delivering deterministic facts without marketing embellishment.
**Tagline**: Real-time cryptographic proof for your digital component lineage.
**Icon Concept**: barcode
**Palette Intent**: electric-signal
**Visual Identity**: High-contrast neon green and stark black define a clinical, monospace-heavy aesthetic that mirrors terminal environments and cryptographic hashes.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: Sourcewheel → DevSecOps Engineer → Enterprise Security Organization
**Gtm Motion**: Sourcewheel acquires users via a freemium CI/CD plugin that automates local component tracing for individual developers, expanding to enterprise contracts when security leaders mandate fleet-wide cryptographic SBOM compliance.
**Agent Channel**: Designed to list in AI agent tool registries like the LangChain integrations hub and autonomous developer ecosystems, allowing AI coding agents to call the API to verify library lineage before committing code.
**Primary Channel**: Discovery via the GitHub Actions Marketplace and GitLab Integration directory when DevOps engineers search for automated SBOM generation and supply chain provenance workflows.

## Startup Customer Journey

```mermaid
flowchart LR;A[GitHub Actions Marketplace]-->B[Freemium CI Plugin];B-->C[Cryptographic SBOM];C-->D[CI Pipeline];D-->E[Enterprise Security Organization];E-->F[SIEM Integration];F-->G[Federal Audit Standard];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day parallel run in a staging CI/CD environment to prove the automated engine generates accurate, cryptographically signed SBOMs for 500 builds with sub-second latency.
- 30-day compliance trial with a government contractor to map existing PyPI and Maven dependencies and generate a complete lineage report that passes a mock federal supply chain audit.
**Target Metrics**:
- Target: Under 1 second of added latency to existing CI/CD build pipelines
- Aim: 100 percent deterministic cryptographic verification for standard npm, PyPI, and Maven component trees
- Target: Reduction from multiple days to under 10 seconds for comprehensive SBOM generation and compliance reporting
**Target Case Studies**:
- Mid-sized fintech provider: Transition from manual weekly software bill of materials compilation to automated deterministic signing on every build, passing compliance audits without dedicated security engineering hours.
- Federal software contractor: Achieve 100 percent deterministic traceability for internal and external component trees, automatically producing evidence that meets strict federal software supply chain audit standards.
- High-growth SaaS platform: Integrate the tracing engine into existing CI/CD pipelines alongside probabilistic scanners, reducing lineage tracing overhead to sub-second durations while maintaining custom internal registry support.
**Testimonial Targets**:
- Chief Information Security Officer at a regulated enterprise expressing confidence that zero-ambiguity lineage proofs easily pass external compliance audits.
- Lead DevOps Engineer validating that the tracing engine runs concurrently during the build phase without slowing down daily deployment velocity.
- Security Engineering Director confirming that internal proprietary packages remain secure and unexposed while still receiving full cryptographic signing.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Major package ecosystems like npm and PyPI natively enforce cryptographic provenance, eliminating the need for a standalone third-party verification tool. · Mitigation Status: unmitigated
- Severity: high · Description: Cryptographic verification overhead slows down developer CI/CD pipelines, causing engineering teams to bypass the tool entirely. · Mitigation Status: in-progress
- Severity: high · Description: Incumbent security platforms like Snyk bundle real-time SBOM generation into their existing enterprise contracts, blocking new market entry. · Mitigation Status: unmitigated
- Severity: moderate · Description: Legacy enterprise build environments lack the deterministic properties required to generate verifiable cryptographic evidence. · Mitigation Status: in-progress
- Severity: low · Description: Open-source package maintainers frequently change metadata schemas, requiring constant maintenance of the parsing engine to prevent false alerts. · Mitigation Status: mitigated

## Startup Competitors

- [Snyk](/Competitors/Snyk) — Incumbent
- [Black Duck](/Competitors/Black_Duck) — Legacy Vendor
- [Manual SBOM Generation](/Competitors/Manual_SBOM_Generation) — Status Quo
- [Chainguard Enforce](/Competitors/Chainguard_Enforce) — Supply Chain Security
- [Endor Labs](/Competitors/Endor_Labs) — Dependency Risk

## Startup Solution Stack

- [Cryptographic Audit Service](/Services/Cryptographic_Audit_Service) — Service-as-Software
- [Lineage Tracing Agent](/Agents/Lineage_Tracing_Agent) — Agent
- [Evidence Verification Worker](/Agents/Evidence_Verification_Worker) — Agent
- [Provenance Graph Engine](/Software/Provenance_Graph_Engine) — Software
- [SBOM Integration API](/Software/SBOM_Integration_API) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the architect of a provable software supply chain
- **Want**: to provide zero-ambiguity software lineage for every production build
- **Identity**: the security engineering lead at a high-growth software company
**Plan**:
- Step: Define namespaces · Detail: Set your internal and public registries to establish the boundary for automated tracing.
- Step: Audit builds · Detail: Sourcewheel automatically traces component lineage and signs the evidence during every Jenkins or GitHub Action run.
- Step: Export evidence · Detail: Download deterministic compliance reports that meet federal audit standards with zero manual mapping.
**Guide**:
- **Empathy**: You shouldn't still be manually verifying component hashes. Snyk wasn't built to provide deterministic cryptographic evidence of lineage.
**Problem**:
- **Villain**: probabilistic scanning
- **External**: Generating a valid SBOM manually or via Black Duck requires days of forensic cleanup across npm, PyPI, and Maven trees.
- **Internal**: You feel exposed during audits because your security tools guess at component origins instead of proving them.
- **Philosophical**: Every engineering lead deserves absolute mathematical certainty — not best-guess vulnerability reports.
**Success**: Every build is backed by a deterministic, signed manifest that survives the toughest security audits with zero manual intervention.
**One Liner**: Every build, security leads struggle with incomplete software manifests. Sourcewheel automates cryptographic lineage tracing so you ship with zero-ambiguity compliance evidence.
**Positioning**:
- **So That**: replace manual SBOM generation with signed cryptographic evidence
- **Unlike**: probabilistic vulnerability scanners
- **For Whom**: security engineering leads
- **Category**: Deterministic Lineage Tracing
**Call To Action**:
- **Direct**: Generate signed SBOM
- **Transitional**: View sample cryptographic lineage
**Failure Stakes**:
- Failed compliance audits
- Undetected supply chain attacks
- Days lost to manual mapping
**Transformation**:
- **To**: the architect who delivers cryptographically provable software
- **From**: the lead engineer buried in Black Duck false positives
**Controlling Idea**: Software lineage should be a deterministic mathematical fact, not a probabilistic scan.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Every build, security leads struggle with incomplete software manifests. Sourcewheel automates cryptographic lineage tracing so you ship with zero-ambiguity compliance evidence.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: b77c0be27d2d8421

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Deterministic Lineage Tracing for security engineering leads. Unlike probabilistic vulnerability scanners — replace manual SBOM generation with signed cryptographic evidence.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: ffc742c7ee972c0e

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Generating a valid SBOM manually or via Black Duck requires days of forensic cleanup across npm, PyPI, and Maven trees.
Solution: Every build, security leads struggle with incomplete software manifests. Sourcewheel automates cryptographic lineage tracing so you ship with zero-ambiguity compliance evidence.
Customer: security engineering leads
Unlike: probabilistic vulnerability scanners
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 4d7d9de43e997be2

## Startup Token M E D D P I C C

**Pain**: Generating a valid SBOM manually or via Black Duck requires days of forensic cleanup across npm, PyPI, and Maven trees.
**Metrics**: Target: Every build is backed by a deterministic, signed manifest that survives the toughest security audits with zero manual intervention.
**Rendered**: Pain: Generating a valid SBOM manually or via Black Duck requires days of forensic cleanup across npm, PyPI, and Maven trees.
Economic buyer: DevSecOps Engineer
Metrics: Target: Every build is backed by a deterministic, signed manifest that survives the toughest security audits with zero manual intervention.
Competition: probabilistic vulnerability scanners
**Mechanism**: spine-derived-v1
**Competition**: probabilistic vulnerability scanners
**Economic Buyer**: DevSecOps Engineer
**Vocab Fingerprint**: 7ba4b51ced05b524

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Deterministic Lineage Tracing for security engineering leads

security engineering leads — Generating a valid SBOM manually or via Black Duck requires days of forensic cleanup across npm, PyPI, and Maven trees. Every build, security leads struggle with incomplete software manifests. Sourcewheel automates cryptographic lineage tracing so you ship with zero-ambiguity compliance evidence.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 2485f93700c3a11a

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Deterministic Lineage Tracing. Every build, security leads struggle with incomplete software manifests. Sourcewheel automates cryptographic lineage tracing so you ship with zero-ambiguity compliance evidence. Serves security engineering leads.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 7d00d9153a770fdd

## Neighborhood

### Candidate solutions

- [Unbillable Tax Data Extraction](/Problems/Unbillable_Tax_Data_Extraction) — candidate solution for · Problems

### Composed of

- [Lineage Tracing Agent](/Agents/Lineage_Tracing_Agent) — composes · Agents
- [Evidence Verification Worker](/Agents/Evidence_Verification_Worker) — composes · Agents
- [SBOM Integration API](/Software/SBOM_Integration_API) — composes · Software
- [Provenance Graph Engine](/Software/Provenance_Graph_Engine) — composes · Software
- [Cryptographic Audit Service](/Services/Cryptographic_Audit_Service) — composes · Services

### Competitors

- [Endor Labs](/Competitors/Endor_Labs) — competes with · Competitors
- [Snyk](/Competitors/Snyk) — competes with · Competitors
- [Black Duck](/Competitors/Black_Duck) — competes with · Competitors
- [Manual SBOM Generation](/Competitors/Manual_SBOM_Generation) — competes with · Competitors
- [Chainguard Enforce](/Competitors/Chainguard_Enforce) — competes with · Competitors

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### What it offers

- [Provenance Engine](/Software/Provenance_Engine) — offers · Software

### Similar Startups

- [Apexorigin](/Startups/Apexorigin) — similar · Startups
- [Veruilt](/Startups/Veruilt) — similar · Startups
- [Autaph](/Startups/Autaph) — similar · Startups
- [Wintrust](/Startups/Wintrust) — similar · Startups
- [Registryard](/Startups/Registryard) — similar · Startups
- [Weavegrove](/Startups/Weavegrove) — similar · Startups
- [Arborforge](/Startups/Arborforge) — similar · Startups
- [Boundoreman](/Startups/Boundoreman) — similar · Startups
- [Houndaga](/Startups/Houndaga) — similar · Startups
- [Verench](/Startups/Verench) — similar · Startups
- [Attategic](/Startups/Attategic) — similar · Startups
- [Sourcenith](/Startups/Sourcenith) — similar · Startups
- [Fusyard](/Startups/Fusyard) — similar · Startups
- [Registrymuse](/Startups/Registrymuse) — similar · Startups
- [Sourcycle](/Startups/Sourcycle) — similar · Startups
- [Anvilhaven](/Startups/Anvilhaven) — similar · Startups
- [Nodehazard](/Startups/Nodehazard) — similar · Startups
- [Codedepot](/Startups/Codedepot) — similar · Startups
- [Traceabilitycrest](/Startups/Traceabilitycrest) — similar · Startups
- [Figis](/Occupations/Software_Developers/Problems/Software_Vulnerability_Remediation/Startups/Figis) — similar · Startups
