# Sectrend · 安势信息 - [CleanBinary|二进制成分分析 · 安势信息](https://www.sectrend.com.cn/cleanbinary.html): CleanBinary 是安势信息的二进制成分分析产品,无源码场景下识别交付物与固件中的隐藏组件与风险。 - [CleanCode Security Agent|新一代 AI 代码安全 Agent · 安势信息](https://www.sectrend.com.cn/cleancode.html): CleanCode Security Agent 是安势信息新一代 AI 代码安全 Agent,检测即修复。理解业务逻辑、敏感数据流与权限边界,取代传统 SAST。 - [CleanSource SCA 社区版|轻量、免费、开放的开源安全合规工具 · 安势信息](https://www.sectrend.com.cn/cleansource-ce.html): CleanSource SCA 社区版 是安势信息面向开发者与中小团队的轻量化 SCA,开放 CLI 与部分模块源代码,免费注册即用。 - [CleanSource SCA|软件成分分析与开源合规 · 安势信息](https://www.sectrend.com.cn/cleansource-sca.html): CleanSource SCA 是安势信息的软件成分分析产品,片段级扫描生成可追溯 SBOM,比对 CVE/CNVD/CNNVD/EUVD/CSSA,管控开源许可证风险。 - [下载中心 · 产品资料 | 安势信息](https://www.sectrend.com.cn/downloads.html): 安势信息产品资料下载:CleanSource SCA、CleanCode、CleanBinary、PureStream、SkillSec 产品介绍 PDF。 - [Air-Gapped SCA: Open Source Governance Without Internet | Sectrend](https://www.sectrend.com.cn/en/airgapped-sca.html): How to run software composition analysis in air-gapped and isolated environments: internal registry mirrors, offline vulnerability intelligence, and intake allowlisting. - [CleanBinary|Binary Composition Analysis · Sectrend](https://www.sectrend.com.cn/en/cleanbinary.html): CleanBinary is Sectrend's binary composition analysis product, surfacing hidden components and risk in delivery artifacts and firmware when no source is available. - [CleanCode Security Agent|Next-gen AI Code Security Agent · Sectrend](https://www.sectrend.com.cn/en/cleancode.html): CleanCode Security Agent is Sectrend's next-generation AI code security agent — detect and fix in the same moment. Understands business logic, data flows, and permission boundaries. Replaces legacy SAST. - [CleanSource SCA Community Edition|Lightweight, Free, Open SCA · Sectrend](https://www.sectrend.com.cn/en/cleansource-ce.html): CleanSource SCA CE is Sectrend's lightweight SCA for developers and small teams — open CLI and partial source, free on sign-up. - [CleanSource SCA|Software Composition Analysis & Open-Source Compliance · Sectrend](https://www.sectrend.com.cn/en/cleansource-sca.html): CleanSource SCA is Sectrend's software composition analysis product: snippet-level scanning generates traceable SBOMs, maps CVE/CNVD/CNNVD/EUVD/CSSA, and governs open-source license risk. - [Download Center · Product Materials | Sectrend](https://www.sectrend.com.cn/en/downloads.html): Download Sectrend product materials: CleanSource SCA, CleanCode, CleanBinary, PureStream and SkillSec PDFs. - [GPL vs LGPL vs AGPL: Copyleft Licenses Compared | Sectrend](https://www.sectrend.com.cn/en/gpl-vs-lgpl-vs-agpl.html): The practical differences between GPL, LGPL and AGPL: what triggers copyleft obligations, linking rules, the SaaS loophole, and how enterprises manage each. - [How to Choose an SCA Tool: Evaluation Guide & Checklist | Sectrend](https://www.sectrend.com.cn/en/how-to-choose-an-sca-tool.html): A practical evaluation framework for SCA tools: detection depth, data quality, false-positive governance, engineering fit and compliance output — plus a POC checklist. - [Sectrend|Software Supply Chain Security for the AI Era](https://www.sectrend.com.cn/en/): Sectrend is an AI + software supply chain security provider. Core products CleanCode Security Agent, CleanSource SCA, and SkillSec cover risk across source, components, binaries, and AI Agents. - [Automotive Software Supply Chain Security | ISO 21434 & SBOM Compliance · Sectrend](https://www.sectrend.com.cn/en/industry-automotive.html): Software supply chain security for the automotive industry: meeting ISO/SAE 21434, UN R155/R156 and EU CRA requirements across source code, open source components and binary deliverables from OEM to Tier-N, with traceable SBOMs and audit-ready records. - [Software Supply Chain Security for Internet & ICT | Open Source Governance at Release Velocity · Sectrend](https://www.sectrend.com.cn/en/industry-internet.html): Software supply chain security for internet and ICT companies: matching high-frequency release cadence, governing tens of thousands of open source dependencies, securing AI-assisted development, and meeting both domestic and export compliance requirements. - [Software Supply Chain Security for Smart Devices & Advanced Manufacturing | Firmware Composition and Export Compliance · Sectrend](https://www.sectrend.com.cn/en/industry-manufacturing.html): Software supply chain security for smart device and advanced manufacturing companies: governing composition risk across embedded firmware and multi-tier supplier deliverables, supporting compliance review at SKU scale and SBOM delivery for global markets. - [Supply Chain Security for Semiconductor & Infrastructure Software | Composition Transparency for SDKs and Distributions · Sectrend](https://www.sectrend.com.cn/en/industry-semiconductor.html): Supply chain security for semiconductor and infrastructure software vendors: establishing composition transparency for chip SDKs, drivers, toolchains and OS distributions, producing SBOMs and license evidence deliverable to downstream customers. - [MCP Security: Risks and an Adoption Checklist | Sectrend](https://www.sectrend.com.cn/en/mcp-security.html): Model Context Protocol security explained: why MCP servers are a new supply chain surface, how prompt injection reaches agent tool-calls, and a pre-adoption audit checklist. - [Software Supply Chain Security Glossary & FAQ | Sectrend](https://www.sectrend.com.cn/en/oss-101.html): Clear, practical explanations of open source security, SBOM, SCA, software supply chain risk and AI agent security. - [PureStream|AI Compliance Governance Platform · Sectrend](https://www.sectrend.com.cn/en/purestream.html): PureStream is Sectrend's AI compliance governance platform, unifying governance of model dependencies, data flows, and Agent-workflow risk. - [SBOM Requirements in 2026: EO 14028, EU CRA, FDA | Sectrend](https://www.sectrend.com.cn/en/sbom-requirements.html): Which regulations actually require SBOMs — US Executive Order 14028, the EU Cyber Resilience Act, FDA premarket guidance — who they apply to, and how to prepare. - [SCA vs SBOM: What's the Difference? | Sectrend](https://www.sectrend.com.cn/en/sca-vs-sbom.html): SCA is the analysis engine; SBOM is the inventory it produces. How the two relate, where each fits, and why you need both for supply chain security. - [SkillSec|AI Skill Security Intelligence · From Malware Detection to Capability Auditing · Sectrend](https://www.sectrend.com.cn/en/skillsec.html): SkillSec is Sectrend's AI Skill security intelligence platform, elevating Skill security from malware detection to capability auditing. Three-tier verdicts; evidence chains down to the SKILL.md line. - [SPDX vs CycloneDX: Which SBOM Format to Use | Sectrend](https://www.sectrend.com.cn/en/spdx-vs-cyclonedx.html): A practical comparison of the two SBOM standards: origins, strengths, ecosystem support, and how to choose — or support both. - [Trust & Credentials · Sectrend](https://www.sectrend.com.cn/en/trust.html): Sectrend's certifications, memberships, ecosystem partnerships and company background: OpenChain's first APAC tool-vendor partner, Shanghai Innovation Product Catalog, on-premises delivery. - [What is an SBOM? Software Bill of Materials Explained | Sectrend](https://www.sectrend.com.cn/en/what-is-an-sbom.html): What a Software Bill of Materials is, what the CISA minimum elements require, SPDX vs CycloneDX formats, and how to generate SBOMs that stay accurate. - [What is SCA? Software Composition Analysis Explained | Sectrend](https://www.sectrend.com.cn/en/what-is-sca.html): What Software Composition Analysis (SCA) is, how it works, snippet-level vs manifest scanning, and how to evaluate SCA tools for license compliance and vulnerability management. - [CleanBinary|二進制成分分析 · 安勢信息](https://www.sectrend.com.cn/hk/cleanbinary.html): CleanBinary 是安勢信息的二進制成分分析產品,無源碼場景下識別交付物與固件中的隱藏組件與風險。 - [CleanCode Security Agent|新一代 AI 代碼安全 Agent · 安勢信息](https://www.sectrend.com.cn/hk/cleancode.html): CleanCode Security Agent 是安勢信息新一代 AI 代碼安全 Agent,檢測即修復。理解業務邏輯、敏感數據流與權限邊界,取代傳統 SAST。 - [CleanSource SCA 社區版|輕量、免費、開放的開源安全合規工具 · 安勢信息](https://www.sectrend.com.cn/hk/cleansource-ce.html): CleanSource SCA 社區版 是安勢信息面向開發者與中小團隊的輕量化 SCA,開放 CLI 與部分模塊源代碼,免費註冊即用。 - [CleanSource SCA|軟件成分分析與開源合規 · 安勢信息](https://www.sectrend.com.cn/hk/cleansource-sca.html): CleanSource SCA 是安勢信息的軟件成分分析產品,片段級掃描生成可追溯 SBOM,比對 CVE/CNVD/CNNVD/EUVD/CSSA,管控開源許可證風險。 - [下載中心 · 產品資料 | 安勢信息](https://www.sectrend.com.cn/hk/downloads.html): 安勢信息產品資料下載:CleanSource SCA、CleanCode、CleanBinary、PureStream、SkillSec 產品介紹 PDF。 - [安勢信息 Sectrend|AI 時代的軟件供應鏈安全](https://www.sectrend.com.cn/hk/): 安勢信息是 AI+軟件供應鏈安全治理解決方案提供商。核心產品 CleanCode Security Agent、CleanSource SCA、SkillSec,覆蓋源碼、組件、二進制到 AI Agent 的全棧風險。 - [汽車行業軟件供應鏈安全解決方案|ISO 21434 與 SBOM 合規 · 安勢信息](https://www.sectrend.com.cn/hk/industry-automotive.html): 面向汽車行業的軟件供應鏈安全方案:滿足 ISO/SAE 21434、UN R155/R156 與歐盟 CRA 要求,覆蓋 OEM 到 Tier-N 的源碼、開源組件與二進制交付物,構建可追溯的 SBOM 與合規台賬。 - [互聯網與 ICT 行業軟件供應鏈安全解決方案|高頻迭代下的開源治理 · 安勢信息](https://www.sectrend.com.cn/hk/industry-internet.html): 面向互聯網與 ICT 行業的軟件供應鏈安全方案:適配高頻發佈節奏,治理萬級開源依賴,護航 AI 輔助開發,滿足等保 2.0 與出海合規要求。 - [智能終端與高端製造軟件供應鏈安全解決方案|固件成分與出海合規 · 安勢信息](https://www.sectrend.com.cn/hk/industry-manufacturing.html): 面向智能終端與高端製造行業的軟件供應鏈安全方案:治理嵌入式固件與多級供應商交付物的成分風險,支撐海量 SKU 的合規審查與出海 SBOM 交付要求。 - [半導體與基礎軟件行業供應鏈安全解決方案|SDK 與發行版的成分透明 · 安勢信息](https://www.sectrend.com.cn/hk/industry-semiconductor.html): 面向半導體與基礎軟件行業的供應鏈安全方案:為芯片 SDK、驅動、工具鏈與操作系統發行版建立成分透明能力,輸出可向下游客户交付的 SBOM 與許可證證明。 - [SBOM、SCA 與開源軟件供應鏈安全指南 | 安勢信息](https://www.sectrend.com.cn/hk/oss-101.html): 解答企業在軟件採購、開源元件管理、漏洞應對及 SBOM 導入方面的常見問題。 - [PureStream|AI 合規治理平台 · 安勢信息](https://www.sectrend.com.cn/hk/purestream.html): PureStream 是安勢信息的 AI 合規治理平台,統一納管模型依賴、數據流向與 Agent 工作流中的安全風險。 - [SkillSec|AI Skill安全情報平台 · 從惡意檢測到能力審計 · 安勢信息](https://www.sectrend.com.cn/hk/skillsec.html): SkillSec 是安勢信息的 AI Skill安全情報平台,把 Skills 安全從惡意檢測升維到能力審計。三級判定、證據鏈精確到 SKILL.md 行號。 - [資質與認證 · 安勢信息](https://www.sectrend.com.cn/hk/trust.html): 安勢信息的權威認證、行業會員、生態合作與公司背景:OpenChain 亞太首個工具廠商會員、上海安勢信息技術有限公司 · 中國上海