Inside the app
A closer look.








About this app
Made for a clear purpose.
Dependquarry is a private software-bill-of-materials review bench for developers, maintainers, auditors, consultants, and small security teams who need a human-readable decision layer without uploading product composition.
Turn machine-oriented SBOM records into an offline, accountable component review with explicit evidence gaps.
KEY FEATURES - CycloneDX and SPDX JSON import - Component and evidence register - Severity and dependency-depth screen - Package URL and provenance notes - Reachability and disposition workflow - License evidence tracking - Portable component decision artifact - No source-code or SBOM upload - Native structured-file or CSV import - Local PDF, workspace JSON, and domain-artifact export - 48 original offline technical reference plates - No account, ads, analytics, tracking, IAP, or subscription
Dependquarry interprets imported component metadata and user-entered findings; it does not fetch advisories, prove exploitability, determine legal obligations, or certify a product. Verify package identity, versions, reachability, licenses, provenance, and current advisories with accountable experts.