Quantify your supply chain risk

Choose the tier that matches your compliance obligations. Every tier runs inside your Splunk environment — no data leaves your network.

The Splunk-native app that unifies SBOM-based software composition analysis (SCA), AI-threat detection, and compliance evidence in one place:

SBOM ingestion Vulnerability correlation Supply-chain risk scoring MITRE ATLAS AI-threat detection Compliance evidence

Every detection is transparent SPL you can open and read, not black-box AI. No external paid security product required. Compliance gap assessment spans nine frameworks: PCI DSS 4.0, NIST CSF 2.0, SOC 2 Type II, HIPAA Security Rule, EU Cyber Resilience Act, FedRAMP / RMF / CISA, DORA, FDA 524B Premarket Cybersecurity, and SEBI CSCRF.

Community
Evaluate the problem
Free
No license key required
  • Pre-loaded CVE correlation against 24+ vulnerability sources via OSV aggregation (including GitHub Advisory Database, NVD, and CISA KEV). Works immediately on install — no internet required.
  • Risk score — current number, with critical/high-severity exposure highlighted
  • Compliance gap assessment (9 frameworks) — see your real gap percentage
  • Long-Unpatched Critical Exposure — flags critical/high vulnerabilities open 180+ days, so long-standing risk doesn't hide in the noise
  • 10 AI/agentic threat detection rules (9 MITRE ATLAS-mapped)
  • AI/LLM telemetry discovery scan — identifies known AI/LLM sourcetypes already present in your environment, with a full 12-platform ingestion guide to get data flowing
  • Cross-SBOM Component Search
  • CycloneDX & SPDX SBOM ingestion
  • Full analysis on your first 5 applications
Install Free on Splunkbase
Federal
Federal compliance evidence on a P-card — under the $15K MPT
$14,500 /year
Email support (48-hr SLA). Priced just under the federal Micro-Purchase Threshold for P-card procurement.
  • Everything in Professional
  • FedRAMP control mapping with evidence
  • Federal compliance evidence — skip the full contracting cycle via P-card, typically saving 6–10 weeks
  • ATO/RMF documentation templates
  • CISA BOD reporting exports
  • FIPS compliance documentation
  • Air-gapped deployment supported
  • IL-compatible deployment guide
Contact for Federal
Enterprise
Operationalize across your security team
$25,000 /year
Priority support (24-hr SLA).
  • Everything in Professional
  • Compound Risk correlation — correlates active AI-threat detections with vulnerable components on the same application, surfacing compounding risk neither signal shows alone
  • Auto-remediation workflow
  • Per-application risk scoring across your SBOM portfolio — replaces 4–8 hours of per-application risk modeling per quarter
  • Silent-Source Detection — flags when a previously-reporting AI/LLM telemetry source goes quiet, closing the blind spot where a silent source looks identical to one with nothing to report
  • AI/ML serialization risk classification — flags models using insecure formats, correlated into the same risk-scoring context as CVE/KEV findings
  • Vendor Risk — per-vendor scoring across your SBOM portfolio
  • Four-eyes enforcement & named-user audit trail
  • Executive & board briefing dashboards
  • Role-based access control (3 roles)
  • API access
Contact for Enterprise
POA&M Generator
Federal Plus
Automated FedRAMP POA&M generation + full operational stack
$35,000 /year
Priority support (24-hr SLA). Available through federal contract vehicles or direct procurement.
  • Everything in Enterprise
  • Everything in Federal
  • POA&M Generator — replaces 15–30 hours of ISSM labor per authorized system, per month
  • Monthly ConMon Package Builder (POA&M + SSP Appendix M Integrated Inventory + Summary)
  • BOD 26-04 risk-tier classification — CISA's four-variable model (public exposure, KEV status, exploit automatability, technical impact) computed per vulnerability, with remediation deadlines and forensic-triage flagging for the highest-risk combinations
  • FedRAMP POA&M Template emission (Excel) — supports both R3.0 (current) and R2.1+2022 (legacy) formats
  • Coverage-Evidence Manifest — AU-12-aligned attestation that AI-monitoring coverage was complete and unbroken over the reporting period, for FedRAMP ConMon evidence packages
  • Named-user audit log for all POA&M edits
  • Deviation Request Form packaging
  • Sticky POA&M ID persistence across regenerations
Contact for Federal Plus

Federal vendor credentials

Active in SAM.gov and CAGE-registered. Verify at SAM.gov using UEI W7BGHT2763E9.

Registration

Legal Business Name GIC Engineering Consultants, Inc.
Unique Entity ID (UEI) W7BGHT2763E9
CAGE Code 239Q9
SAM.gov Status Active

Business Classification

Business Size Small Business
Registration Renewal August 6, 2027
Primary NAICS 541511 — Custom Computer Programming Services
Additional NAICS 541512, 541519, 541690

See what your gap assessment looks like

Download a sample PCI DSS 4.0 gap assessment generated from a real Java web application SBOM. This is the exact output Professional tier customers receive — not a mockup.

Download Sample Report (PDF)

Questions

What happens to my data if I cancel?
Nothing. Your SBOM data, CVE correlation results, and compliance dashboards live entirely in your Splunk environment. GIC Engineering Consultants holds no customer data. If you cancel, the app degrades to Community tier — all your indexed data remains intact and searchable. You keep everything except the paid-tier features.
Can I pay by invoice or ACH instead of credit card?
Yes. Stripe supports ACH bank transfer at checkout. If your organization requires a formal purchase order or NET-30 invoice, email contact@gicengineeringconsultants.com and we'll handle it manually. Federal Plus is available through federal contract vehicles or direct procurement, not via Stripe checkout.
Does the app phone home? We have an air-gapped environment.
No phone-home for license validation. License keys are validated entirely offline using HMAC cryptography — no server contact required. Bundled vulnerability data works immediately on install with no internet connection. Paid tier outbound connections (vulnerability feed updates, CISA KEV, EPSS) are optional and can be disabled for air-gapped deployments. Federal Plus specifically targets on-prem and air-gapped Splunk Enterprise.
Is there a free trial of the paid tier?
The Community Edition is the evaluation — it's free, installs in 5 minutes, and shows you exactly which CVEs you're missing and why your current compliance posture can't be exported to an auditor. Download the sample PCI DSS 4.0 report above to see exactly what the paid export looks like.
What Splunk versions are supported?
Splunk Enterprise 9.2 and above, and Splunk Cloud. Compatible with standalone and distributed deployments (indexer cluster + search head cluster). Splunk Enterprise Security is not required — ES integration is an optional enhancement. Note: the Federal Plus POA&M Generator custom search command targets on-prem and air-gapped Splunk Enterprise only; all other features including the other four tiers run on Splunk Cloud.
How do I find my Splunk GUID?
Run this search in Splunk: | rest /services/licenser/licenses | table machine_GUID — the result is your Machine GUID. Or navigate to Settings → Licensing → License Manager and copy the Master GUID shown at the top. For Splunk Cloud, log in to your admin portal and find it under Settings → Licensing. You'll need this when you purchase a license.
What's the difference between Federal and Federal Plus?
Federal ($14,500/year) is priced just under the $15,000 federal Micro-Purchase Threshold for P-card velocity. It includes Professional baseline plus federal-specific compliance items (ATO/RMF templates, CISA BOD reporting, FedRAMP control mapping, IL deployment, FIPS documentation). It does not include Enterprise operational features like Vendor Risk, RBAC, or API access. Federal Plus ($35,000/year) includes every Enterprise operational feature, every Federal compliance item, and the automated POA&M Generator — a capability that replaces 15–30 hours of ISSM labor per authorized system per month. Federal Plus is available through federal contract vehicles or direct procurement because it is above the Micro-Purchase Threshold.
What does support cover?
SCIP product support covers license key issues, SBOM ingestion failures, CVE correlation errors, and dashboard rendering problems. Splunk environment configuration — sourcetype mapping, index design, infrastructure questions — is outside product support scope. Professional and Federal: 48-hour email response. Enterprise and Federal Plus: 24-hour priority response. Monday–Friday, 9am–6pm Eastern.
Questions? contact@gicengineeringconsultants.com