Internet Supply Chain Intelligence

Illuminating the internet supply chain operating within your application.

Modern web apps assemble themselves at runtime from code, media, and data served by dozens of third-party vendors, almost none of it visible to the owner, and none of it to the user. SBOMs and vendor questionnaires describe what should load. SCVue™ shows you the facts: every vendor, every resource, every outbound payload, captured and analyzed as evidence.

The SCVue interactive supply chain graph: one source domain at the center, with first-party and third-party relationships radiating outward for a single page load.
The interactive supply chain graph: source, first-party, and third-party relationships for a single page load. Click any node for its calls, assets, owning company, and intelligence profile.
Supply chain integrity

Modern web applications are commonly assembled from parts supplied by other people. A single page load can quietly reach out to dozens of other companies: an analytics provider, an advertising network, a font service, a video player, a chat widget, a payment processor, a content delivery network, a fraud detection service. Each of those is a supplier. Each is a place where data can leave, where code you did not write can run, and where a problem in someone else's business becomes a problem in yours.

That collection of suppliers is your digital supply chain, and for most organizations it is invisible. Your supply chain is not only the vendors you contracted. It is the code you maintain and the technology integration partners you build on, together with everything they load in turn.

SCVue™ is about knowing and identifying the technology dependencies inside your applications.

By examining their code, resources, data, and runtime network communication, you can see what your sites and apps really do, who they depend on from both a technology and a third-party integration standpoint, and where risk enters your supply chain.

Vendor Discovery

Every vendor, host, and service the app actually loads, resolved to real companies and products.

Runtime Behavior Profiling

What the code really does: scripting, tracking, fingerprinting, and outbound payloads.

Resource Baselining

Every resource content-addressed by SHA-256 and validated as known, trusted code.

Continuous Monitoring

Scheduled recaptures detect any change and raise alerts the moment behavior shifts.

Who Can Use SCVue

Built for Individuals, Business, Governments, Academia, & Researchers

SCVue helps people and organizations run comprehensive, continuous monitoring across a wide range of specialties and industries. It is a robust tool for organizations managing their own applications and internal portals, and it supports integration providers just as fully, whether they rely partly or entirely on third-party vendors.

Diligence Services Providers

Vetting, risk assessment, background and screening, audit and review.

Vulnerabilities in Your Own Supply Chain

Across the technology and software products you depend on, and the people who impact them, through all five classes of supply chain: people, knowledge, financial, digital, and physical.

Assessments of Other Companies' Applications

For possible partnership, acquisition, competitive analysis, vulnerabilities, or dependencies.

Deep Research and Competitive Analysis

The measurement works from the outside, with no source code and nothing to install, whether the work is commissioned by the company or carried out independently.

Public-Facing Portfolios

Organizations managing or overseeing multiple sites that service the public domain.

Individuals and Businesses

Validating the trustworthiness of a web-based product.

Legal, Compliance, and Auditors

Compliance with legal terms, GDPR, flow-down clauses, and jurisdictions.

Software Vendors

Knowing and documenting your third-party dependencies, SBOM style work.

Testers and PENTEST Teams

Validating that services and behavior run as designed and developed.

Risk Managers

Understanding third-party risk in technology supply chains.

See more about our solutions

How it does it

Discover & Visualize from a Single Capture

Risk factor analysis on every HTTP request

  • One scale: Ten analysis engines roll up to High, Warning and Info, each finding deep-linked to its report.
  • Code risks: CSP and SRI weaknesses, HTTPS downgrades, runtime code generation, and fetch-to-execute patterns.
  • Tracking risks: Web beacons, tracking parameters, and fingerprinting in media and POST traffic.
  • Evidence only: Derived from captured code and traffic, never from build manifests.
SCVue risk factors report, showing findings graded High, Warning and Info with category, detail, originating host and URL for each.
Findings on a single application, each linked to its evidence.

X-ray every request, map every outgoing data flow

  • Every payload: Inspect what the application transmits out, decoded call by call.
  • Automatic flags: Device fingerprinting, personal information, cross-site and session tracking, behavior logging.
  • Data flow mapping: See exactly which service providers receive data about your application and your users.
SCVue HTTP POST report listing every call that transmitted a payload, with a detail panel decoding one payload and flagging device fingerprinting and tracking behavior.
POST calls on one page, with those flagged for device fingerprinting called out.

Revealing who is behind every resource

  • Real entities: Enrichment resolves observed domains to companies, software products, and individuals.
  • Influence Factors: Flags on the parties themselves: ownership, control, sanctions, jurisdiction.
  • Deep intelligence: Backed by nDiligence profiles, with on-demand enhanced reports and analyst research.
SCVue entities report resolving observed domains to the companies that operate them, with country, category and role for each.
The companies operating behind one application, by country and role.

Map the infrastructure, hosting, and jurisdictions

  • Complete inventory: Domains, hostnames, IPs, ISPs, cloud providers, CDNs, SSL certificates.
  • Automatic attribution: Pattern engines identify CDN and cloud-provider usage.
  • Jurisdiction mapping: Geo and ASN resolution shows where data is stored and served.
SCVue hostname matrix, listing every hostname observed in a capture alongside the infrastructure and providers serving it.
Hostname matrix with CDN attribution, IPs, and asset mix per host.

See more about the platform

How it is different

What makes SCVue™ distinctive is its evidence-based approach, derived from captured code and traffic

It is built with intent, to confirm the application is performing as expected without a narrowed view. We have a ten analysis engine process, with comparison modeling, vendor discovery, continuous monitoring, and influence factor flagging. Performing only one or a couple of these processes can leave a blind spot in the future.

Evidence, Not Claims

Reports what code and traffic are observed to do, never what a manifest declares.

Three Independent Axes

Compare any report across time, capture context, and page.

Risk & Influence Factors

Is the code risky? Are the parties behind it flagged?

Privacy by Design

A local, private workspace keeps all data in the browser. Cloud storage receives only data whose POST payloads have been scrubbed of PII.

See more about SCVue

How to start

One capture can get you started

Getting started with the Community edition is easy. When your needs develop further, or you have a harder problem to solve, or a big organization to support, we have flexible options to help. Not only do we have advanced technology options, we also have reach-back support for your hardest challenges.

Capture

Import a HAR capture, or let SCVue capture remotely from real browsers on real devices in cities worldwide, with scripted interaction.

Parse & Normalize

One deduplicated data model across apps, versions, collections, views, and calls.

Analyze

Ten engines profile code, traffic, payloads, media, entities, and infrastructure.

Report & Monitor

Dashboards, baselines, deltas, and alerts in a comprehensive Analyst Toolkit.

See editions and pricing

Reveal and monitor your application's digital supply chain

Start free with Community, or ask us for a guided demo on your own portfolio.

SCVue is built by nDiligence, which uses it on its own investigations. SCVue puts the measurement in your hands; when a question outgrows a capture, Digital Supply Chain and Equity Chain Mapping take it further.