Uploaded December 2025 | Updated September 2026, 1 week ago
Imagine you just bought a brand new smart light bulb. How would you find its SBOM? What about certifications, attestations, or other transparency artifacts? Now, imagine needing that same information for a SaaS product, packaged software, or even a connected car.
Today, this kind of security metadata is fragmented, vendor-specific, and often hard to access, and it is sometimes still exchanged by email. The OWASP Transparency Exchange API (TEA), an emerging Ecma standard, aims to solve this.
In this session, we'll explore how TEA enables a standardized, automated way to discover and access SBOMs / xBOMs, certifications, and other transparency artifacts across the software and hardware supply chain. We'll cover the motivation behind the standard, walk through the current specification, show live implementation demo, and preview what’s next.
Pavel Shukhman
Reliza
Co-Founder & CEO
Ottawa, Canada
linkedin.com/in/pshukhman
Pavel Shukhman is Co-Founder and CEO of Reliza, where he oversees the company's efforts in managing software and hardware releases, xBOMs, versioning and component identification. With over a decade of experience leading software teams, he has helped organizations implement DevOps and DevSecOps best practices. Pavel holds a Master’s degree in Computer Science from the University of Illinois Urbana-Champaign.
Managed by the OWASP® Foundation
owasp.org
Imagine you just bought a brand new smart light bulb. How would you find its SBOM? What about certifications, attestations, or other transparency artifacts? Now, imagine needing that same information for a SaaS product, packaged software, or even a connected car.
Today, this kind of security metadata is fragmented, vendor-specific, and often hard to access, and it is sometimes still exchanged by email. The OWASP Transparency Exchange API (TEA), an emerging Ecma standard, aims to solve this.
In this session, we'll explore how TEA enables a standardized, automated way to discover and access SBOMs / xBOMs, certifications, and other transparency artifacts across the software and hardware supply chain. We'll cover the motivation behind the standard, walk through the current specification, show live implementation demo, and preview what’s next.
Pavel Shukhman
Reliza
Co-Founder & CEO
Ottawa, Canada
linkedin.com/in/pshukhman
Pavel Shukhman is Co-Founder and CEO of Reliza, where he oversees the company's efforts in managing software and hardware releases, xBOMs, versioning and component identification. With over a decade of experience leading software teams, he has helped organizations implement DevOps and DevSecOps best practices. Pavel holds a Master’s degree in Computer Science from the University of Illinois Urbana-Champaign.
Managed by the OWASP® Foundation
owasp.org










