Introduction
Overview of the TACO platform -- what it does, platform URLs, tech stack, and service count.
TACO (Transparent Automated Compliance & Operations) is a vulnerability management platform that ingests Software Bills of Materials (SBOMs), scans components for known vulnerabilities, enriches findings with exploit intelligence, and delivers actionable alerts to development teams.
What TACO Does
- SBOM Ingestion -- Accepts CycloneDX and SPDX SBOMs via API or automated fetching from container registries and artifact repositories.
- Vulnerability Scanning -- Matches every component against a multi-source vulnerability database (NVD, OSV, GHSA, Alpine, Debian, Ubuntu, Red Hat, ALAS, CISA KEV).
- Secret Detection -- Scans SBOMs for leaked credentials, API keys, and private keys embedded in metadata.
- CVE Enrichment -- Enhances findings with EPSS exploit probability, CVSS vectors from NVD, known-exploit status from CISA KEV, and CVSS data from OSV.dev.
- Risk Scoring -- Computes a composite risk score combining CVSS base score, EPSS probability, and KEV status.
- Alerting -- Notifies teams via Slack, email (Mailgun), generic webhooks, and PagerDuty when new vulnerabilities are found.
- Multi-tenant SaaS -- Supports subscriptions, projects, RBAC, OAuth (GitHub/Google), and Stripe billing.
Platform URLs
| Service | URL |
|---|---|
| Portal (Frontend) | portal.taco-sec.com |
| Inbound API | taco-inbound.taco-sec.com |
| Public Docs | docs.taco-sec.com |
| Corporate Site | taco-sec.com |
| Internal Docs | internaldocs.taco-sec.com |
Service Count
The platform consists of 14 microservices plus infrastructure components (MySQL, RabbitMQ, Valkey, HAProxy, Nexus). All services are containerized and deployed via Docker Compose on a single server.
Tech Stack
| Layer | Technology |
|---|---|
| Backend services | Go (Echo framework, standard library HTTP) |
| Frontend | Next.js 16, React 19, Tailwind CSS 4 |
| Database | MySQL 8.0 |
| Message broker | RabbitMQ 3 |
| Cache / sessions | Valkey 8 (Redis-compatible) |
| Reverse proxy | HAProxy 3.1 |
| Container registry | GHCR (GitHub Container Registry) |
| CI/CD | GitHub Actions (self-hosted runners) |
| Artifact repo (dev) | Nexus 3 |