Hexamind

Docs

Search docs...

⌘K
ENRequest Access
Documentation
  • Getting Started

  • TrustBOM

    • Concepts

    • Sign & Share

    • TrustObjects

    • Certificates

    • External Verify

  • Hexamind AI

    • Concepts

    • AI Advisor

    • Analysis Panel

    • Reports

  • Security Advisory

    • Terms & Concepts

    • Projects

    • Vulnerability Audit

    • Environments

  • Compliance

    • Security Baseline

    • License Management

    • Vulnerability DB

  • Security & Policy

    • Security Architecture

    • AI Analysis & Data Security

    • VDP

  • Regulations

  • FAQ

Back to Home

Contact

FAQ

Frequently Asked Questions

Answers to frequently asked questions about product capabilities, regulations, and account management.

Product & Technology

How is Hexamind AI different from general-purpose AI tools like ChatGPT or Gemini?

General LLMs can summarize vulnerabilities or draft reports from attached files. Hexamind AI is different because it works with project SBOMs, vulnerability data, operating context, and compliance information that are already connected inside the platform. That lets teams review what matters first in their own environment without rebuilding context every time.

Can automation features cause service disruption?

Automation can help reduce operational overhead, but results may vary across environments. We recommend expanding automation scope gradually, aligned with your organization's risk tolerance and operating policy.

Is hiring security experts such as a CISO or consultants a more reliable option?

Security experts remain essential. Hexamind Platform is designed to support them, not replace them, by reducing repetitive inspection and data-handling work so teams can focus on higher-value decisions. It helps small organizations establish a baseline process quickly and helps mature teams run supply chain security more consistently.

Regulations & Policy

If the Korean 2027 supply chain security mandate is delayed, would this investment be wasted?

Timelines can shift, but the need for supply chain security operations already exists. U.S. and EU requirements are already active or entering enforcement phases, and Korean public procurement expectations are also tightening. Independent of regulation, managing SBOMs, licenses, and vulnerabilities systematically improves both delivery readiness and internal security operations.

How can we determine whether the EU Cyber Resilience Act applies to us?

If your organization sells or distributes digital products or components into the EU market, the CRA likely applies. That can include SaaS services, smart devices, and software libraries. Purely non-commercial open source may qualify for limited exceptions, but legal review is recommended for an authoritative determination.

What SBOM format is typically required for submission?

In practice, U.S. E.O. 14028 commonly expects SPDX or CycloneDX. The EU CRA does not prescribe a single mandatory format, but SPDX and CycloneDX are the most widely used options. Korean public procurement is also expected to rely heavily on CycloneDX JSON or XML. Hexamind Platform supports standard SBOM formats, but exact submission requirements should still be validated against the contracting authority or procurement terms.

Usage & Features

Can I use the platform even if I do not already have an SBOM?

Some capabilities can be used without a prebuilt SBOM, but vulnerability analysis in Security Advisory and signing workflows in TrustBOM work best when an SBOM is available. If you do not have one yet, the platform can extract component information from package manifests, container images, and source archives to help bootstrap that process.

How should we manage multiple versions of the same software product?

We recommend registering each release as a separate project. Versioned projects make it easier to compare vulnerability history and change over time. With TrustBOM, you can also show recipients which version was delivered and how its security posture differs from previous releases.

What should I do if Hexamind AI gives an incomplete or incorrect answer?

That can happen occasionally. In those cases, try asking a more specific question and confirm that the correct project is selected. Connecting environment data also improves answer quality. Important decisions should still be reviewed by security professionals.

Account & Billing

How much can I do with the Free plan?

During the current Early Access period, you can explore the major capabilities broadly. After general availability, plan-specific limits and billing policies will be shown in account settings.

How can I change my account type or upgrade to an organization plan?

If you need to change your account type or transition to an organization plan, please reach out through the support channel.

Why is the password policy so strict?

Strong password requirements exist to maintain a level of account protection appropriate for a security platform. Weak credentials can affect the broader supply chain security posture, so using a password manager is strongly recommended.

Which payment methods are supported?

The billing flow is designed to support both domestic cards and major international cards, and enterprise customers can usually discuss contract-specific arrangements. Detailed payment policy may evolve as plans mature.

Support & Contact

How can I receive technical support?

Technical support and general inquiries can be sent to [email protected]. For vulnerability reports, please include [VDP] in the subject line.

Can we request a demo or adoption consultation for Hexamind Platform?

Yes. You can request a demo or consultation through the landing page inquiry form or by email. Depending on your needs, this can include an online walkthrough, scenario review, and organization-specific discussion.


Need more help?

If you did not find the answer here, feel free to contact us directly.

Email Support
Previous

Regulations