Software Bill of Materials
A CycloneDX SBOM ships as a release asset with every release since 4.1.7 — your dependency inventory, machine-readable, without asking.
phpMyFAQ is open source software, developed in Germany since 2001, and runs entirely on your own infrastructure. No SaaS dependency, no data leaving your control — a European answer to proprietary knowledge-base clouds.
Software cannot be “GDPR-compliant” on its own — compliance is achieved in operation. What phpMyFAQ gives you is the position to achieve it: full control over where data lives, which services are involved (none, by default), and how long anything is retained.
The EU Cyber Resilience Act is making software supply chains auditable. When your procurement or security team asks for the paper trail, phpMyFAQ already has it:
A CycloneDX SBOM ships as a release asset with every release since 4.1.7 — your dependency inventory, machine-readable, without asking.
Published since 2004 — two decades of transparent vulnerability handling, all in the advisory archive.
Report vulnerabilities privately via GitHub or security@phpmyfaq.de — with documented support windows and end-of-life dates on the security page.
Open code, auditable line by line on GitHub. No black boxes in your supply chain.
We describe what the project does, not a certification it holds: the CRA largely exempts non-commercial open source, and compliance always depends on how you deploy. These artifacts are what due diligence actually asks for — and closed-source vendors rarely show them.
Universities, public-sector institutions and companies across Europe run phpMyFAQ in production. Try the online demo or download it and keep your knowledge base on your own terms.