← News

ReARM at Black Hat USA 2026

We are excited to announce that ReARM has been selected for the Arsenal at Black Hat USA 2026 in Las Vegas!

Pavel Shukhman, CEO of Reliza, will demo ReARM: Release Governance Platform live on Thursday, August 6, 11:20 AM - 12:20 PM at Arsenal Station 3 in the Business Hall, as part of the Vulnerability Assessment track.

Black Hat Arsenal is where security practitioners get hands-on with working open source tooling, and that is exactly how we will run this session. Come by the station to see ReARM answer the questions that an accumulating pile of SBOMs, xBOMs, and security findings normally cannot:

  • Portfolio forensics - paste a PURL and get every affected release across a multi-component portfolio in seconds, including products releases; see a real multi-component SBOM for the shipped product release created in just a few clicks.
  • Security posture over time - diff a release's security posture between two points in time.
  • Agent observability - inspect ReARM's records of what autonomous agents did in the pipeline.
  • VEX as a workflow - import a contradictory multi-statement CycloneDX VEX and watch it accept, stage, and reject statements through a trust gate, then export your own triage downstream.

Everything demoed is fully open source (AGPL-3.0), self-hostable, and reproducible - you can manually install ReARM CE and run every demo yourself.

If you are attending Black Hat USA 2026, stop by Arsenal Station 3 on August 6 - Pavel would love to show you how ReARM turns SBOM compliance artifacts into a queryable, auditable release governance platform.