Our Story
CRACI was founded in Helsinki in 2025, after the same conversation kept repeating itself with CISOs, CTOs and compliance leads. They knew the Cyber Resilience Act deadline. They had read the regulation. What they didn't have was tooling that could prove what was actually in the products they had already shipped.
Existing scanners stop at build time. But the vulnerabilities that matter surface later, in transitive dependencies that were clean when you shipped and aren't anymore โ and a build-time scan can't tell you which version of which component is running in which product today. So we built the SBOM generation into the CI runner itself, where the evidence is provable rather than inferred.
In 2026 we raised a โฌ1.4M pre-seed led by Lifeline Ventures, with First Fellow Partners and Wave Ventures, to bring continuous compliance to every team that has to meet the CRA.