99% more reported CVEs per day in 2026 than last year.
CRACI

Features for CRA Compliance

Build-time SBOMs, vulnerability tracking and the evidence your Cyber Resilience Act process needs

SBOM Generation

CRACI records the SBOM during the build. A package-aware proxy observes what each job actually fetches, including packages restored from CI caches, and every SBOM carries a completeness state. Export it in CycloneDX or SPDX, with transitive dependencies and declared licenses, and know exactly what is in the software you ship.

Learn more โ†’
An SBOM recorded during the build Packages from npm, PyPI, Cargo, Go, OCI registries and the CI cache pass through a package-aware proxy on the CRACI runner. The job's SBOM lists what was fetched, states its completeness and exports as CycloneDX or SPDX. Package sources npm PyPI Cargo ยท Go OCI registries CI cache restore Package- aware proxy on the runner Job SBOM express 5.2.1 requests 2.32.3 serde 1.0.219 + transitive deps Declared license on every component Complete Completeness states per job and cache: Complete, Complete with connections, Incomplete, Unavailable, Not recorded CycloneDX ยท SPDX

Vulnerability Tracking

CRACI keeps re-evaluating monitored SBOMs as new vulnerabilities are published and aggregates findings across builds and repositories. Security teams triage what it finds and send it to the teams that own the fix, with VEX support. The SBOMs you collect from your own vendors are monitored alongside your builds.

Learn more โ†’
Vulnerability tracking after release After a release ships, its SBOM stays monitored. When a new vulnerability is published, CRACI re-evaluates the monitored SBOMs, finds the affected releases, and the security team triages the finding and routes it to the team that owns the fix. The inventory view shows which software versions are deployed to which products. Release shipped SBOM monitored Later New advisory published Re-evaluated automatically Finding: critical, in 2 releases 1. Triage 2. Route to owner 3. Team fixes Policy gates can block a build on findings ยท VEX supported Inventory: deployed versions Product Version Web app v4.12.0 Mobile API v2.3.1

Compliance Reports

Export the evidence your CRA process needs: build-time SBOMs, vulnerability records and signed provenance that links each artifact to the build that produced it. Reports export as PDF, HTML, CSV, Excel and JSON for your technical documentation. CRACI automates a significant part of the supply chain visibility and evidence your CRA process needs.

Learn more โ†’
Evidence exports from the build record SBOMs, vulnerability records, signed provenance and network traces export as PDF, HTML, CSV, Excel or JSON, or through the public REST API, for customers, auditors and frameworks such as the EU Cyber Resilience Act, NIS2, FDA SBOM requirements and ISO 27001 supply chain controls. The build record SBOMs Vulnerability records Signed provenance Network traces Export PDF HTML CSV Excel JSON or the REST API Who asks for it Customers Auditors Security reviews Frameworks this evidence supports EU Cyber Resilience Act NIS2 supply chain security FDA SBOM for cyber devices ISO 27001 supply chain controls

CI/CD Integration

CRACI replaces the runner, not GitHub Actions. Change runs-on to craci and your runs still appear in GitHub. Every job records what it fetched and runs under an egress policy that is validated before the job starts and fails closed. GitHub Actions is supported today; other CI systems are on the roadmap.

Learn more โ†’
GitHub Actions jobs on CRACI runners A GitHub Actions workflow sets runs-on to craci. Each job runs in its own isolated virtual machine on a CRACI runner, on Linux x86-64 or ARM64, hosted in Europe, and the run still appears in GitHub. .github/workflows/release.yml jobs: build: runs-on: craci was: ubuntu-latest CRACI runners Hosted in Europe Job VM build Linux x86-64 Job VM test Linux ARM64 Job VM publish Linux x86-64 One isolated virtual machine per job, 1 to 32 vCPU Runs still appear in GitHub About 2x GitHub-hosted speed

Ready to get started?

Book a demo to get early access to CRACI

Book a demo