Built in public, on purpose, so anyone we talk to can see exactly what they're signing up for.
Mapped the CRA reporting requirements in detail, evaluated the open-source vulnerability tooling landscape, and designed the core monitoring pipeline.
Repository connection, automated component mapping, and continuous actively-exploited-vulnerability matching built and tested against real codebases.
A small group of companies we've spoken with gets early access to test the full flow (connect, monitor, alert, report) before the reporting deadline hits.
CRA Alert opens to every company we've talked to, at founding-customer terms, launching the same month the CRA reporting duty itself becomes active.
If ENISA's reporting platform opens up system-level access, or based on direct demand from customers, we plan to offer a done-for-you submission service as an add-on.
We're watching whether the same monitoring core is worth extending toward adjacent EU obligations, like NIS2. No commitment yet, and we'd rather do one thing well first.