Oct19
Details
Automated Cyber Resilience
for every build
Software supply chains are the #1 attack surface. CRACI helps companies ship secure releases with automated SBOMs, vulnerability tracking, and audit-ready evidence right from your CI/CD.
Backed by
End-to-end lifecycle management
CRACI organizes supply chain security around four connected workspaces — from your first build to your next audit.
Builds
#247Clone repository
Install dependencies
Build artifact
Sign artifact
Deploy artifact
Generating SBOM
Manage your applications0/5
Builds
Trusted builds, faster CI
- Trigger builds across all your repositories
- Sign artifacts with provenance attestations
- Generate and export a complete SBOM
- Accelerate your CI builds
Security
248 packages trackedreact19.2.4
contentful11.10.5
lodash4.17.21
CVEframer-motion12.38.0
Monitoring vulnerabilities for SBOM #247live
Security
View your supply chain dependencies
- Discover vulnerable packages in your supply chain
- Triage builds sharing vulnerable dependencies
- Assess supply chain vendor risks
- Set up automated alerts for new CVEs
Inventory
7 regionsGlobal monitoring1 at risk
Inventory
Monitor your devices and deployments
- Investigate sites and products currently flagged at risk
- Manage out-of-date software versions
- Resolve version divergencies across deployments
- Manage inventory across regulatory regions
Compliance
auto-mode enabledCVEs disclosed
ENISA reports filed
Right teams notified
Customers notified
Audit-ready0/4
Compliance
Manage your compliance reports
- Detect and remediate product compliance issues
- Submit required CRA reports to ENISA
- Set up customer notification integration
- Prove compliance to vendors
Why the SBOM is different
CRACI sees the traffic. Scanners don't.
Other SBOM tools read the lockfile or the build's output and guess what went in. CRACI sees what actually comes into each build, including the hidden dependencies that install hooks, build scripts and base images pull in.
Featured
Designed for products of all scales.
Whether you're shipping a single microservice or managing hundreds of repositories, CRACI brings supply chain security to every build.
Automated SBOM Generation
Generate a provably complete Software Bill of Materials directly from CRACI's build runner. CycloneDX and SPDX formats supported.
Vulnerability Tracking
Continuous vulnerability management with real-time monitoring across all your dependencies.
Compliance Reports
Generate CRA-ready SBOM reports and vulnerability disclosures for ENISA with one click.
CI/CD Integration
Runs as your GitHub Actions runner, with your runs still in GitHub. Other CI systems are on the roadmap.
Team Collaboration
Assign vulnerabilities, track remediation progress, and coordinate disclosures.
Research
Disclosure is outpacing triage
We rebuild the full CVE record from the CVE Program's official
cvelistV5 repository every day and publish what
it shows. In 2026 the rate is still climbing.
CVEs published per day
259 +98% vs 2025
One every 6 minutes in 2026
High or Critical per day
133 +149% vs 2025
Up from 54 per day in 2025
Records analysed since 2020
243,840
Rebuilt daily from the CVE Program's cvelistV5