Lumeatec / AI Consulting / crAcken
AI Consulting - 02 - SaaS

crAcken.

The CRA flight recorder for connected products. Understand, assess, comply: crAcken turns SBOMs, vulnerability findings and security decisions into one traceable release workflow — so when the EU Cyber Resilience Act’s reporting clock starts on 11 September 2026, your organisation can prove what it knew, what it decided, and what it did.

Request a demoStart free - 30 days, no credit card

Scanners find vulnerabilities. crAcken proves what you did about them.

CRA compliance is not a document problem. SBOMs, CVEs and decisions sit siloed across tools and teams, ownership is unclear, and screenshots and emails do not constitute a defensible record. crAcken connects the systems you already use into one product, release, decision and evidence workflow.

The workflow is deterministic by design — no LLM on the critical path. Each stage gates the next, creating an unbroken chain of custody from first signal to final report preview: every step recorded, every decision traceable, nothing assumed.

FLIGHT RECORDER — RELEASE 4.2.1 SBOM parsed — 214 componentsCycloneDX · deterministic · 09:41 Changed finding — severity: highmonitoring re-check · alert sent · 09:52 Awareness recorded — owner namedtimestamp 09:53 · 24h / 72h clock armed Decision approved — reportableAI memo reviewed · human decision · 11:20 Early warning ready — within 24hreport preview generated · 13:05 Evidence bundle sealedapprovals · files · manifest · export-ready
The deadline

The first CRA deadline is not December 2027.

11 Sep 2026
mandatory reporting obligations begin - fifteen months before the main CRA applicability date. Many teams are planning to the wrong deadline.
24h / 72h
early warning within 24 hours, main notification within 72 hours for actively exploited vulnerabilities and severe security incidents.
€15M
or 2.5% of turnover - the maximum penalty for infringements of essential cybersecurity requirements and key reporting obligations.
11 Dec 2027
main CRA requirements fully applicable: risk assessment, technical documentation, conformity assessment, EU declaration and CE marking.
How it works

From SBOM to defensible product-trust record.

i.

Release context & analysis

Register the product family, release version, market status, support period and owner. Upload your CycloneDX or SPDX SBOM: deterministic parsing and component-to-vulnerability matching, with no ambiguity and no LLM on the critical path.

ii.

Monitor & catch the change

Continuous per-release re-checks detect new or changed findings and severity shifts - not only what the SBOM showed on day one. Alerts trigger a recorded awareness timestamp with a named owner, and the 24h / 72h workflow markers start.

iii.

Decide & prove

A structured case workflow connects facts, decision and approval. A human-reviewed AI memo lays out facts, missing facts, hypotheses and recommendations - then the evidence bundle assembles approvals, files, manifest and report preview in one place.

Built for

The people who carry the obligation.

Security

PSIRT & product security

Stop reconstructing awareness from tickets, emails and spreadsheets. Every signal, owner and decision lands in one defensible timeline, ready for the 24h and 72h windows.

Engineering

Embedded & firmware leads

Findings connected to the exact product, version and support context - across FPGA and SoC platforms, embedded Linux stacks, supplier firmware and field-deployed variants.

Executive

Compliance owners

An audit-ready evidence bundle and report preview that stands up in front of authorities and notified bodies - proof of what the organisation knew, decided and did.

Start with crAcken

Start free. Validate on a real release. Scale when monitoring grows.

30 days - €0

Try it free

Use your own CycloneDX or SPDX SBOMs: up to 10 complete analysis runs, 3 products and 3 active releases, with Findings, Release Workspace, Flight Recorder preview and report preview. No credit card required.

€149 / month

Essential

For smaller product teams establishing a structured CRA readiness baseline on their first supported releases.

€599 / month

Professional

For manufacturers operating multiple supported releases - scheduled monitoring, alerts, integrations and reporting workflows. Enterprise plans available with custom deployment, data residency and support.

— The window is shorter than most teams realise —

Is your reporting process ready?

Start with a guided CRA Reporting Drill Sprint (€9,500 - 5 to 10 business days): one real product and release, SBOM and vulnerability review, a simulated 24h / 72h reporting workflow, an evidence bundle with executive readiness report, a prioritised remediation roadmap - and six months of Professional access included.

Request a demo →Back to AI Consulting