Under CRA Article 14 the clock starts the moment you become aware — not when you confirm.

If you place on-prem, desktop or embedded software on the EU market, an actively exploited dependency puts you on a 24-hour reporting deadline. See your exposure in ninety seconds — free, with nothing to install and nothing stored.

The penalty ceiling is €15m or 2.5% of global turnover (CRA Article 64 (opens the primary source in a new tab)). Filing is manual — ENISA provides no API. This tool provides detection, evidence and drafts; it does not make you compliant.

The fastest trigger produces no CVE

Exploitation in the wild, not just CVEs

Article 14 triggers on active exploitation. We surface it — including the abandoned and ownership-changed packages a CVE-only feed never flags in time.

The clock starts at awareness

A timestamped, tamper-evident record of when each signal arrived is the one fact that determines liability. It only accrues value the longer it runs.

Honest about the filing

ENISA provides no API; filing is manual. We say so plainly and give you a pre-drafted payload in the platform’s field order — not a promise of automation that doesn’t exist.

Run CRA Article 14 readiness for your clients

White-label or co-branded. You own the client and bill directly; we provide the detection, the awareness record, and the payload underneath. No numbers on the page — the specifics are set with you.

Partner with us