Product overview

From SBOM to retained CRA evidence.

CRA Ledger connects SBOM intake, vulnerability review, remediation tracking, audit history, and readiness reporting across product versions.

CRA Ledger Operations Console

Real product view

CRA Ledger dashboard showing compliance review progress, pending reviews, severity filters, risk trend, recent scans, and top risk components

Live product dashboard example — portfolio evidence, SLA pressure, and review progress.

Product capabilities

What CRA Ledger helps you manage

A structured operating layer for product-version evidence, SBOM intake, vulnerability review, remediation work, and retained activity history.

Evidence workspace

Product-version records

Connect SBOMs, findings, and evidence to product/version context for retained release history.

Evidence file uploads

Attach supporting files or external references to vulnerability review decisions.

Decision rationale

Record review status, justification, details, and reviewer context for vulnerability decisions.

Owner & timestamp history

Retain owner, reviewer, and timestamp context across review and evidence activity.

SBOM & component records

SBOM intake

Upload SBOM files through the product workflow or authenticated intake endpoints.

CycloneDX/SPDX parsing

Detect and parse supported CycloneDX and SPDX formats for review.

Component normalization

Turn component data into structured, searchable component records.

Original artifact retention

Retain uploaded source artifacts with source metadata and SHA-256 hash records.

Hash/source metadata

Keep filenames, upload metadata, and content hashes tied to retained evidence.

Vulnerability & remediation

Vulnerability review

Review CVE findings against normalized component inventories.

Severity/status/owner tracking

Track severity, review status, and ownership across vulnerability findings.

SLA visibility

Surface overdue and time-sensitive vulnerability review pressure based on severity timelines.

Remediation tracking

Capture remediation status, notes, resolved dates, and supporting evidence references.

Audit trail & readiness

Evidence history

Preserve review records, evidence attachments, report history, and ingestion activity.

Audit activity log

Track tenant-scoped operational and review activity for later inspection.

Readiness reportingPartial

Prepare product-security summaries and reports for readiness conversations.

Exportable evidence summariesPartial

Download available reports and evidence summaries without claiming legal certification.

Alerts & integrations

Email alertsPartial

Notification delivery is available where configured; alert coverage is still expanding.

Authenticated intake APIPartial

Programmatic SBOM intake exists for authenticated workflows, not a broad public API program.

Intake webhooksPartial

Webhook subscriptions support intake events; broader integration coverage is still maturing.

Slack alertsPlanned

Dispatch finding status alerts directly to engineering channels.

Scanner importsPlanned

Sync findings from external scanners and registries.

Security & administration

Tenant-scoped history

Keep workspace data, reports, and audit history scoped to the tenant context.

Access controls (RBAC)

Assign Auditor, Engineer, or Admin roles to enforce least privilege access.

Admin-visible activity

Provide system administrators with audit records of configuration changes.

Security contact process

Provide a public contact path for responsible security reports.

Workflow outcomes

What CRA Ledger gives you

Keep product security work connected from intake to release-ready evidence.

Product-version evidence

SBOMs, findings, decisions, and remediation history stay tied to a product release.

Review-ready risk context

CVEs, ownership, SLA pressure, and review decisions stay visible in one workflow.

Retained product-version record

Original uploads, decisions, timestamps, and evidence history are preserved for CRA readiness.

Process flow

How the evidence workflow works

A systematic pipeline designed to turn raw engineering artifacts into retained product-security evidence records.

1

Register product version

Register a software product and define its release version.

2

Add SBOM evidence

Upload CycloneDX or SPDX files to index the component inventory.

3

Normalize components

Automatically parse and map component coordinates for structured review.

4

Review vulnerabilities

Triage CVEs with severity details, review state, and decisions.

5

Track remediation

Monitor SLA pressure, remediation status, and review updates.

6

Preserve evidence history

Retain the upload artifacts, decisions, and reviewer timestamps.

7

Prepare readiness output

Prepare evidence summaries and reports for release-readiness reviews.

Deliverables

The output: retained product-version evidence

CRA Ledger helps teams keep SBOMs, vulnerability decisions, remediation context, timestamps, reviewer context, and audit activity connected to the product version they belong to.

Original SBOM retained

Retain raw CycloneDX and SPDX files with source metadata and SHA-256 hash records.

Review decisions logged

Vulnerability decisions can document rationale, reviewer context, status, and timestamps.

Remediation context preserved

SLA state, finding status, and remediation notes stay connected to affected components.

Audit activity available

Historical logs track re-analysis runs, imports, and user modifications.

Readiness summary prepared

Summaries and reports help teams discuss readiness without claiming legal certification.

Product status

What is available and what is coming next

CRA Ledger separates current evidence-workflow capabilities from roadmap ideas so teams can evaluate the product without roadmap ambiguity.

Available now

Current workflow areas presented as active CRA Ledger product capabilities.

Available
Product-version records
Owner and timestamp history
SBOM intake
Supported CycloneDX/SPDX parsing
Component normalization
Original artifact retention
Hash and source metadata
Evidence file uploads
Decision rationale
Vulnerability review
Severity/status/owner tracking
SLA visibility
Remediation tracking
Evidence history
Audit activity log
Tenant-scoped history
Access controls (RBAC)
Admin-visible activity
Security contact process

Partial / maturing

Capabilities that exist in limited form today or depend on configuration and workflow coverage.

Partial
Readiness reporting
Exportable evidence summaries
Email alerts
Authenticated intake API
Intake webhooks

Planned / roadmap

Future product directions, shown separately so buyers can distinguish what exists from what is coming next.

Roadmap
Supplier evidence portal
Customer evidence packs
Scanner imports
Slack alerts
Expanded webhook coverage
Advanced reporting
Multi-regulation workflows

Trust and scope

Designed for readiness evidence, not legal certification.

CRA Ledger helps organize product security evidence and CRA readiness workflows. It does not provide legal certification, notified body approval, or a guarantee of compliance.

Next step

Start building CRA evidence before the pressure starts.

Join early access or book a focused walkthrough of the SBOM-to-evidence workflow.