Components are checked against vulnerability advisories
offline, with OSV and NVD only when you opt in. Every finding
shows how confident the match is and where it came from. A
match the engine cannot settle goes to a person, and a
supplier’s “not affected” never closes your
finding.
If you choose a requirement regime, the same evidence is
mapped to it. Today that is the EU Cyber Resilience Act, with
SBOM field checks against the NTIA 2021 minimum elements and
BSI TR-03183-2. It is an engineering gap assessment, never a
conformity conclusion — choose no regime and this step
does not run.
Automatic: matching, confidence labelling, exploitation context, coverage mapping when a regime is declared, gap lists.
Yours: triage outcomes, what a finding means for your product, and the conformity judgment — with your assessor, notified body, or counsel.
Outcome: findings with confidence and provenance, and a coverage map that says where evidence exists and where it does not. Zero findings never means no vulnerability.
Vulnerability review → EU CRA readiness, one optional regime → Observed vs reviewed →