How it works

Six steps. The first is free and needs no account. The whole loop runs without anyone here answering a phone.

1

Answer the free wizard

It tells you whether you are in scope and whether you are Default, Important Class I, Class II or Critical. That decides whether you sign your own conformity paperwork or pay a notified body. You get a dated PDF. No signup.

2

Get a component list

Two ways in. If you build from source, add one CI step and every build publishes an SBOM. If your firmware came from an ODM, upload the image and we read the components out of it. Both paths merge into one canonical SBOM per release.

3

Watch it continuously

Every component is matched against NVD, CISA KEV, EUVD and GitHub Advisory. Findings are ranked by whether the flaw is being exploited, using KEV membership and EPSS, so you work a short list. When something on your list starts being exploited, you get an email and a webhook the same day.

4

Answer, or report

Most findings are answered with a VEX statement. "Not affected, the vulnerable code is never called in our build" is a documented position you can point at forever. The few that are actively exploited go to the Article 14 console, which drafts the 24-hour, 72-hour and final notifications against the field set ENISA published.

5

Generate the file

Vulnerability handling policy, disclosure policy, support-period declaration, risk assessment, EU declaration of conformity, technical documentation and user instructions. Built from your product data and your current SBOM, versioned with diffs, flagged stale when the component list moves under them.

6

Keep it, and prove it

Everything is retained for ten years, because that is the obligation. Export one reviewable bundle for a market surveillance authority, or a narrower one for a customer procurement team, in one click.

The ranking matters more than the scan

A Linux-based router image matches several thousand CVEs. A list that long is the same as no list. Four of them will be under active exploitation, and those four are what Article 14 is about.

So the rank is weighted towards proof, not severity. Being on the CISA KEV catalog is worth 60 points out of 100. EPSS, the probability of exploitation in the next 30 days, is worth up to 25. CVSS measures how bad it would be rather than how likely it is, so it is worth 12. The arithmetic is printed next to every finding and you can check it.

What we say when we cannot check something

Some components have no public vulnerability identifier. Vendor BSPs from Realtek, MediaTek and Broadcom are catalogued per silicon part, not per SDK. A few small libraries are not in the NVD dictionary at all.

Those components are listed by name, with the reason, on the product page and in every export bundle. Nothing else in this category does that. It matters because "we found nothing" and "we did not look" produce the same clean row, and only one of them is worth anything to an auditor.

Start with the free wizard

No account, no email address, dated PDF at the end.

Check my product