CRA Snapshot

What does your vulnerability handling look like from outside?

Enter your company domain. We check the public signals that researchers, customers and market surveillance authorities use to judge how you handle vulnerabilities. You see the result right away, no email needed.

We do not store the domain unless you ask for the PDF report.

What we check

  • security.txt against RFC 9116
  • a PSIRT page or CVD policy
  • advisories in CSAF format
  • CNA status in the CVE Program
  • CVEs from the last 12 months in ENISA EUVD
  • the likely CRA product class
How we check
  • security.txt: we fetch /.well-known/security.txt and /security.txt over HTTPS and check the file against RFC 9116, including the RFC 3339 date format.
  • PSIRT or CVD page: we look for homepage links containing security, PSIRT, vulnerability, CVD or disclosure. We cannot see content loaded by scripts.
  • CSAF: we check /.well-known/csaf/provider-metadata.json and the CSAF field in security.txt.
  • CNA: we compare the domain and company name with the CVE Program's public CNA list, refreshed daily.
  • CVEs: we search ENISA EUVD for the vendor over the last 12 months (up to 100 entries).
  • A timeout, a refusal (403) or a server error (5xx) is shown as "could not check", never as missing.
  • We only connect to public addresses, over HTTPS, with time and size limits.

This is not a conformity assessment or legal advice. The result is based only on information publicly available at the time of the check.