NF / GitHub
ForgeVault CRA
GitHub-native evidence for the EU Cyber Resilience Act.
ForgeVault CRA collects operational evidence where engineering already happens — releases, SBOM references, vulnerability handling, decisions — and organises it into reviewable CRA-aligned packs. Evidence tooling, not legal advice.

ForgeVault CRA — product interface
NF / Problem
What problem does this solve?
CRA evidence scattered across issues, releases and docs is painful to assemble during scrutiny.
Regulators, customers and internal reviewers ask the same questions: what shipped, what was known, what was fixed, when. ForgeVault keeps that trail structured and exportable from GitHub activity.
NF / How it works
3 steps, no platform.
- 01Link reposScope the repositories in question.
- 02CollectAssemble release, advisory and decision signals.
- 03PackExport an evidence pack for review.
NF / Features
What it does.
Only shipped behaviour is marked active. Beta and planned items are labelled honestly.
- planned
Release ledger
Versioned record of what shipped.
- planned
Vulnerability trail
Handling history in one place.
- planned
Evidence export
Reviewable pack for stakeholders.
Built for
- Engineering leads
- Security teams
- Compliance support
NF / FAQ
Questions, answered plainly.
Is ForgeVault legal advice?
No. It is operational tooling that organises evidence. Regulatory interpretation remains yours and your counsel's.
ForgeVault CRANF / Support
Need help with ForgeVault CRA?
Docs, troubleshooting and a direct line to the people who build it.