About KROMSE

Evidence a CRA decision can stand on — not a score that pretends to be one.

KROMSE sits at the point where product security, incident response, legal review, and Cyber Resilience Act preparation meet.

Why it exists

Vulnerability scanners produce technical findings. A CRA response needs affected-product context, evidence, an owner, a deadline, a decision, and a record that holds up if someone checks it later. KROMSE connects those layers — it does not replace the judgment of the people who sign off on them.

What it controls

Repository and SBOM evidence, verified vulnerability intelligence, product impact, CRA response cases, report drafts, and audit history stay inside your organization's own tenant, reviewed by your own people before anything moves.

The operating principles

  • Evidence comes first. We show our work, not just a verdict.
  • CRA gets its own scope — we don't blend it with regimes we haven't built for yet.
  • A person signs off on every security and legal call KROMSE surfaces.
  • Nothing goes to a regulator unless someone in your organization decides to send it.
  • Your evidence stays inside your tenant, never pooled across customers.
  • When we're not sure, we say so, instead of rounding uncertainty up to confidence.
Open KROMSE
KROMSE

Connect a GitHub repository or upload an SBOM. KROMSE scans the exact commit, explains every finding in plain English, and prepares a CRA Article 14 report draft for a human to approve. Free workspace, no checkout.

© 2026 KROMSE. All rights reserved.