This page is written to survive a lawyer's read, because lawyers will read it. What the CRA actually says, what we actually do, and what we refuse to claim.
Every statement in the file is signed and verifiable. An auditor, customer or authority checks the evidence itself; nobody has to take our word, or yours.
A component list can be reconstructed with scanning tools. Your VEX layer cannot: whether a CVE is actually exploitable in your product is knowledge only you hold. The file captures it, signed and dated.
Signatures verify against the artefact, not against our platform. Trust sits in the evidence, not in our promise.
Every change is recorded with a timestamp. Under the PLD, a known flaw with a documented date and a documented response is the whole case; the file is that record.
Conformity is mostly self-assessment, and there are no harmonised standards in the OJEU yet. We say conformity, backed by evidence. Anyone selling you a certificate is selling something else.
It lives in the technical file, available to market surveillance authorities on reasoned request. Sharing with customers is your choice; controlled views make it a safe one.
TrustEngine operationalises detection, evidence and sharing. Conformity remains your assessment; we make it one you can stand behind.