For the serious questions

The precise page, for people who check claims.

This page is written to survive a lawyer's read, because lawyers will read it. What the CRA actually says, what we actually do, and what we refuse to claim.

How the evidence holds up.

01 — the signature

Cryptographically signed claims

Every statement in the file is signed and verifiable. An auditor, customer or authority checks the evidence itself; nobody has to take our word, or yours.

02 — the VEX layer

The judgement only you can make

A component list can be reconstructed with scanning tools. Your VEX layer cannot: whether a CVE is actually exploitable in your product is knowledge only you hold. The file captures it, signed and dated.

03 — third-party verifiable

Verification without us in the room

Signatures verify against the artefact, not against our platform. Trust sits in the evidence, not in our promise.

04 — the record

History that cannot be rewritten

Every change is recorded with a timestamp. Under the PLD, a known flaw with a documented date and a documented response is the whole case; the file is that record.

Claims discipline

What we won't claim.

There is no CRA certificate

Conformity is mostly self-assessment, and there are no harmonised standards in the OJEU yet. We say conformity, backed by evidence. Anyone selling you a certificate is selling something else.

Your SBOM need not be public

It lives in the technical file, available to market surveillance authorities on reasoned request. Sharing with customers is your choice; controlled views make it a safe one.

We do not make you compliant

TrustEngine operationalises detection, evidence and sharing. Conformity remains your assessment; we make it one you can stand behind.

Mark what matters. Strike the rest.

0% panic added. Urgency comes from the dates, not from us.