CRA readiness, without the compliance theatre

Keep your product signal in sight.

Threadcairn turns dependency and vulnerability signals into a reviewable CRA trail for small teams, without pretending a snapshot is a legal conclusion.

Start with a public, read-only scan or follow the onboarding handoff for your own public or private repositories.

Built for 2–50 person teams Poland + Germany first
Live readiness board
northstar-api / release 2.8.1
Monitoring
SBOM
Current
Dependencies
142 tracked
Last review
12 min ago
Signal queue3 events
CVE-2025-4428
Review recommended
14 min ago
express 4.18.2
Version in SBOM
2 h ago
Release 2.8.1
Evidence captured
Yesterday
Review window open. Your evidence trail is ready for a human decision.

Why Threadcairn

A small team’s early-warning system.

The CRA asks for a living view of your product. Threadcairn keeps the technical facts close to the people who ship, so review starts with context instead of a spreadsheet hunt.

01 /

SBOMs that follow releases

Generate and maintain software bills of materials from connected GitHub repositories, with a release-by-release history you can actually explain.

02 /

Signals that deserve attention

Monitor dependencies for known and actively exploited vulnerabilities, then turn a noisy alert into a focused CRA review when the context calls for it.

03 /

Evidence with a place to go

Capture discovery time, affected products and versions, CVE details, evidence, mitigations, and reporting deadlines in one guided workflow.

The working loop

From repository to review-ready.

A calm, repeatable path for teams that need evidence without hiring a compliance department.

01

Connect the source

Point Threadcairn at a GitHub repository and get a baseline SBOM for each release.

02

Watch the moving parts

Track dependencies, CVEs, and active exploitation signals before they disappear into a backlog.

03

Build the evidence trail

Open a guided review with discovery time, affected versions, mitigations, and deadline context.

The record, at a glance

A review file that gets more useful over time.

Keep the facts connected from first signal to resolved release. Threadcairn prepares the information for customer review; your team makes the decision.

Discovery time and vulnerability details
Affected products, versions, and releases
Evidence, owners, mitigations, and status
A release-by-release history for audits

Start with one repository

Know what deserves a closer look.

Get a free repository scan, then choose the level of ongoing coverage that fits your products and your team.

Threadcairn prepares reporting information for customer review. It does not provide legal advice or decide whether an incident is legally reportable.