Upload your dependency manifest. Within 24 hours you receive a two-page exposure report showing what you ship, what carries known vulnerabilities, and what would trigger an Article 14 reporting obligation today.
We scan your dependency manifest against the PyPI/NVD advisory databases and the CISA Known Exploited Vulnerabilities catalogue. You get a dated report — not a sales pitch.
Name, email, and a note about your product. If you have your dependency manifest ready, mention it — we'll reply with a secure upload link, or you can simply email the file.
Your manifest is checked against the OSV vulnerability database and the CISA Known Exploited Vulnerabilities catalogue. Automated first pass, then human review of every finding.
A two-page dated summary in your inbox within 24 hours. What you ship, what carries known issues, and whether any component has confirmed active exploitation — which is what triggers Article 14.
| Area | Finding | Rating |
|---|---|---|
| Component inventory | 67 pinned packages scanned | ✓ PASS |
| Known vulnerabilities | 41 records across 4 packages | ⚠ FLAG |
| Article 14 exposure | 1 finding matches CISA KEV | ✗ CRITICAL |
| Remediation path | 4 packages need major-version upgrade | ⚠ FLAG |
The free scan tells you where you stand. If you need a full readiness process — SBOM audit, reporting runbook, designated reporter delegation, tabletop exercise, and daily monitoring — before September 11:
See the full CRA Readiness engagement →