vulnerability.core, Continuous Vulnerability Monitoring

An automated SBOM/HBOM-based scanner that watches your software and hardware components for known vulnerabilities, continuously and in the background, with email alerts and EU CRA-aligned reporting.

A Component You Trusted Yesterday Can Be Vulnerable Today

A modern product is built from hundreds of software and hardware components. One that's clean at release can have a critical CVE disclosed against it a month later, and you won't know unless something is watching for you.

vulnerability.core keeps an SBOM/HBOM for your product and checks it against known vulnerabilities around the clock, alerting you the moment a relevant one shows up. That's exactly the kind of ongoing vulnerability handling the EU CRA expects, with reporting duties from September 2026 and full enforcement in December 2027.

What vulnerability.core Does

SBOM/HBOM Analysis

Builds and maintains a Software and Hardware Bill of Materials for your product.

Background Scanning

Keeps scanning those components against known-vulnerability data on its own, with no manual runs to remember.

Vulnerability Detection

Flags newly disclosed vulnerabilities that affect your specific components, not generic noise.

Email Alerts

Tells your team the moment a relevant vulnerability shows up.

Multi-Tenant Security

Handles many products or customers, each kept separate, built for suppliers and OEM portfolios.

How vulnerability.core Works

  1. Inventory

    We generate an SBOM/HBOM of your product's components.

  2. Baseline

    Each component is mapped against known-vulnerability sources.

  3. Monitor

    Background scanning runs continuously, checking as new vulnerabilities are disclosed.

  4. Alert

    An email alert fires the moment a relevant vulnerability is detected.

  5. Report

    EU CRA-aligned reporting documents your vulnerability handling, ready as conformity evidence.

Where vulnerability.core Fits

vulnerability.core is security.core's Monitoring & Response layer. It takes prioritisation from threat.core and closes the loop back to testing whenever new risks emerge.

1
Testing Layer, pentest.core & fuzz.core find the issues
2
Analysis, threat.core prioritises them
3
Monitoring & Response, vulnerability.core watches continuously

vulnerability.core loops new risks straight back to testing

What you get

  • A maintained SBOM/HBOM
  • Continuous scan results
  • Prioritised vulnerability alerts
  • EU CRA-aligned vulnerability-handling reports
  • Multi-tenant dashboards

Need full conformity support? See our EU CRA Compliance service

vulnerability.core, Common Questions

An SBOM lists your software components, while an HBOM lists your hardware ones. vulnerability.core handles both, so you can monitor the whole product, not just half of it.

The EU CRA requires ongoing vulnerability handling and disclosure. vulnerability.core maintains your SBOM, monitors it continuously, and produces EU CRA-aligned reporting that covers exactly that obligation.

Continuous. Background scanning checks your components as new vulnerabilities are disclosed and alerts you automatically, so there's nothing to remember to run.

Yes. Multi-tenant security keeps each product or customer isolated, which is exactly what suppliers and OEM portfolios need.

Stay Ahead of the Next CVE, and the EU CRA

Start an assessment and we'll set up continuous SBOM/HBOM monitoring for your product, with the alerting and EU CRA-aligned reporting that keeps you in the European market.