vulnerability.core, Continuous Vulnerability MonitoringAn automated SBOM/HBOM-based scanner that watches your software and hardware components for known vulnerabilities, continuously and in the background, with email alerts and EU CRA-aligned reporting.
A modern product is built from hundreds of software and hardware components. One that's clean at release can have a critical CVE disclosed against it a month later, and you won't know unless something is watching for you.
vulnerability.core keeps an SBOM/HBOM for your product and checks it against known vulnerabilities around the clock, alerting you the moment a relevant one shows up. That's exactly the kind of ongoing vulnerability handling the EU CRA expects, with reporting duties from September 2026 and full enforcement in December 2027.
vulnerability.core DoesBuilds and maintains a Software and Hardware Bill of Materials for your product.
Keeps scanning those components against known-vulnerability data on its own, with no manual runs to remember.
Flags newly disclosed vulnerabilities that affect your specific components, not generic noise.
Tells your team the moment a relevant vulnerability shows up.
Handles many products or customers, each kept separate, built for suppliers and OEM portfolios.
We generate an SBOM/HBOM of your product's components.
Each component is mapped against known-vulnerability sources.
Background scanning runs continuously, checking as new vulnerabilities are disclosed.
An email alert fires the moment a relevant vulnerability is detected.
EU CRA-aligned reporting documents your vulnerability handling, ready as conformity evidence.
vulnerability.core Fitsvulnerability.core is security.core's Monitoring & Response layer. It takes prioritisation from threat.core and closes the loop back to testing whenever new risks emerge.
vulnerability.core loops new risks straight back to testing
What you get
Need full conformity support? See our EU CRA Compliance service
vulnerability.core, Common QuestionsAn SBOM lists your software components, while an HBOM lists your hardware ones. vulnerability.core handles both, so you can monitor the whole product, not just half of it.
The EU CRA requires ongoing vulnerability handling and disclosure. vulnerability.core maintains your SBOM, monitors it continuously, and produces EU CRA-aligned reporting that covers exactly that obligation.
Continuous. Background scanning checks your components as new vulnerabilities are disclosed and alerts you automatically, so there's nothing to remember to run.
Yes. Multi-tenant security keeps each product or customer isolated, which is exactly what suppliers and OEM portfolios need.
Start an assessment and we'll set up continuous SBOM/HBOM monitoring for your product, with the alerting and EU CRA-aligned reporting that keeps you in the European market.