EU CYBER RESILIENCE ACT · ART. 14 · APPLIES 11 SEP 2026

Your firmware just got a deadline.

An actively exploited vulnerability in your product will mean an early warning to the authorities within 24 hours — then 72 hours, then a final report. Aisthetix is the monitoring and reporting engine that makes those clocks survivable. Built for small IoT and Maschinenbau manufacturers.

T-MINUS / ART. 14 ––d ––h ––m ––s
SCROLL SBOM/X-RAY · ESP32-WROOM-32
(00)

Drop your SBOM. Watch the clock start.

Free scans, no account. Your CycloneDX or SPDX JSON runs through the same live pipeline our tenants use — OSV.dev, CISA KEV, EUVD. If anything in your stack is being actively exploited, you see the Art. 14 clock it would start. Demo data is purged after 48 hours.

DROP YOUR SBOM HERE
or click to choose a file
CYCLONEDX 1.4–1.6 JSON · SPDX 2.2/2.3 JSON · ≤ 8 MB
(01)

From SBOM to signed report. One pipeline.

You already build an SBOM in CI. Aisthetix takes it from there — the same engine runs in your pipeline, in our EU cloud, and air-gapped on your bench.

AISTHETIX SCAN — CLI

Parses CycloneDX 1.4–1.6 and SPDX 2.2/2.3, matches components purl-first against OSV.dev, CISA KEV and ENISA EUVD, scores CVSS v3.1 and speaks ecosystem version rules — semver, Debian EVR, RPM. --fail-on gates your CI; offline mode runs air-gapped.

$ aisthetix scan build/sbom.cdx.json --fail-on kev
HOSTED MONITORING — MULTI-TENANT

Upload an SBOM per product version; scans run as async jobs on a Postgres SKIP LOCKED queue. Findings keep their triage state across rescans — a human decision is never overwritten by a robot. Every read is tenant-scoped, every action lands in the audit log.

FEEDSYNC — EVERY 15 MIN

OSV bulk archives bootstrap the advisory cache; modified_id.csv deltas keep it current. Changed advisories trigger targeted rescans — only the SBOMs whose match keys overlap, found with one indexed query. No nightly full-fleet rescan theatre.

KEV & EUVD ESCALATION

The KEV catalog is diffed on every cycle. A CVE entering "known exploited" flips your affected findings in one pass — ransomware-campaign flags included — and your PSIRT is emailed immediately. Under Art. 14, actively exploited is the phrase that starts the clock.

ALERTS — SIGNAL OVER NOISE

Exploited findings alert immediately; everything else arrives as a daily digest. Delivery goes through the job queue — SMTP with retry and backoff — so an alert is a record, not a hope.

(02)

Continuous watch, not annual audit.

The 24-hour clock starts when you become aware. We make sure "aware" happens on our watchfloor — not in a customer call, not in a headline.

FLEET / SECURITY PERIMETER — LIVE
⟵ DRAG ⟶
— EVENT LOG (REPRESENTATIVE) —

    This is the actual product loop: feed deltas come in, only affected SBOMs get rescanned, KEV escalations go out as immediate alerts, and CRA deadline reminders escalate until you mark the milestone submitted.

    (03)

    The obligation engine.

    When you determine you're aware of an actively exploited vulnerability or a severe incident, you open a case. From that moment Aisthetix runs the legal clock — you keep the judgement, we keep the time.

    • Deadlines are precomputed the moment a case opens; reminders escalate as they approach, keep nagging when overdue, and stop the second you mark a milestone submitted.
    • Per-stage report drafts are honest: every missing field is listed as [TODO]. A draft says ready only when it is.
    • The ENISA Single Reporting Platform isn't live yet — drafts are built for guided manual submission today; the SRP adapter slots in the day ENISA ships it.
    EARLY WARNING — ACTIVELY EXPLOITED VULNERABILITY
    ART. 14(1), 14(2)(A) CRA
    productacme-gateway 2.4.0
    referenceCVE-2026-1337
    awareness2026-09-14T04:12:11Z
    exploitationObserved in the wild per CISA KEV listing.
    member_states[TODO — fill in before submission]
    ready: false · missing: member_states
    (04)

    A front door for the people who find your bugs.

    CRA Annex I requires a coordinated vulnerability disclosure policy and a contact address. Every Aisthetix tenant gets a public intake portal and a generated security.txt — live today.

    DEVICE / SMART THERMOSTAT — DISCLOSED
    ⟵ DRAG ⟶
    /cvd/acme/security.txt
    
          
    • Public per-tenant page at /cvd/<your-slug>: your policy text and a structured report form that works with no JavaScript and no reporter account.
    • Anonymous reports accepted; a honeypot and rate caps keep the bots out — quietly.
    • Every report gets a reference, lands in your triage queue, and alerts your PSIRT through the same pipeline as a KEV hit. RFC 9116 security.txt generated for your own domain.
    (05)

    Start before the deadline does.

    Service first, product always — both engagements run on the platform you just scrolled through. Free while we onboard our first design partners.

    FIXED SCOPE · 30 DAYS

    CRA-Ready in 30 Tagen

    FREE — EARLY ACCESS

    Pricing to be announced.

    • SBOM baseline scan of your firmware — findings, triage, fix plan
    • CVD policy + published security.txt + intake portal
    • PSIRT runbook and Art. 14 report templates, rehearsed once
    • The CLI in your CI, gating on exploited vulnerabilities
    Request the package
    RETAINER · MONTHLY

    External PSIRT

    FREE — EARLY ACCESS

    Pricing to be announced.

    • We watch your products continuously — feeds, KEV, EUVD
    • We draft your 24 h / 72 h / final reports; you review and sign
    • Deadline reminders that escalate — to us as well as to you
    • Quarterly evidence pack for auditors and market surveillance
    Talk to us

    BUILT IN THE EU · HOSTED IN THE EU (FRANKFURT) · YOUR SBOMS ARE PROCESSED AND STORED IN THE EU.