Comparison
CRACI vs Xygeni
Xygeni scans your code, dependencies and pipelines and adds attestations to the builds you already run. CRACI is the runner your GitHub Actions builds execute on, so it records what each build fetched and controls what it can reach.
Updated
The short answer
Xygeni is an application security platform from Valladolid, Spain. It describes itself as "one AI-powered platform that detects, prioritizes, and remediates vulnerabilities and malware end-to-end". Its modules cover SAST, SCA with reachability and malware detection, secrets, IaC, containers, CI/CD security, build security with SLSA and in-toto attestations, anomaly detection, DAST, API security and an ASPM layer. It publishes its prices and has a free plan. It does not run builds: it plugs into the CI systems you already use.
CRACI competes for the same supply chain budget from a different place. It is the runner for GitHub Actions: it records the packages each job actually pulled in, enforces an egress policy while the job runs and keeps monitoring what shipped. Xygeni is far broader across AppSec; CRACI goes deeper on the build and what came out of it.
At a glance
| Capability | CRACI | Xygeni |
|---|---|---|
| Runs your builds | Jobs run on CRACI runners | Scanners and sensors in the CI you already run |
| Where the SBOM comes from | Recorded by the runner from what each job fetched, including CI cache restores, with a completeness state per job. | Analyzers read dependency descriptors and resolve versions; exported in SPDX or CycloneDX. |
| Build network egress policy | Default deny or allow, validated before the job, fails closed | Not stated |
| Signed build attestations | No signed provenance | SLSA provenance and in-toto, keyless signing; an Enterprise option |
| Policy gates | Block a build on findings, including a specific CVE | Blocks tampered artifacts before delivery |
| CI/CD posture checks | Pipeline misconfigurations, OWASP Top 10 CI/CD risks | |
| Anomaly detection in SCM and CI | Sensors for GitHub, GitLab, Jenkins, Azure; an Enterprise option | |
| Malicious package detection | Flags known releases with a CVE; egress policy limits sources | ML-assisted detection, quarantine, dependency firewall |
| Reachability analysis | Part of SCA prioritization | |
| SAST, secrets, IaC and containers | Native scanners; DAST and API security as options | |
| CI systems covered | GitHub Actions today; GitLab CI and Jenkins on the roadmap | GitHub, GitLab, Jenkins, Azure Pipelines, Bitbucket, CircleCI, Travis CI |
| Deployment | Managed runners on European infrastructure; customer-hosted runners on the roadmap. | On-premise deployment is an Enterprise option. |
| Pricing | $0.002 per vCPU-minute ($0.004 for 2 vCPU), metered per second; no monthly fee and no per-SBOM charge | Free for up to 5 contributors. Team from about $3,828 (€3,300) and Business from about $6,844 (€5,900) a year with 10 contributors; Enterprise by quote (as of September 2026). |
- Included
- Not included
- On the roadmap
"Not stated" means we could not confirm it in Xygeni's public pages.
What Xygeni does well
- Breadth in one platform. SAST with AI autofix, SCA with reachability and automatic upgrade pull requests, secrets detection with auto-revocation, IaC and container image scanning, and, on Enterprise, DAST, API security and ASPM with third-party data ingestion.
- Malware in open source. Xygeni says it analyzes thousands of new and updated open-source packages every day, uses an ML-assisted engine to detect unknown malware, quarantines suspicious packages and can block them with a dependency firewall. That goes beyond matching CVEs.
- CI/CD security. It looks for misconfigurations in build scripts and pipelines, addresses the OWASP Top 10 CI/CD risks, checks settings such as branch protection and multi-factor authentication, and flags harmful commands in pipelines, such as reverse shells and malware downloads.
- Build attestations. Build Security adds one line to a pipeline to gather evidence from each stage of the build and generate SLSA provenance and in-toto attestations, signed with keyless signatures. Attestations can carry vulnerability scans, SBOMs in SPDX or CycloneDX and test results, and tampered artifacts can be blocked before delivery.
- Anomaly detection. Sensors for GitHub, GitLab, Jenkins and Azure watch for unauthorized changes to code, dependencies, pipelines and build configuration, and alert in real time.
- Wide CI coverage and published prices. Xygeni lists integrations with GitHub, GitLab, Jenkins, Azure Pipelines, Bitbucket, CircleCI and Travis CI, and it offers on-premise deployment on Enterprise.
Where CRACI is different
Recorded from the build, not read from descriptors
Xygeni's documentation says its analyzers process dependency descriptors to extract direct and indirect dependencies and resolve their versions. That is the standard way to build an SBOM from a repository. CRACI sees the traffic coming into each build instead: a package-aware proxy records every package the job fetched across npm, PyPI, RubyGems, Cargo, Go, Nix, OCI, apt, apk and Git sources, plus download presets. Packages restored from CI caches stay in the record.
That is how CRACI records the hidden dependencies that lockfile-based tools miss: code downloaded by npm install hooks, Rust build scripts that fetch at build time, and the base image layers of a container build. Every SBOM carries a completeness state per job and per cache (Complete, Complete with connections, Incomplete, Unavailable or Not recorded), so when the record has a gap, it says so.
Control while the build runs
Xygeni's CI/CD checks look at how pipelines are configured and what commands they contain. CRACI limits what the build can reach. Egress policies are default deny or default allow, with 24 built-in software-source presets, typed custom sources for npm, PyPI, apt, apk, the Go proxy, Nix, Cargo, OCI registries and Git, and explicit TLS, TCP, UDP and ICMP rules. They are validated before the job starts and fail closed. Because a default-deny policy allows only what the build needs, a compromised package that tries to send your secrets to an unknown host is blocked, even in an attack nobody has seen before, and CRACI alerts you about the violation.
Provenance and monitoring from one record
Xygeni signs attestations from a step added to the pipeline you run. CRACI's record comes from the runner the job ran on: the API returns SBOMs, network traces and provenance. CRACI does not sign provenance and claims no SLSA level. CRACI keeps re-evaluating the SBOMs of what you shipped as new vulnerabilities are published, and shows every past build that contained a vulnerable dependency, so you know how long you were exposed.
The runner is part of the product
Because CRACI is the runner, the evidence comes with compute: runs still appear in GitHub, and CRACI runs builds about twice as fast as GitHub-hosted runners, thanks to faster hardware, shorter queue times and caching. CRACI charges only for build minutes, $0.002 per vCPU-minute ($0.004 for a default 2 vCPU runner), metered per second, with no monthly fee and no per-SBOM charge. See CRACI pricing.
Which one fits
Xygeni is the better fit when
- You want one AppSec platform for SAST, SCA, secrets, IaC, containers and pipeline configuration.
- You want malicious open-source packages detected and blocked before an advisory exists.
- You build on GitLab, Jenkins, Azure Pipelines, Bitbucket, CircleCI or Travis CI.
- You need SLSA and in-toto attestations, or an on-premise deployment.
- A small team wants to start on a free plan with published prices.
CRACI is the better fit when
- You build on GitHub Actions and want the runner, egress policy and dependency record in one place.
- You need an SBOM of what each build actually fetched, with a completeness state you can show an auditor.
- You want monitoring of what shipped and build history from the same record.
What you give up by moving build evidence to CRACI
For the software you build on GitHub Actions, CRACI takes over the job of Xygeni's SBOM export: the record, the provenance data and the monitoring come from the runner. To be plain about what that costs: CRACI has no reachability analysis, does not detect new malicious packages by behavior or reputation (it flags known malicious releases once an advisory with a CVE is published), opens no upgrade pull requests, signs no provenance, claims no SLSA level, has no anomaly detection across source control, and runs GitHub Actions only today, with GitLab CI and Jenkins on the roadmap.
Xygeni's SAST, secrets, IaC and CI/CD posture checks cover ground CRACI does not touch by design, so those can stay where they are. CRACI replaces the runner, not GitHub Actions, so a scanning step runs on a CRACI runner like any other step.
For the Cyber Resilience Act
The Cyber Resilience Act is one of several frameworks that ask for an SBOM and a vulnerability handling process. Xygeni lists software supply chain compliance checks against CIS and OpenSSF on its Business plan. CRACI automates a significant part of the supply chain visibility and evidence a CRA process needs: build-time SBOMs exported as CycloneDX or SPDX, vulnerability tracking, and provenance through the API. See CRA evidence. Neither tool makes a product compliant on its own.
For other platforms in this space, see CRACI vs Cycode, CRACI vs OX Security, CRACI vs Wiz and software supply chain security tools.
Xygeni questions, answered
What is Xygeni?
Xygeni is an application security platform from Valladolid, Spain. It combines its own scanners (SAST, SCA with reachability and malware detection, secrets, IaC, containers, CI/CD security, and optionally DAST and API security) with an ASPM layer, plus build security with SLSA and in-toto attestations and anomaly detection across source control and CI systems.
How much does Xygeni cost?
As of September 2026, Xygeni's pricing page shows a free plan with SAST, SCA, secrets and an IDE plugin for up to 10 repositories, 200 scans a month and 5 contributors. Team starts at about $3,828 (€3,300) a year and Business at about $6,844 (€5,900) a year, each including 10 contributors, and Enterprise is priced by quote. A contributor is anyone who committed to a scanned repository in the past 90 days. Build Security and Anomalies Detection are Enterprise options.
Does Xygeni provide CI runners?
No. Xygeni integrates with the CI systems you run, such as GitHub, GitLab, Jenkins, Azure Pipelines, Bitbucket, CircleCI and Travis CI, and adds its scanners and attestation step to your pipelines. CRACI is the runner: GitHub Actions jobs run on CRACI, which records what each job fetched and controls what it can reach.
What is the difference between Xygeni and CRACI?
Xygeni is a broad AppSec platform that scans code, dependencies, secrets, IaC and pipeline configuration across many CI systems. CRACI is a GitHub Actions runner that records the packages each build actually fetched, enforces an egress policy while it runs and keeps monitoring what shipped. Xygeni is far broader; CRACI records the build itself.
Can CRACI replace Xygeni?
For the build evidence of software you build on GitHub Actions, yes: CRACI's recorded SBOM, provenance and vulnerability monitoring cover that job. CRACI does not replace Xygeni's SAST, secrets, IaC, CI/CD posture checks, malware detection or reachability analysis, and it runs GitHub Actions only today, with GitLab CI and Jenkins on the roadmap.
Run one real build and compare
Point one GitHub Actions workflow at CRACI and compare its SBOM and network trace with what your scanners report today.
Book a demo