92% more reported CVEs per day in 2026 than last year.
CRACI

Automating cyber resilience

The software supply chain is the largest attack surface most companies have, and it is the one they understand least. CRACI makes resilience automatic โ€” generating a provably complete inventory inside the build, then watching it for as long as the product ships.

The market we're building for

Disclosure volume has outrun the teams meant to triage it.

251
CVEs published per day โ€” up 92% on 2025
130
High or Critical per day โ€” up 142% on 2025
239,457
Vulnerability records CRACI has analysed since 2020
600,000+
Companies that must prove product security to sell in the EU

Market Opportunity

The attack surface is code nobody wrote

Most of what a modern product ships is third-party and transitive code. A build that was clean on release is not clean a month later, and almost no team can say which version of which component is running in which product today. That gap is where supply chain attacks land.

Resilience has to be continuous

Development-time scanners take a snapshot and stop. CRACI generates SBOMs inside its own CI runner, so the artifact shipped is provably the artifact described โ€” then keeps matching it against new records across the deployed fleet, currently 92% more per day than last year.

Our Journey

2024

Initial idea

Started with a conviction that securing a software supply chain has to happen where the software is built, not after the fact

2025

CRACI founded in Helsinki

Four co-founders set out to build the security evidence into the build pipeline itself

2026

โ‚ฌ1.4M pre-seed

Led by Lifeline Ventures, with participation from First Fellow Partners and Wave Ventures

Backed By Leading Investors

Lifeline Ventures logo
Lifeline Ventures
First Fellow Partners logo
First Fellow Partners
Wave Ventures logo
Wave Ventures

Why Invest in CRACI?

Demand that isn't discretionary

Supply chain attacks are accelerating and disclosure volume is rising faster than headcount ever will. Regulation such as the EU's Cyber Resilience Act turns that pressure into a deadline: security evidence becomes a condition of selling, not a line item to defer.

A defensible technical position

Owning the build runner is hard to retrofit and hard to copy. It is what makes an SBOM provably complete instead of best-effort, and it puts CRACI in the pipeline rather than beside it.

Backed by Nordic operators

A team of 14 in Helsinki, with four co-founders across engineering, product and security, backed by Lifeline Ventures, First Fellow Partners and Wave Ventures.

Partner With Us

Interested in learning more about investment opportunities? Get in touch with our team.