Take supply chain security to your clients
Sell CRACI, run it for your clients, or put it behind your own brand. Every model is on the table, and you earn up to 20% commission on ARR for two years.
Work with us the way that fits your business
Three common shapes, and combinations of them. If the model you have in mind is not here, propose it โ all models are possible.
Resell
Sell CRACI under your own commercial agreement. You own the customer relationship and the invoice; we support you behind it.
Operate
Run CRACI on your client's behalf: set up the runners, hold the egress policy, review what the builds record and report back.
White label
Put CRACI behind your own brand and deliver supply chain security as part of your own service.
Up to 20%
of annual recurring revenue, for two years
Commission is paid on the ARR of the customers you bring, for the first two years of each account. The rate depends on the model you choose and how much of the relationship you carry โ we agree it with you before you sell anything.
What one customer can be worth
A worked example, not a quote: a mid-sized company running 2 million build minutes a month, with a portfolio of products kept under continuous monitoring.
| Line | Working | Per month |
|---|---|---|
| Build minutes | 2,000,000 a month at โฌ0.004 a minute | โฌ8,000 |
| Continuous monitoring | Scales with how many SBOMs and products they keep under watch | about โฌ5,000 |
| Customer pays | Around โฌ156,000 a year | about โฌ13,000 |
~โฌ31,000
Your commission in year one, at the full 20% of that ARR
~โฌ62,000
Across the two years commission is paid, from this one customer
Round numbers, and deliberately so. Build minutes come off the published rate on our pricing page; what a customer pays for monitoring depends on how many SBOMs and products they keep under watch. A customer at this scale would be on an Enterprise agreement with its own terms, and 20% is the top of the range โ treat this as the shape of the opportunity rather than a number to quote a client.
Who we are looking for
Firms whose clients already trust them with how software gets built, secured, or signed off.
Software consultancies
You already build and ship for your clients. CRACI replaces the runner their pipelines use, so every release comes with an SBOM and signed provenance without changing how they work.
Cyber security consultancies
Your clients ask what is actually in their software. CRACI records the packages each build really pulled in, so your advice rests on evidence from the build rather than a scan taken nearby.
Compliance consultants
CRA reporting obligations have applied since 11 September 2026, with the regulation applying in full from 11 December 2027. CRACI produces the supply chain evidence your clients' process needs.
What you get from us
A partnership is more than a discount code. Here is what comes with it.
Sales enablement and training
Full sales enablement materials โ decks, battlecards, demo scripts and the evidence behind every claim โ plus ongoing training as the product moves, so your team keeps selling the current CRACI rather than last quarter's.
Partner portal
Register and claim the deals you are working, follow them through to close, and see what commission each one has earned. No spreadsheets passed back and forth, and no argument about who brought which customer.
A dedicated partner manager
One named person on our side who knows your business, joins your client calls when you want them there, and is accountable for getting you answers.
What you are selling
CRACI replaces the runner, not the pipeline: runs-on: craci, and
the runs still appear in GitHub. It is a recorder rather than a scanner,
observing the release build as it happens. GitHub Actions is the supported CI
integration today, and builds execute on European bare-metal infrastructure.
Cheaper CI builds
About 23% below GitHub's list price for a standard 2 vCPU Linux runner, and metered per second rather than rounded up to the whole minute โ so pipelines made of many short jobs save the most.
Faster builds
About twice as fast as GitHub's standard hosted runners, on sizes from 1 to 32 compute units, native x86-64 and ARM64 at the same rate.
Advanced supply chain security
Egress policy enforced at the runner, validated before the job starts and failing closed. Signed provenance, Ed25519 over SHA-512, ties each artifact โ including OCI images โ to the build that produced it.
SBOMs and continuous vulnerability tracking
An SBOM per build, exported as CycloneDX or SPDX, re-evaluated as new vulnerabilities land, with reports in PDF, HTML, CSV, Excel or JSON. The CRA and the US FDA's section 524B ask for an SBOM outright; NIS2 and ISO 27001 ask for supply chain security and vulnerability handling, where an SBOM and continuous monitoring are the evidence.
Apply to the partner program
Tell us about your firm and how you would like to work with CRACI. After you send this you can book a call with Arturs straight away.
Thanks โ we have your application
Pick a time with Arturs below and we'll go through the models, the commission and what your clients need.