92% more reported CVEs per day in 2026 than last year.
CRACI

Security at CRACI

Documented, not asserted

Teams rely on CRACI for the evidence behind their compliance claims, so we hold our own security to the same standard. A claim is only worth the evidence behind it, and that applies to us as much as to the SBOMs we generate.

Our Trust Center is where we publish that evidence. It lists how we handle security today and stays current as our program grows, so you can review it before you bring CRACI into your supply chain.

What you'll find in the Trust Center

Policies

The information security policies that govern how we build, run and support CRACI.

Controls

The security controls we have in place across the company and the platform, and where each one stands.

Documentation

The security documentation your team needs to complete a vendor assessment of CRACI.

Review our security posture

Browse our policies and controls, or request documentation for your vendor assessment.

Visit the Trust Center