Manufacturers
Teams placing products with digital elements on the EU market and maintaining them.
Secure by Evidence
Structure the CRA product-security work you already do — products, releases, assessments, SBOMs, vulnerabilities, evidence, documents and post-market monitoring — in one connected lifecycle.
Who the CRA affects
The Cyber Resilience Act creates obligations around products with digital elements across development, release, vulnerability handling and the support period. The exact legal role and scope depend on your product and position in the supply chain.
Teams placing products with digital elements on the EU market and maintaining them.
Teams that need repeatable security evidence across releases, components and support.
Organizations that need reliable product-security information from their supply chain.
The problem
Security work is usually spread across tickets, spreadsheets, scanners, repositories and documents. CRA increases the cost of that fragmentation because decisions need context, evidence and lifecycle traceability.
Release decisions and supporting material are hard to reconstruct later.
Scanner findings are not the same as product decisions, ownership or remediation status.
People spend time collecting status instead of improving the product.
Who we are
AA-sec is built by engineers used to traceable decisions, repeatable QA and long product lifecycles. We use that discipline to make CRA work operational instead of document-only.
How AA-sec helps
AA-sec Platform links the work from product definition through release and post-market monitoring without replacing the engineering tools your teams already use.
What the platform includes
Each capability stays connected to products and releases so the status you see has context and the evidence behind it remains traceable.
Structure products, variants and releases and keep security work attached to the lifecycle it belongs to.
Run structured CRA assessments and checklists while keeping the final decision with your organization.
Connect SBOMs and component information to the product and release they describe.
Track vulnerability candidates, decisions and remediation context instead of stopping at a scanner result.
Keep supporting material connected to the decisions, assessments and releases it proves.
Generate repeatable outputs from structured product and evidence data.
Support post-market monitoring and structured handling of relevant external facts and reporting workflows.
Connect existing engineering and security workflows through APIs, service access and integrations.
Security by design
The platform is designed around tenant-scoped access and protected customer data. Security claims are kept separate from legal compliance claims.
Authorization and data access are scoped to the customer organization.
Confidential values and customer files use application-level protection controls.
Our hosted service is positioned for EU customers with GDPR requirements in mind.
Planned annual independent security reviews as the service moves through commercial rollout.
See the workflow
The demo is a separate environment for exploring the product experience. It does not change the website deployment and is maintained independently.
Pricing
All platform features included. The base subscription includes one organization, unlimited users and one product.
Annual
€490
per month, billed on an annual contract
Monthly
€590
per month
Additional products: +€290 per product/month. 6+ products: volume terms by contract. Onboarding: €4,900 one-time where not included. Training: €3,000/day. On-prem from €12,000/year. Custom integrations: T&M. Prices exclude VAT. Non-binding request until the contract is signed.
Small Business Program
Tell us about your product and company. We review Small Business Program requests individually rather than removing platform capabilities.
Contact
Ask a question, request a plan or tell us about your Small Business Program case. We will respond with the next concrete step.