Insights

Research, writeups, and plain-language notes.

Vulnerability writeups and notes on the CRA and product security. This is where we show the work.

Am I in scope for the CRA? The five questions that decide it.

The scope logic of the Cyber Resilience Act in plain language: what counts as a product with digital elements, who in the chain carries the duties, and what being in scope obliges you to do before December 2027.

Read →
Vulnerability writeups, under embargo for now

Findings from our scanner are moving through coordinated disclosure with the affected projects. The writeups publish here once fixes ship and the embargoes lift.

Embargoed
More writeups
in progress