FARION.AI
  • Home
  • Product
      • Platform
      • Platform overview
      • Exploitability Analysis
      • Supply Chain Security
      • Vulnerability Management
      • Active Verification
      • Software License Compliance
      • Solutions
      • Cyber Resilience Act
      • NIS2 Compliance
      • SaaS Application Security
      • AI-Generated Code Security
      • Container Security
      • Pricing
      • Plans & pricing
      • About
      • Technology overview
      • Contact us
      • Imprint
      • Privacy
      • Farion dashboard
        Start free now
  • About
Sign in
Start free now
The compliance hub for software

EU compliance needs more than a generic scanner.

The Cyber Resilience Act requires manufacturers to identify and document product components and vulnerabilities, address vulnerabilities throughout the support period, and maintain technical documentation. Farion combines transitive SBOMs, evidence-backed VEX and license analysis in one workflow built for European software teams.*

* Regulation (EU) 2024/2847, Annex I Part II and Annex VII.

Start free nowNo credit card required
Book a technical demo
Transitive SBOMs

The whole dependency tree — not just your direct dependencies.

VEX with justification

What's actually exploitable, with evidence — not a finding list.

Deep license testing

The actual license text from the code — not a registry guess.

The problem with most tools

Generic scanner output is not enough for CRA-ready vulnerability handling.

A package list and a CVE list do not show whether a component ships with the product, whether vulnerable code is reachable, or why a vulnerability can be classified as affected or not affected. Farion turns these signals into structured evidence for remediation and technical documentation.

They stop at the minimum dependency list

The CRA requires an SBOM covering at least top-level dependencies. Resolving the transitive dependency tree provides the fuller component inventory needed to investigate newly disclosed vulnerabilities across the software supply chain.

They stop at CVE lists

Raw vulnerability lists do not provide reachability, application-specific exploitability or a justification for an affected or not-affected decision.

They rely on registry license metadata

Registry license metadata can be incomplete or incorrect. Farion analyzes the license files shipped with the dependency and evaluates the resulting obligations against the configured policy.

Built for the European market

Developed in Germany for European software teams.

Farion is developed in Berlin by engineers with years of experience building cloud-native platforms, security automation and DevSecOps systems in complex and regulated environments. The platform was designed around European data-residency, deployment and evidence requirements from the outset.

What Farion does that others don't

The hard parts in detail.

The three capabilities that decide whether your compliance evidence holds up.

Transitive SBOMs

Inventory the entire dependency tree, resolved and reachable — exported as CycloneDX or SPDX.

The full tree, not the top level

Every transitive dependency that ships with your product, resolved and attributed.

Reachability built in

See which components are actually reachable, so your SBOM carries context, not just names.

Sample data · as of October 2026
FILTERS
Payments Platformpayment-service
mainJun 11, 2026, 9:00 AM
​
/
​

Dependencies

Reachability
All
​
Source
All
​

Risk & Exploitation


Ecosystem & License


Saved views
KEV + Fix
Reachable + Fix
No Fix Available
Tip: click column headers to sort.

VEX with justification & exploitability

A defensible affected / not-affected verdict per vulnerability, with the evidence behind it.

Exploitability, not a CVE count

Farion reasons about reachability and data flow to say what is genuinely exploitable in your product.

Traceable evidence for audit review

Every verdict carries its justification — the raw material of a VEX statement.

Sample data · as of October 2026
AI analysis by Farion
True Positive

CVE-2024-38816 (path traversal in spring-webmvc functional endpoints) is reachable: GET /files/** serves static resources via RouterFunctions.resources() from a FileSystemResource location, and the request path reaches PathResourceLookupFunction without normalization.

Key evidence
  • Route GET /files/** registered via RouterFunctions.resources()
  • Resource location is a FileSystemResource
  • spring-webmvc 6.1.12 in affected range (fixed in 6.1.13)
  • EPSS 14.7 % (96th percentile), as of 2026-09-29

Deep license testing

Extract the real license text from the source and catch the copyleft traps that metadata hides.

The actual license text

Farion reads the license from the code itself, not the registry field that is so often wrong or empty.

Copyleft caught early

Strong-copyleft obligations are flagged with the clause and the risk — before they reach your customers.

Sample data · as of October 2026
License Identity
GPL-2.0-or-later
Registry & scan match
Detected fromScancode
License file
license.md
Confidence96%
Classification
TypeStrong copyleft
Copyleft
strong
Obligations
Disclose SourceSame LicenseState ChangesInclude License
Copyright Holders
Ephox Corporation DBA Tiny Technologies, Inc
License Text
Full details

The licenses for most software are designed to take away your freedom to share and change it. By contrast, the GNU General Public License is intended to guarantee your freedom to share and change free software--to make sure the software is free for all its users.

Package Info
Web based JavaScript HTML WYSIWYG editor control
Repository
https://github.com/tinymce/tinymce
Policy
Verdict
License not on allowlist
The output

Structured compliance evidence, not another finding list.

Farion produces versioned artifacts for vulnerability handling and technical documentation, including transitive SBOMs, evidence-backed VEX statements and license reports.

SBOM

CycloneDX and SPDX, transitive and complete.

VEX statements

Exploitability determinations with justification, per finding.

License report

Extracted texts, obligations and policy results as a basis for your legal review.

Make your software compliance future-proof.

Prepare for CRA vulnerability handling with transitive SBOMs, evidence-backed VEX and deep license analysis in one workflow.

Start free nowNo credit card required
Book a technical demo

FARION.AI

The Farion platform combines native SAST, exploitability-aware SCA with SBOM, VEX and license compliance, and SAST-informed active AI verification.

Platform
Platform overviewExploitability AnalysisSupply Chain SecurityVulnerability ManagementActive VerificationLicense Compliance
Solutions
Cyber Resilience ActNIS2 ComplianceSaaS Application SecurityAI-Generated Code SecurityContainer SecurityCompliance
Scanners
SASTSCADAST
Technology
Technology overviewVulnerability IntelligenceRoute & Data Flow AnalysisLanguages & FrameworksArchitecture & DeploymentIntegrations
Farion
About usPricingFAQsSecurityContact us
Legal
ImprintPrivacyTerms and Conditions (AGB)
Contact
sales@farion.ai

© All rights reserved.