EU compliance needs more than a generic scanner.
The Cyber Resilience Act requires manufacturers to identify and document product components and vulnerabilities, address vulnerabilities throughout the support period, and maintain technical documentation. Farion combines transitive SBOMs, evidence-backed VEX and license analysis in one workflow built for European software teams.*
Transitive SBOMs
The whole dependency tree — not just your direct dependencies.
Real VEX
What's actually exploitable, with evidence — not a finding list.
Deep license testing
The actual license text from the code — not a registry guess.
Generic scanner output is not enough for CRA-ready vulnerability handling.
A package list and a CVE list do not show whether a component ships with the product, whether vulnerable code is reachable, or why a vulnerability can be classified as affected or not affected. Farion turns these signals into structured evidence for remediation and technical documentation.
They stop at the minimum dependency list
The CRA requires an SBOM covering at least top-level dependencies. Resolving the transitive dependency tree provides the fuller component inventory needed to investigate newly disclosed vulnerabilities across the software supply chain.
They stop at CVE lists
Raw vulnerability lists do not provide reachability, application-specific exploitability or a justification for an affected or not-affected decision.
They rely on registry license metadata
Registry license metadata can be incomplete or incorrect. Farion analyzes the license files shipped with the dependency and evaluates the resulting obligations against the configured policy.
Developed in Germany for European software teams.
Farion is developed in Berlin by engineers with years of experience building cloud-native platforms, security automation and DevSecOps systems in complex and regulated environments. The platform was designed around European data-residency, deployment and evidence requirements from the outset.
The hard parts, done properly.
The three capabilities that decide whether your compliance evidence holds up — each one built deeper than the market standard.
Transitive SBOMs
Inventory the entire dependency tree, resolved and reachable — exported as CycloneDX or SPDX.
The full tree, not the top level
Every transitive dependency that ships with your product, resolved and attributed.
Reachability built in
See which components are actually reachable, so your SBOM carries context, not just names.
Dependencies
Risk & Exploitation
Ecosystem & License
Real VEX & exploitability
A defensible affected / not-affected verdict per vulnerability, with the evidence behind it.
Exploitability, not a CVE count
Farion reasons about reachability and data flow to say what is genuinely exploitable in your product.
Traceable evidence for audit review
Every verdict carries its justification — the raw material of a VEX statement.
AI Analysis by Farion
True PositiveThis CVE-2024-38816 path traversal in spring-webmvc is reachable through the /api/v1/files/upload endpoint. The vulnerable FileSystemResource is directly instantiated with user-controlled input from the request path parameter without sanitization.
Deep license testing
Extract the real license text from the source and catch the copyleft traps that metadata hides.
The actual license text
Farion reads the license from the code itself, not the registry field that is so often wrong or empty.
Copyleft caught early
Strong-copyleft obligations are flagged with the clause and the risk — before they reach your customers.
Structured compliance evidence, not another finding list.
Farion produces versioned artifacts for vulnerability handling and technical documentation, including transitive SBOMs, evidence-backed VEX statements and license reports.
SBOM
CycloneDX and SPDX, transitive and complete.
VEX statements
Exploitability determinations with justification, per finding.
License report
Extracted texts, obligations and policy verdicts your legal team can sign.
Make your software compliance future-proof.
Prepare for CRA vulnerability handling with transitive SBOMs, evidence-backed VEX and deep license analysis in one workflow.