TRACEABLE COMPLIANCE INTELLIGENCE

Compliance evidence that traces itself.

Scanner findings to auditor-ready proof — every issue traced from finding to scan-verified fix. ISO 27001, NIS2, CRA, SOC 2.

No spam, ever. We’ll email you the moment it’s ready.

ISO 27001
NIS2
CRA
SOC 2

Your data never leaves your premise · Self-hosted · EU-first

WHY CVET

Your scanners already have the evidence. CVET makes it count.

The findings already exist. The proof doesn’t. It’s scattered across 10+ tools, screenshots, and spreadsheets — then rebuilt by hand before every audit.

CVET turns that scramble into one continuous, auditor-ready record.

“A lot of time was spent manually organizing screenshots, reports, and approvals.”
— Security Engineer, Enterprise (1,000+) · from our practitioner interviews

What practitioners told us

1–6 months

Typical audit-prep time practitioners reported

10+ tools

Evidence sources teams juggle before an audit

€10–50k/yr

Budget teams allocate to fix this

WHY NOW

The compliance clock is already ticking.

Three EU mandates. One enforcement wave. Click any card to learn what it means for your team.

LIVE

Jan 2025

Enforcement began

DORA

Digital Operational Resilience Act

ICT-risk evidence for EU financial entities — auditable on demand.

Banks, payment processors, insurers, and crypto providers must prove continuous vulnerability management and remediation traceability. Supervisory authorities can request evidence at any time.

LIVE

160,000+

Organisations in scope

NIS 2

Network & Information Security Directive

160,000+ orgs across 18 sectors. Board-level accountability is mandatory.

Covers energy, transport, healthcare, digital infrastructure, and more. Boards are personally liable for non-compliance. Fines up to €10M or 2% of global turnover.

SEPT 2026

24 hrs

Vulnerability reporting window

CRA

EU Cyber Resilience Act

24-hour vulnerability reporting + SBOMs for any product sold in the EU.

Security-by-design obligations, coordinated vulnerability disclosure, and full enforcement by December 2027. If you sell software in Europe, this applies to you.

STRATEGIC

EU-first

Data residency by default

Data Sovereignty

EU Data Residency & Sovereignty

EU buyers want evidence to stay in Europe. US-only tools lose deals.

GDPR Article 25 data protection by design, Schrems II implications, and growing demand for European cloud infrastructure (Hetzner, Scaleway, OVH). CVET is EU-hosted by default.

THE PLATFORM

One platform.
Four frameworks.
Zero drama.

Automation without traceability is just faster guesswork. CVET traces every finding to a control, every fix to a deploy.

One system of record

Every scanner's output — Trivy, Semgrep, Snyk, SARIF — normalised in one place.

Map once, cover four

One control satisfies ISO 27001, NIS2, CRA and SOC 2 at the same time.

Proof it got fixed

Every risk traced from finding to scan-verified, on a tamper-evident log.

Auditor-ready in a click

Coverage matrix, CycloneDX SBOM and point-in-time evidence, on demand.

FRAMEWORKS

One scan covers every framework that matters.

ISO 27001:2022

COVERED
  • Annex A control mapping
  • Coverage & gap detection
  • Point-in-time evidence packs
Covered

NIS2 Directive

COVERED
  • Art. 21 control mapping
  • Remediation traceability
  • Continuous scanning
Covered

EU Cyber Resilience Act

COVERED
  • CycloneDX SBOM
  • Vulnerability evidence
  • Coverage & gaps
Covered

SOC 2

COVERED
  • CC control mapping
  • Continuous evidence
  • Coverage matrix export
Covered

DORA

COMING
  • ICT-risk control mapping
  • Evidence traceability
On the roadmap

HOW IT WORKS

Audit-ready in three steps.

STEP 01

Point It at a Repo

Bundled Trivy + Semgrep scan it — or ingest Snyk, Checkov, SARIF/OCSF.

STEP 02

Map Findings to Controls

Auto-mapped to ISO 27001, NIS2, CRA and SOC 2. Gaps surface instantly.

CVET

STEP 03

Ship the Audit Pack

Auditor-ready packs on demand — every fix scan-verified. Not a spreadsheet.

Launching soon · Stay tuned

Stop proving compliance by hand.

We’re building in the open. Join the waitlist for founder pricing and first access at launch.

No spam, ever. We’ll email you the moment it’s ready.

Self-hostedEU data residencyNo spam, ever