TRACEABLE COMPLIANCE INTELLIGENCE

Compliance evidence that traces itself.

Scanner findings to auditor-ready proof — every fix traced from commit to production. CRA, NIS 2, DORA, SOC 2, ISO 27001.

No spam. Unsubscribe anytime. Join 400+ engineers on the waitlist.

NIS 2
DORA
SOC 2
ISO 27001
CRA

Your data never leaves your premise · Self-hosted · EU-first

WHY CVET

Your scanners already have the evidence. CVET makes it count.

Connect Trivy, Snyk, Wiz, or Checkov. CVET normalises findings, maps them to controls across five frameworks, and generates audit packs — continuously.

No new scanners to deploy. No evidence to chase. Remediation traced from ticket to PR to production.

200 → 20 hrs

Monthly compliance engineering time

5 min

To first evidence graph after connecting a scanner

€0

New tools to buy — works with your existing stack

WHY NOW

The compliance clock is already ticking.

Three EU mandates. One enforcement wave. Click any card to learn what it means for your team.

LIVE

Jan 2025

Enforcement began

DORA

Digital Operational Resilience Act

ICT risk management for 20 categories of EU financial entities. Evidence obligation is immediate and auditable.

Banks, payment processors, insurers, and crypto providers must prove continuous vulnerability management and remediation traceability. Supervisory authorities can request evidence at any time.

LIVE

160,000+

Organisations in scope

NIS 2

Network & Information Security Directive

160,000+ enterprises across 18 critical sectors. Supply-chain security and board-level accountability are mandatory.

Covers energy, transport, healthcare, digital infrastructure, and more. Boards are personally liable for non-compliance. Fines up to €10M or 2% of global turnover.

SEPT 2026

24 hrs

Vulnerability reporting window

CRA

EU Cyber Resilience Act

Mandatory 24-hour vulnerability reporting and SBOM requirements for all products with digital elements sold in the EU.

Security-by-design obligations, coordinated vulnerability disclosure, and full enforcement by December 2027. If you sell software in Europe, this applies to you.

STRATEGIC

EU-first

Data residency by default

Data Sovereignty

EU Data Residency & Sovereignty

EU enterprises increasingly require that compliance evidence stays within European borders. US-only platforms are losing deals.

GDPR Article 25 data protection by design, Schrems II implications, and growing demand for European cloud infrastructure (Hetzner, Scaleway, OVH). CVET is EU-hosted by default.

THE PLATFORM

One platform.
Five frameworks.
Zero drama.

Automation without traceability is just faster guesswork. CVET traces every finding to a control, every fix to a deploy.

Evidence Intelligence Layer

Normalise and contextualise scanner output from Snyk, Wiz, Checkov, and Trivy. One system of record for all findings.

All Frameworks

Cross-Framework Control Mapping

One control satisfies multiple frameworks. Map findings to SOC 2, ISO 27001, NIS 2, DORA, and CRA automatically.

All Frameworks

Evidence Graph

Structured graph linking findings, controls, owners, and remediation states. Live posture score with drill-downs.

NIS 2 · DORA

Remediation Traceability

Track finding → ticket → PR → deployment with auditable lineage. End-to-end proof that risks get fixed.

DORA · SOC 2

Audit Pack Generator

Generate auditor-ready evidence packs continuously. Pre-organised, timestamped, tamper-evident packages.

ISO 27001 · SOC 2

Platform Exports

Push engineering-grade evidence into Vanta, Drata, and Secureframe. Your compliance platform, powered by real data.

CRA · NIS 2

FRAMEWORKS

One scan covers every framework that matters.

SOC 2 Type II

COVERED
  • CC controls automated
  • Continuous monitoring
  • Auditor evidence portal
Covered

ISO 27001:2022

COVERED
  • Annex A mapping
  • Risk register integration
  • ISMS policy templates
Covered

NIS 2 Directive

LIVE
  • 72hr notification workflows
  • Supply chain risk assessment
  • Board reporting
Covered

DORA

LIVE
  • ICT risk management evidence
  • Remediation traceability
  • Continuous detection proof
Covered

EU Cyber Resilience Act

SEPT 2026
  • SBOM generation
  • Vulnerability disclosure
  • SDL checklists
Covered

HOW IT WORKS

Audit-ready in three steps.

STEP 01

Plug In Your Scanners

Trivy, Snyk, Wiz, Checkov — connect what you already run. First evidence graph in under five minutes.

STEP 02

Map Findings to Controls

Every finding maps to controls across CRA, NIS 2, DORA, SOC 2, and ISO 27001. Gaps surface automatically.

CVET

STEP 03

Ship the Audit Pack

Evidence packs generate continuously. Every fix traced from ticket to PR to deploy. Hand it to the auditor, not a spreadsheet.

Stop proving compliance by hand.

Early access. Founder pricing. Your first evidence graph in five minutes.

No spam. Unsubscribe anytime. Join 400+ engineers on the waitlist.

Self-hostedEU data residencyNo spam, ever