What we do

The evidence layer between security and audit.

CVET turns raw scanner output into continuous, auditor-ready proof — mapped to the frameworks European SMEs actually answer to. Here’s what that looks like in practice.

Continuous Evidence Collection

Connect a repository and CVET scans it on a schedule, normalising every finding into one system of record — no manual screenshots, no spreadsheets.

Always-on

Cross-Framework Mapping

Each finding is mapped once to the controls it satisfies across ISO 27001, NIS2, CRA and SOC 2 — so one piece of evidence proves many obligations.

ISO · NIS2 · CRA

Remediation Traceability

Follow every issue from found → fixed → scan-verified, with a tamper-evident history that shows risks actually get closed.

Auditable

Auditor-Ready Reporting

Generate coverage matrices, SBOMs and point-in-time evidence packs on demand — organised the way an assessor expects to read them.

On demand

Secure Credential Handling

Named credentials are encrypted at rest and every access to your code is recorded in a verifiable log. Least-privilege by design.

Encrypted

Self-Hosted Deployment

Run CVET as a single binary next to your data — EU residency, air-gap friendly, your evidence never leaves your walls.

EU residency

Launching soon · Stay tuned

Stop proving compliance by hand.

We’re building in the open. Join the waitlist for founder pricing and first access at launch.

No spam, ever. We’ll email you the moment it’s ready.

Self-hostedEU data residencyNo spam, ever