An SBOM for every version
A software bill of materials in CycloneDX for each product version, with a note on gaps. SPDX on request.
Taking our first founding clients
SBOMs, exploited-vulnerability checks, VEX and ENISA report drafts for device makers with 10 to 249 staff. Your team reviews and signs. We do the preparation.
Or email [email protected]
Why now
The CRA arrives in steps. Your customers often ask for the evidence before the law does.
11 Sep 2026 In force
Manufacturers must report actively exploited vulnerabilities: an early warning in 24 hours, a notification in 72 hours and a final report within 14 days after a fix.
Q4 2026 Customers ask
Large OEMs ask suppliers for CRA evidence. For example, Honeywell's supplier page asks each supplier for a CRA attestation or roadmap by Q4 2026, with a machine-readable SBOM per component.
11 Dec 2027 Main duties
Products on the EU market must meet the CRA requirements. This includes a technical file that shows how each product meets them.
What you get
For each product family, we prepare the documents that your customers and the authorities can ask for.
A software bill of materials in CycloneDX for each product version, with a note on gaps. SPDX on request.
Every day, we check each SBOM against CISA KEV, the EU Vulnerability Database (EUVD) and OSV.
With maintenanceA VEX draft for each match, with the reason. Your engineer confirms each "not affected" status.
Prefilled templates for the 24-hour early warning, the 72-hour notification and the final report. You file them.
What exists, where it lives, and a list of gaps with owners. With draft policies for disclosure, security contact and support period.
Answers to the CRA questionnaires that your customers send, based on the evidence. You sign and send them.
How it works
We do the preparation. Your engineers check it, and your company signs and files.
We talk about your products and what your customers ask for. We sign an NDA and a data processing agreement before we see any data.
We list products, versions and support periods. We build an SBOM for each version, from your build or from build files that you send.
We check the SBOMs against exploited-vulnerability lists. We draft VEX, ENISA reports, policies and questionnaire answers.
Your engineers confirm each VEX status. You sign the documents and file each report.
We aim to finish the setup of one product family in 2 to 3 weeks.
Pricing
A product family is up to 3 related products on one code base.
€2,500
per product family, one time
€450 / month
per product family
Founding clients
Relvault is new. The first 3 to 5 clients pay €1,500 for setup instead of €2,500. Their monthly price stays the same for 12 months. In return, we ask for honest feedback and, if you are satisfied, a short testimonial.
Setup: you pay 50% at signing and 50% on delivery. Maintenance: invoiced monthly in advance. Prices exclude VAT.
Clear limits
We prepare technical evidence. Legal and conformity decisions stay with you and your advisers.
Who runs Relvault
Relvault is run by Chhabi Acharya, a software engineer based in Nepal. Relvault is new and small: when this site says "we", it means Chhabi.
He works with clients remotely, in English.
FAQ
No. We prepare evidence. We do not certify products or decide conformity, and we never call a product "compliant". You sign the EU declaration of conformity. Where the CRA requires it, a notified body assesses the product.
No. We do not interpret the law for your case, for example the scope or the product class. When a question needs a lawyer, a test lab or a CRA consultancy, we tell you.
Not always. We can set up open-source SBOM tools in your build pipeline together with your engineers, or run them on build files that you send. We do not ask for long-lived access to your systems.
By default, the evidence stays in your own repository. We keep working copies only while the work needs them, encrypted on Chhabi's work computer in Nepal, and we delete them when the contract ends. We sign an NDA and a data processing agreement before we see any data. We do not put your data into third-party AI tools without your written consent.
Yes, if the work around the SBOM takes your engineers' time. We use your SBOMs as they are and add the rest: the exploited-vulnerability check, VEX drafts, ENISA report drafts, the technical-file index and questionnaire answers.
Chhabi lives in Nepal. The work does not need an office: SBOMs, checks and documents are remote work. Nepal is 3 h 45 min to 4 h 45 min ahead of Central European Time, so calls fit the European early afternoon. The GDPR applies to our work in full.
Send a short email. Tell us what your product is and what your customers ask for.