Product tour · sample data

See the system of record before the call.

Nine screens with realistic sample data from a fictional manufacturer, Acme Connected Systems GmbH — the same records a security engineer, a product owner and the assigned representative work with every day. Nothing here is a customer, a benchmark or a claim: values are invented; CVE identifiers are real public advisories so the intelligence columns look the way they do in the product.

Product registry

Demo data · Acme Connected Systems GmbH is fictional

Every obligation attaches to a product placed on the EU market. The registry holds lifecycle state, classification with reasoning and approver, owners, support period, versions and SBOM status — and shows gaps as gaps.

ProductTypeClassificationLifecycleSupport periodOwner / security ownerVersionsSBOMExposed
EdgeGate RouterHybrid (hardware + firmware)Important · Class I
Router / modem (Annex III)
Active2024-03 → 2029-03L. Brandt / M. Keller3Matched 2 h ago4
DeviceHub DesktopSoftwareDefault
Desktop software
Active2023-06 → 2028-06S. Okafor / M. Keller5Matched 2 h ago2
SensorLink FirmwareHardware (embedded)Default
IoT device firmware
Active2025-01 → 2030-01L. Brandt / J. Weiss2Matched 2 h ago1
FleetSync Cloud AgentSoftwareDefault
Remote management agent
DevelopmentNot yet placed on the marketS. Okafor / — (gap)1No SBOM (gap)0

Component inventory

Demo data · Acme Connected Systems GmbH is fictional

One deduplicated catalogue across every SBOM, keyed by package URL: which products contain a component, whether it is a direct or transitive dependency, its licence and its current exposure.

Package URLVersionLicenceUsed byDependencyOpen findings
pkg:npm/lodash@4.17.204.17.20MITDeviceHub Desktoptransitive1
pkg:golang/golang.org/x/net@0.15.00.15.0BSD-3-ClauseEdgeGate Router, FleetSync Cloud Agentdirect1
pkg:generic/openssl@3.0.123.0.12Apache-2.0EdgeGate Router, SensorLink Firmwaredirect1
pkg:generic/busybox@1.36.11.36.1GPL-2.0-onlyEdgeGate Router, SensorLink Firmwaredirect0
pkg:npm/electron@28.1.028.1.0MITDeviceHub Desktopdirect1
pkg:pypi/requests@2.31.02.31.0Apache-2.0FleetSync Cloud Agentdirect0

SBOM ingestion

Demo data · Acme Connected Systems GmbH is fictional

An SBOM arrives from CI, the API, the GitHub App or an upload. The original file is preserved with its checksum; components are parsed, deduplicated, diffed against the previous version and matched — every step timestamped.

File
edgegate-router-3.2.0.cdx.json
Format
CycloneDX 1.5 (JSON)
Product · version
EdgeGate Router · 3.2.0
Source
CI pipeline via API token (release job)
Checksum · size
sha256:7f3c…a91e · 412 KB
Uploaded
2026-09-18 06:42 CEST
Parsed
2026-09-18 06:42 CEST · parser 2.3.0
Components
1,284 (96 direct · 1,188 transitive)
Matched
2026-09-18 06:44 CEST · OSV + GitHub advisories · enriched with CISA KEV and EPSS
Findings
7 new · 1 known exploited · 1 fix available
Diff vs previous
+14 components, −9 components, 3 version bumps vs 3.1.4

Vulnerability queue

Demo data · Acme Connected Systems GmbH is fictional

Ranked by exploitation evidence, not alphabetically. Every row carries the product on the market it affects, the human triage state with its reason, the explicit CRA review answer and the remediation owner.

PriorityAdvisoryComponent · productSeverityKEVEPSSTriage stateCRA reviewOwner · due
94CVE-2023-44487golang.org/x/net 0.15.0
EdgeGate Router 3.2.0
High 7.5exploited0.82Confirmed reportable
HTTP/2 rapid-reset exhaustion reachable on the remote-management API; exploitation in the wild is documented.
ConfirmedM. Keller
Fix in 3.2.1 (released)
78CVE-2024-3094xz 5.6.0
SensorLink Firmware 1.4.2
Critical 10.0—0.31In remediation
Backdoored build present in the toolchain image; no evidence of exploitation on shipped devices, review open.
Potentially reportableJ. Weiss
2026-09-25
58CVE-2024-27980node 20.11.0
DeviceHub Desktop 2.0.1
High 8.1—0.06Triaged · affected
Windows batch injection needs local shell access; not remotely exploitable in this product.
Not reportableS. Okafor
2026-10-15
29CVE-2021-23337lodash 4.17.20
DeviceHub Desktop 2.0.1
High 7.2—0.02Not affected (VEX)
Vulnerable function (_.template) not used; VEX statement published.
Not reportableS. Okafor
—
22CVE-2023-5678openssl 3.0.12
EdgeGate Router 3.2.0
Medium 5.3—0.01New
Awaiting triage.
Not reviewed—
SLA: 10 days

Prioritisation — why the top finding is on top

Demo data · Acme Connected Systems GmbH is fictional

Priority is explainable: each factor and its weight are shown on the finding, and organisations can tune the weights. Reachability is recorded by a reviewer; Vellaci never infers it.

CVE-2023-44487
94 / 100

golang.org/x/net 0.15.0 in EdgeGate Router 3.2.0. Sources: OSV, GitHub advisories, CISA KEV, FIRST EPSS — each with fetched, checked and modified times.

  • Active exploitation (CISA KEV)
    Listed 2023-10-10; the strongest single signal for Article 14.
    +40
  • EPSS 0.82 (30-day exploitation probability)
    Top 2 % of all CVEs scored that day.
    +24
  • CVSS 7.5, network vector, no privileges
    Base score contributes; exploitability matters more than severity alone.
    +14
  • Product on the EU market · Important Class I
    Regulatory exposure of the affected product.
    +10
  • Component reachable (HTTP/2 remote-management API)
    Recorded by the reviewer; Vellaci never infers reachability.
    +6

Incident timeline

Demo data · Acme Connected Systems GmbH is fictional

From a finding to a final report, every step has a person, a timestamp and a recorded reason. Awareness is confirmed by a named person under a written rule — that confirmation, not a ticket timestamp, starts the Article 14 clocks.

  1. 2026-09-18 06:44Vellaci (matching job)Finding created: CVE-2023-44487 in EdgeGate Router 3.2.0 — KEV listed, EPSS 0.82.
  2. 2026-09-18 08:05M. Keller (security owner)Triage: affected, exploitation evidence acknowledged, reachable on the HTTP/2 remote-management API. Remediation assigned.
  3. 2026-09-18 08:11M. KellerAwareness confirmed: 2026-09-18 08:05 CEST (revision 1). Rule: awareness = security owner confirms exploitation evidence applies to a shipped version.
  4. 2026-09-18 08:20A. Rossi (assigned representative)Reportability review: confirmed reportable — actively exploited vulnerability in a product placed on the EU market (Art. 14(1)).
  5. 2026-09-18 08:20VellaciReporting case CRA-2026-0007 opened. Deadlines computed in Europe/Berlin: early warning 2026-09-19 08:05, notification 2026-09-21 08:05.
  6. 2026-09-18 21:30A. RossiEarly warning submitted through the ENISA Single Reporting Platform; receipt reference recorded, PDF filed as evidence.
  7. 2026-09-20 15:10A. RossiNotification submitted: affected versions, mitigation (rate-limit HTTP/2 streams on the management API), corrective measure 3.2.1 planned.
  8. 2026-09-23 11:00L. Brandt (product owner)Corrective measure available: EdgeGate Router 3.2.1 released with golang.org/x/net 0.17.0. Final-report deadline set: 2026-10-07.

Reporting workflow — case command center

Demo data · Acme Connected Systems GmbH is fictional

Deadlines are computed server-side from the confirmed awareness time in the organisation's timezone. Forms are staged with required, recommended and missing indicators; the manufacturer submits through the ENISA platform and records the submission with evidence.

Case
CRA-2026-0007
Type
Actively exploited vulnerability
Product
EdgeGate Router 3.2.0
Awareness
2026-09-18 08:05 CEST (rev. 1)
Assigned representative
A. Rossi
Workflow state
Notification submitted → final report preparing
StageDue (Europe/Berlin)StatusFieldsSubmission evidence
Early warning2026-09-19 08:05Submitted 2026-09-18 21:306/6 requiredSRP receipt · PDF snapshot · hash 3c1f…
Notification2026-09-21 08:05Submitted 2026-09-20 15:1011/11 required · 3/4 recommendedSRP receipt · PDF snapshot · hash 9a4d…
Final report2026-10-07 (14 days after corrective measure)Preparing · 8/12 requiredroot cause, mitigations, users informed pending—

Two final-report triggers, kept distinct: 14 days after a corrective measure for exploited vulnerabilities; one month after the notification for severe incidents.

Evidence vault

Demo data · Acme Connected Systems GmbH is fictional

Private, checksummed files and links tied to products, requirements, findings and cases — with classification, review dates, retention category and legal hold. This is what an auditor or an authority is shown.

EvidenceKindClassificationLinked toChecksumReviewRetention
EdgeGate Router — security test report Q3 2026.pdfTest reportConfidentialAnnex I Part II(3) · EdgeGate Routersha256:b81e…2027-03-3110 years (regulatory)
Coordinated vulnerability disclosure policy v2.1PolicyPublicAnnex I Part II(5) · organisationsha256:0f9c…2027-01-1510 years
CRA-2026-0007 — early warning receipt (ENISA SRP)Submission evidenceRestrictedArt. 14(2)(a) · case CRA-2026-0007sha256:3c1f…—10 years · legal hold
Support period rationale — SensorLink FirmwareDecision recordInternalArt. 13(8) · SensorLink Firmwaresha256:77aa…2027-01-0110 years
Reporting drill 2026-06 — findings and actionsDrill reportInternalReadiness · reportingsha256:e2d0…2026-12-0110 years

Audit history

Demo data · Acme Connected Systems GmbH is fictional

An append-only, hash-chained log per organisation: who changed which decision, when, with the previous and new value. Verifiable and exportable; it cannot be edited, not even by Vellaci.

#TimeActorActionEntityChain hash
48122026-09-23 11:00:12L. Brandtcra_case.corrective_measure_recordedCRA-2026-00075e0b…c3a1
48112026-09-20 15:10:44A. Rossicra_case.stage_submittedCRA-2026-0007 · notification9a4d…17f0
48102026-09-20 15:09:58A. Rossireport_snapshot.signednotification rev. 22b77…88de
48092026-09-18 21:30:03A. Rossicra_case.stage_submittedCRA-2026-0007 · early warning3c1f…4be2
48082026-09-18 08:20:31A. Rossivulnerability.reportability_reviewedCVE-2023-44487 → confirmedc0a9…e51d
48072026-09-18 08:11:07M. Kellervulnerability.awareness_setCVE-2023-44487 · rev. 171d3…0a6f
48062026-09-18 08:05:49M. Kellervulnerability.triagedCVE-2023-44487 · affectedd4e8…9c02
48052026-09-18 06:44:15vellaci-systemvulnerability.finding_created7 findings · EdgeGate Router 3.2.0a1f2…b3c4

Every screen above exists in the free Evaluation workspace with your own product. The seeded demo workspace that Vellaci operators use in live walkthroughs carries the same fictional organisation, flagged as demo data in every table.

Ready to see it with your data?

Create a free Evaluation workspace, upload one SBOM and watch exposure, triage and the reporting workflow connect — or take the eight-minute assessment first.