Incident handling
Incidents capture detection, awareness (confirmed by a human), impact, root cause and mitigation, linked products and vulnerabilities, and an append-only decision history. Reportability under CRA Article 14 is reviewed on the incident and can only be reversed with an MFA-verified session (and a second approver when enabled).
Incidents can be created through the API (e.g. from a SIEM) — the awareness timestamp is never set automatically.
Last updated . This page describes the current release.