Answer six questions about the product
What it does, who ships it, how it is distributed, how long you support it. These become the legal facts the rest of the file hangs off - and you can change them later.
Preparing the evidence view…
Point ConformOps at a repository. It reads your manifests, lockfiles, CI, SBOMs and security docs, maps what it finds to the regulation, and hands back the evidence package - with every conclusion linked to the exact file and line it came from.
Drafts stay marked as drafts. Nothing here is a declaration of conformity until you approve it - and the approval is recorded against the exact assessment it was based on.
This is the output for an example .NET desktop product. Click through the tabs - the numbers, paths and line ranges are the shape of what you get.
18 of 32 requirements have source-backed evidence. Coverage is not compliance - it tells you how much of the file writes itself.
Your SECURITY.md covers intake, but nothing records who decides an early warning is due, or how the 72-hour notification gets filed.
CRA Art. 14writing, not engineeringunblocks the declaration gateWhat it does, who ships it, how it is distributed, how long you support it. These become the legal facts the rest of the file hangs off - and you can change them later.
Read-only GitHub App, a ZIP, or just the files that matter: manifests, lockfiles, CI, SECURITY.md, SBOMs. Secrets are redacted first. Nothing is run.
Each gap reads like a ticket. When you ship again, ConformOps re-runs, tells you what changed, and invalidates only the conclusions the change touched.
Consultants add valuable judgement and spreadsheets offer a familiar starting point. ConformOps connects source evidence, actions, and release history so the record keeps moving with the product.
You are handing a compliance tool your source. Here is exactly how far it goes, in the same words we use in the codebase.
The GitHub App asks for repository contents, read. Tokens are encrypted, expiring, and minted per import for the one repository you picked.
Redaction happens before persistence, before indexing, and before any model call. Paths and line numbers stay so the evidence remains checkable.
No builds, no scripts, no hooks. Only a bounded text subset - docs, manifests, build files, common source extensions - is read.
ZIPs are streamed, not kept. Temporary objects are deleted once the sanitized snapshot exists, and abandoned ones expire within 24 hours.
Optional model proposals are stored with their prompt and snapshot version. They cannot mark a requirement met, approve a risk, choose a route, or sign a declaration.
A product can hold several repositories and components inside one CRA scope · Portfolio is €249/mo for five active products