How it works

Four stages. You only have to be present for two of them.

ConformOps sits above the tools you already run. It collects evidence, maps it to cited rules, holds decisions open until a human makes them, and then keeps operating the file as the product moves.

Time from signup to first result
  • 0–4 minProduct facts
  • 4–6 minSource connected, secrets redacted
  • 6–12 minAssessment run, register populated
  • thenYour gap queue, in priority order
Stage 01

Write down what you actually ship

Intended purpose, market role, distribution, proposed category, support period, and the Article 32 facts. Six fields and three checkboxes. They stay editable - and every later conclusion points back to them.

product facts · aurora-desktop
  • Market roleManufacturer
  • DistributionCommercial product
  • Proposed categoryDefault product
  • Support period60 months
  • Article 32 route facts☐ Harmonised standards applied in full☐ Common specification applied☐ European cybersecurity certificate held
These three answers, not a scan, decide whether an external route applies.
Stage 02

Evidence gets collected, redacted and pinned

Repository, ZIP, or just the files that matter. Secrets are redacted before storage, indexing or AI. What remains is a sanitized snapshot bound to a commit, with hashes - so the same run can be reproduced and reviewed.

ingestion log · 41 files accepted · 4 credentials redacted
  • packages.lock.json218 components resolved
  • .github/workflows/release.ymlSBOM job found
  • SECURITY.mdintake and disclosure found
  • appsettings.json L12api credential → [REDACTED]
  • docs/ops.md L44DefaultAdminPassword kept readable
  • bin/, obj/, vendor/excluded
snapshot 9f4c1ab · sha256 3b7e…c410 · raw upload deleted
Stage 03

Nothing becomes a conclusion until you say so

Rules are versioned and cited - the Regulation is marked binding, guidance is marked non-binding. Proposals sit as proposals. Approvals are appended, never overwritten, and bound to the exact assessment they were made against.

Optional AI can propose an evidence mapping. It cannot mark a requirement met, approve a risk, pick a route, or sign anything.

approval gates · assessment 8c21…9de0
  • Scope confirmationProduct facts recorded 14 Aug · awaiting accountable confirmation
    pending
  • Classification approvalProposed: default product · no Annex III core functionality identified
    pending
  • Risk assessment sign-offTwo product-security risks are still UNASSESSED - no invented likelihood
    blocked
  • Declaration gateCannot close while a scope, classification, risk or documentation gate is open
    blocked
Stage 04

Then it operates: releases, clocks, reviewers

Every new release makes a new snapshot and a delta. Reporting cases run the 24h / 72h / final clocks. External assessment work and certificates have a register. Reviewers get a workbook instead of raw JSON.

release delta · 2.8.0 vs 2.7.2
  • Evidence coverage64% → 71%
  • New components+6
  • Conclusions invalidated3
  • New OSV matches1
Only what the change touched is re-opened.
reporting case · CVE-2026-24101
  • Early warning · 24hfiled 03:12
  • Notification · 72hdue in 41h
  • Final reportnot yet due
Event records, not reminders in a calendar.
Free, no card, 2 products

See stage one and two on your own repository.

Start free