Skip to content

European artifact repository for secure software supply chains.

Craftifact connects reliable package repositories with SBOMs, vulnerability findings, access controls, and policy signals in an operated European SaaS.

Start with the read-only demo, then use a sandbox or guided evaluation when you need to test provisioning, administration, and day-to-day workflows.

Illustration of an open artifact chest with software supply chain signals

The artifact repository is one of the last controlled checkpoints

Before artifacts reach deployments or users, software teams need more than a place to store packages. For teams that need reliable and trustworthy releases, the artifact repository becomes a key control point in the software supply chain. They need to know which artifacts exist, what is inside them, which findings matter, who can publish or consume them, and which policy decisions shaped the release path.

Craftifact keeps those workflows close to the repository instead of spreading them across heavyweight tooling and self-hosted operations.

Repository reliability with supply-chain context

  • Hosted, proxy, and group repositories for common package workflows
  • SBOM-connected dependency and vulnerability views for artifact-level visibility
  • RBAC, groups, robot accounts, and scoped tokens for controlled access
  • EU operations by a German company under full EU jurisdiction

Evaluate the workflow, not just the feature list

Read‑only demo

Get an overview of repository browsing, package metadata, findings, and supply-chain views.

Sandbox

Test provisioning, administration, and repository workflows in a temporary isolated environment.

Guided evaluation (optional)

For teams with supply-chain, security, or CRA-relevant requirements, we align on fit and boundaries.

Artifacts, SBOMs, findings, and access in one operated flow.

  • Reliable package access for CI/CD without operating the repository stack yourself
  • SBOM upload and generated SBOM support for selected hosted content
  • Vulnerability, license, secret, and pull-policy signals close to the affected artifact
  • Predictable pricing, European operations, and clear plan boundaries

Features

Craftifact focuses on the repository and supply-chain workflows software teams need every day.

  • Support for common package formats: Maven, npm, Python, OCI (Docker), and Gobeta
  • Repository, tag, and artifact details in the UI
  • Dependency, vulnerability, license, and exposed-secret signals from SBOM-connected data
  • Roles, scopes, and token access (RBAC)
  • APIs for CI/CD and audit-support workflows
  • CRA-relevant artifact, SBOM, vulnerability, and access workflows with clear non-goals
  • Backup & restore within plan scope

Trust & boundaries

  • European provider with operations under EU law
  • Clear product boundary: repository and supply-chain visibility, not a legal compliance suite
  • CRA readiness page with official dates, supported workflows, and explicit non-goals
  • Honest communication instead of marketing promises

Next step: evaluation

Use the demo for a first scan. If your requirements include SBOMs, vulnerability workflows, access governance, or CRA-relevant preparation, we can assess the fit together.

Or view the read‑only demo first.