European artifact repository for secure software supply chains.
Craftifact connects reliable package repositories with SBOMs, vulnerability findings, access controls, and policy signals in an operated European SaaS.
Start with the read-only demo, then use a sandbox or guided evaluation when you need to test provisioning, administration, and day-to-day workflows.
The artifact repository is one of the last controlled checkpoints
Before artifacts reach deployments or users, software teams need more than a place to store packages. For teams that need reliable and trustworthy releases, the artifact repository becomes a key control point in the software supply chain. They need to know which artifacts exist, what is inside them, which findings matter, who can publish or consume them, and which policy decisions shaped the release path.
Craftifact keeps those workflows close to the repository instead of spreading them across heavyweight tooling and self-hosted operations.
Repository reliability with supply-chain context
- Hosted, proxy, and group repositories for common package workflows
- SBOM-connected dependency and vulnerability views for artifact-level visibility
- RBAC, groups, robot accounts, and scoped tokens for controlled access
- EU operations by a German company under full EU jurisdiction
Evaluate the workflow, not just the feature list
Read‑only demo
Get an overview of repository browsing, package metadata, findings, and supply-chain views.
Sandbox
Test provisioning, administration, and repository workflows in a temporary isolated environment.
Guided evaluation (optional)
For teams with supply-chain, security, or CRA-relevant requirements, we align on fit and boundaries.
Artifacts, SBOMs, findings, and access in one operated flow.
- Reliable package access for CI/CD without operating the repository stack yourself
- SBOM upload and generated SBOM support for selected hosted content
- Vulnerability, license, secret, and pull-policy signals close to the affected artifact
- Predictable pricing, European operations, and clear plan boundaries
Features
Craftifact focuses on the repository and supply-chain workflows software teams need every day.
- Support for common package formats: Maven, npm, Python, OCI (Docker), and Gobeta
- Repository, tag, and artifact details in the UI
- Dependency, vulnerability, license, and exposed-secret signals from SBOM-connected data
- Roles, scopes, and token access (RBAC)
- APIs for CI/CD and audit-support workflows
- CRA-relevant artifact, SBOM, vulnerability, and access workflows with clear non-goals
- Backup & restore within plan scope
Trust & boundaries
- European provider with operations under EU law
- Clear product boundary: repository and supply-chain visibility, not a legal compliance suite
- CRA readiness page with official dates, supported workflows, and explicit non-goals
- Honest communication instead of marketing promises
Next step: evaluation
Use the demo for a first scan. If your requirements include SBOMs, vulnerability workflows, access governance, or CRA-relevant preparation, we can assess the fit together.
Or view the read‑only demo first.