Security
Craftifact protects package repositories and supply-chain visibility workflows, so access control, artifact integrity, availability, and clear boundaries are central requirements.
Service security
Craftifact runs as an operated European SaaS with a controlled platform boundary. The service is designed around tenant separation, encrypted transport, protected administrative access, regular maintenance, and plan-scoped backup and restore workflows.
Relevant evaluation paths:
- Backups and recovery
- Storage and custom domains
- Support and Maintenance Policy
- Service Level Agreement
Access security
Repository access should be explicit and reviewable. Craftifact supports OIDC-based login paths, the SoluForge IdP option, RBAC, groups, robot accounts, and scoped tokens so teams can separate human access from automation credentials.
Relevant evaluation paths:
- Access and identities
- Identity provider for Craftifact instances
- Create a robot account and use its token
Artifact security
Craftifact keeps package workflows close to controlled repository operations. Hosted, proxy, and group repositories, artifact metadata, upload/download controls, lifecycle workflows, and pull-policy gates help teams keep package access reliable and governed.
Relevant evaluation paths:
Supply-chain visibility
Craftifact connects artifacts with SBOM-backed dependency, vulnerability, license, and exposed-secret signals. Suppressions, freshness signals, pull-policy holds, and Fast-track decisions support controlled triage without turning Craftifact into a legal compliance assessor.
Relevant evaluation paths:
- Generate SBOMs with client tools
- Explore dependencies
- Review vulnerability findings
- CRA-relevant supply-chain workflows
- CRA readiness
Boundaries
Craftifact is an artifact repository and supply-chain visibility layer. It is not a source-code scanner for all customer repositories, a legal compliance suite, a conformity assessor, a CE-marking service, or a replacement for customer incident response and vulnerability disclosure ownership.
Security requirements evolve continuously. We prioritize improvements that deliver practical security value for repository, artifact, and supply-chain workflows.
Security contact & responsible disclosure
If you have security-related questions or want to report a vulnerability responsibly, please contact us:
Email: soc@soluforge.de
For encrypted communication, we provide our public PGP key:
We treat security reports confidentially and with appropriate care.