Audience
Software vendors, SaaS companies, product manufacturers, and Platform, DevOps, DevSecOps, and application security teams that manage private packages or container images and need SBOM-connected dependency, vulnerability, license, access-control, and CRA-relevant evidence workflows. Particularly relevant for European organizations and teams with EU data-protection or software supply-chain requirements.
About Craftifact
Craftifact is a European artifact repository SaaS for software teams that need reliable package distribution together with supply-chain visibility. It provides hosted, proxy, and group repositories for Maven, npm, Python, OCI/Docker, and Go, with browser-based artifact metadata and repository management. CycloneDX SBOMs can be uploaded and, for selected hosted content, generated and linked to artifacts or OCI digests. Teams can inspect dependencies and review vulnerability, license, exposed-secret, and policy signals close to the affected artifact. Access is controlled through OIDC, RBAC, groups, robot accounts, and scoped tokens, with APIs for CI/CD and evidence workflows. Craftifact is operated in Europe by a German company under EU jurisdiction and includes managed updates, monitoring, backups within plan scope, and predictable non-seat-based pricing. It supports CRA-relevant technical preparation but does not replace legal or conformity assessment.