CRA Bureau

Terms and privacy

The short version

What this service is

What it is not

Your responsibility

What data we hold

  • Account details: your email address, name, and the organisation details you enter. The organisation details are the ones that appear on your declaration of conformity, so they are necessarily identifying.
  • Product records: everything you type into the workspace — descriptions, risk assessments, requirement implementations, evidence notes.
  • Dependency data: component names and versions parsed from the manifests you supply. We do not read, store or transmit your source code.
  • Generated documents: the PDFs and SBOMs produced, with their SHA-256 hashes.
  • The audit trail: a hash-chained record of compliance-relevant actions, including who performed them and when.
  • Free tool submissions: the answers given to the scope checker and the results of a public SBOM scan, so the document can be regenerated without re-running the scan.

Third parties

Retention, and why you cannot simply be deleted

Availability and liability

Changes