Acquire evidence
Bring repository, security and technical findings into governed evidence flows at immutable revisions.

AssureCRA connects product evidence, cybersecurity assurance, code findings and CRA assessment in one governed system â so your teams can see what is supported, what is missing and how each conclusion was reached.
Know where you stand. Prove how you got there.
Governed evidence flow
Two independent evidence paths. One CRA assessment layer.
Security assurance path
Repository evidence governed through Core and Cyber
Repository
Source & revision
QUILONS
Core + Cyber
Regulatory
CRA assessment
Code findings path
Independent SentryCode acquisition and governed finding review
Repository
Source & revision
QUILONS
SentryCode
Regulatory
CRA review
Customer workspace
QUILONS Compliance
Traceable findings, evidence status, review outcomes and CRA readiness in one governed view.
The CRA evidence problem
CRA work spans product security, source code, vulnerability handling, product documentation and organizational evidence. AssureCRA is designed to connect those facts to regulatory assessment without hiding uncertainty or treating every requirement as automatically provable.
Bring repository, security and technical findings into governed evidence flows at immutable revisions.
Connect technical facts and product evidence to CRA requirements without pretending software alone proves every obligation.
Separate supported facts, partial support and external evidence needs so teams know what is proven and what still needs action.
Keep lineage, assessment results and evidence references traceable for internal review, release decisions and technical documentation.
How it works
AssureCRA keeps repository security assurance and source-code scanning distinct, then brings their evidence into the CRA layer for regulatory interpretation and review.
Important architectural boundary
SentryCode acquires repositories independently. It is not downstream of Core. CRA owns the review and disposition of SentryCode findings.
Core governs repository access and identity. Cyber generates security assurance evidence. CRA interprets that evidence in the regulatory context, and Compliance exposes the governed result to the customer.
SentryCode independently analyzes source and publishes governed technical findings. CRA controls finding review and regulatory disposition before the result is surfaced through Compliance.
Result
A traceable chain from source evidence to CRA assessment.
The goal is not a magic compliance score. It is a reviewable body of evidence that shows which facts support the assessment and where additional evidence or human judgment is required.
The complete solution
AssureCRA is the customer product experience built from specialized QUILONS capabilities rather than a monolithic compliance database.
Identity, governance, repository access and governed artifact foundations.
Security assurance and cybersecurity evidence acquired through Core-governed repository access.
Independent source-code scanning and technical findings, delivered into CRA for governed review.
Regulatory interpretation, evidence mapping, assessment and finding disposition semantics.
The customer-facing workspace for assessment status, evidence and governed readback.
Customer-private deployment, lifecycle operations and release evidence packaging.
Evidence coverage
Not every CRA obligation can be proven from code or scanner output. The platform makes that boundary explicit instead of converting missing evidence into false confidence.
Technical evidence is sufficient to support the relevant factual part of a requirement.
AssureCRA has technical evidence, while product-specific or operational proof is still required.
The obligation depends on evidence outside automated technical analysis and must be supplied or reviewed separately.
Customer-private by design
AssureCRA is designed for customer-private deployment, with dedicated module boundaries, separate persistence and governed service-to-service access.
Deploy the solution inside infrastructure controlled by your organization.
Core, Cyber, SentryCode and CRA retain their own data boundaries.
Versioned capability APIs and evidence flows replace cross-module database access.
QUILONS Installer supports installation, lifecycle operations and release evidence.
Assurance, not a legal shortcut
AssureCRA helps manufacturers establish, maintain and demonstrate confidence in CRA readiness through governed evidence and traceable assessment. It does not replace the manufacturer's legal responsibility, declaration of conformity or any third-party conformity assessment required for a product.

Walk through your repository model, security evidence, CRA obligations and deployment constraints with QUILONS.
Product page: /assurecra · AssureCRA is a QUILONS product.