Public previewRAGSuite is open-source, self-hosted and EU-ready — and we build it in the open.See it live

Platform Platform overviewSee it in actionAI SearchAI AssistantAI Connectors & MCPIntegrationsQuality LoopAdministration & SecurityMobile app
Solutions IT & Platform teamsCompliance & Data ProtectionDevelopersAgencies & Partners
Sovereignty
References
Pricing
Resources Trust CenterEU AI ActSecurity & disclosureFree toolsOpen source & open coreDocumentation ↗API reference ↗GitHub ↗ReferencesBlogChangelog
Company AboutPartnersContact
Search See it live Book a demo
Trust Center · Cyber Resilience Act

Built for the EU Cyber Resilience Act.

The Cyber Resilience Act is Europe’s product-security law for software. Because RAGSuite is software you host yourself, it’s in scope — and we’re engineering it to the CRA’s essential requirements, on a documented path to full conformity ahead of the 11 December 2027 obligations. Not legal advice; the honest state of play.

How we build to it
Supply chainSigned release · cosignSBOM · CycloneDXCoordinated disclosurePublished security.txtPinned versionsCRA-aligned
The timeline

When each duty applies.

The CRA entered into force in December 2024 and phases in. Unlike the EU AI Act, these dates were not pushed back by the 2026 simplification debate.

  1. 10 Dec 2024

    Entered into force

    The Cyber Resilience Act (Regulation (EU) 2024/2847) became law.

  2. 11 Sep 2026

    Reporting duties begin

    Actively exploited vulnerabilities and severe incidents must be reported — a 24h / 72h / 14-day cascade via the ENISA Single Reporting Platform.

  3. 11 Dec 2027

    Main obligations apply

    Essential requirements, technical documentation, conformity assessment, the EU Declaration of Conformity, CE marking, support-period and SBOM duties.

Why this is good news for you

In scope, on purpose.

Most AI tools are cloud-only, which keeps them outside the CRA’s product-security law. RAGSuite is self-hosted, so it sits inside that law — and we treat that as a feature. You get software built to a published European security bar, on infrastructure you control. You can’t inherit a standard a vendor never had to meet.

What we’re building to

Security you can verify — not adjectives.

Signed, pinned releases

Every release is cryptographically signed (cosign) and version-pinned — verify before you run.

cosign

SBOM on every release

A machine-readable software bill of materials (CycloneDX) of what we ship.

CycloneDX

Coordinated disclosure

A published security contact and a coordinated vulnerability disclosure policy.

security@

Secure by default

Hardened defaults, local-by-default processing, nothing phones home.

by default

Every control documented for due diligence · see the Trust Center →

The honest comparison

Cloud-only sidesteps it. Self-hosted is built to it.

Both can be true — and that’s the point.

Cloud-only AI tool
  • Generally outside the CRA’s product scope
  • You can’t inherit a standard the vendor never had to meet
  • Data leaves your perimeter to their cloud
  • Caught by NIS2 as a service, not product-security law
RAGSuite, self-hosted
  • In CRA scope as a product with digital elements
  • Built to the CRA’s essential cybersecurity requirements
  • Local-by-default, no egress, optional air-gap
  • Signed releases, SBOM and coordinated disclosure
The open-source point

Open source — and honest about it.

RAGSuite’s core is Apache-2.0 and fully inspectable. That helps trust — but it does not make us exempt. Because we offer a commercial edition, NITSAN is the manufacturer under the CRA and carries the full obligations. We’d rather meet the bar than argue our way around it.

Reference
“Clever advertising today also means AI that’s accessible and sovereign. RAGSuite fits both.”
Sascha Rizzello · Werbeagentur 3-iQ, Solingen
Read the case study
Accessible
BITV-ready
Citations
on every answer
On-prem
no egress
DE
interface

All references

Security you can prove, on infrastructure you control — built to Europe’s product-security law.
On the Cyber Resilience Act
FAQ

The Cyber Resilience Act, answered

Is RAGSuite “CRA-compliant”?

We’re CRA-aligned — engineered to the CRA’s essential requirements, on a documented path to full conformity. Nobody can truthfully be “CRA-compliant” yet: the main obligations don’t apply until 11 December 2027 and the harmonised standards aren’t final. We’d rather tell you exactly where we are than over-claim.

Does the CRA apply to you — aren’t you open source?

It applies. The open-source exemption only covers software its maker doesn’t monetise. We offer a commercial edition, so NITSAN is the manufacturer and carries the full obligations. Apache-2.0 gives you inspectability and no lock-in — not a loophole.

Our AI vendor says the CRA doesn’t apply to them. Who’s right?

Both can be true — and it’s the point. Pure-SaaS tools generally fall outside the CRA’s product-security scope (NIS2 applies to them instead). Self-hosted software like RAGSuite is in scope, so you get software actually built to that bar.

Does the CRA add cost or delay for us?

No. The obligations sit with us as the manufacturer, not with you as the deployer. You get the security work; you don’t inherit the paperwork. This page is information, not legal advice.

RAGSuite is being engineered to the CRA’s essential requirements ahead of the 11 December 2027 obligations. We do not yet claim CRA conformity, CE marking or certification; those follow the formal conformity assessment. This page is information, not legal advice.

Stefan Reinhardt, Public Sector & Compliance
Stefan Reinhardt
Public Sector & Compliance

Talk to us about your CRA review.

Self-hosted software is in scope — and we build to it: signed releases, an SBOM, coordinated disclosure.

Founding-customer programme open now — own your AI, on your own infrastructure.
Trust Center