Every tool here started as a method we applied by hand in an engagement, then productised so that a product team can use it without a security specialist in the room: find the CRA category of a product, evaluate a portfolio against the requirements, derive security requirements from a risk assessment, produce the RED documentation, write and score a vulnerability disclosure policy. Several are free; the others are the platforms we deploy with clients.
Pick a tool on the left. Each page explains what it does, who it is for and how to get it.








