CRACI
A runner for GitHub Actions that records packages fetched during a job and generates build‑time SBOMs.


Startup · Finland
HQ FinlandFounded 202511-50 employees
CRACI records build dependencies, identifies releases affected by vulnerabilities, and tracks the response from triage to a fixed release.
A runner for GitHub Actions that records packages fetched during a job and generates build‑time SBOMs.
An egress‑policy system that controls and blocks unauthorized network connections from builds.
A service that stores SBOMs, network traces and provenance for each build.
A package‑aware proxy that records every external dependency fetched during a build.
A build runner that executes CI jobs in isolated virtual machines.
Continuous monitoring of recorded SBOMs against known vulnerabilities and triage workflow.
Newest unveiled first. Open a product for its milestone timeline, components and sources.
| Announced | Stage | Amount | Valuation | Lead investors | Other investors | Confidence |
|---|---|---|---|---|---|---|
| May 19, 2026 | Pre-Seed | €1.4M | — | Lifeline Ventures | First Fellow Partners, Wave Ventures | Reported |
Totals add known amounts using recorded USD conversions where available; other currencies are shown separately. A ~ marks an estimated amount.
CRACI · Supports Organization · description, Organization · name, Organization · website
“CRACI records build dependencies, identifies releases affected by vulnerabilities, and tracks the response from triage to a fixed release.”
PitchBook · Supports Organization · employee range, Organization · founded year, Organization · linkedin url, Organization · x url
“employee_range: 11-50 (profile: 15)”
Sixth-Domain · Supports Organization · country, Organization · kind
“{"country": "Finland", "hq_iso2": "FI", "id": "b15c6ad7-3ac3-49f3-ad4c-8b85a9dc4710"}”
CRACI · Supports System
“CRACI is a runner for GitHub Actions. You change `runs-on` to `craci`, and while each job runs, a package-aware proxy records what it fetched, including packages restored from CI caches. Each SBOM carries a completeness state per job and per cache, an egress policy is validated before the job starts and fails closed, and CRACI keeps re-evaluating the SBOMs of what shipped”
CRACI · Supports System
“CRACI Secure Build Service Jobs run on CRACI runners in isolated virtual machines. Runners scale from 1 to 32 compute units (1 vCPU and 3 GB of RAM each), on native x86-64 and ARM64, with a GitHub-compatible Ubuntu image or CRACI's slim images”
Startup Rise · May 19, 2026 · Supports Funding round · amount
“CRACI has raised €1.4 million in pre-seed funding led by Lifeline Ventures, with participation from First Fellow Partners and Wave Ventures.”
Each fact on this page is attached to the sources that support it. Archived copies are linked when we keep one.