Project detail

SuperSimple CRA Operations

A release-evidence workspace for software manufacturers that brings evidence, risks and release decisions together in one traceable record.

The problem

Software manufacturers increasingly need to explain what is included in a release, which risks were assessed and why decisions were made. In practice, this information is often spread across tools, documents and conversations.

One traceable release record

CRA Operations connects a release, its SBOM, vulnerability observations, decisions and technical evidence. This creates a coherent record that can be understood and supported later.

For product, security and compliance teams

  • An overview of releases and their software components.
  • A structured place for risks, measures and decisions.
  • Evidence linked to the release it supports.
  • A clear basis for collaboration and review.

My role in the project

I work on the SaaS architecture, backend, AI and search functionality, tenant isolation, integrations, release processes and technical foundation. The aim is to turn complex compliance questions into a workable software workflow.

Technical foundation

  • Laravel 13 and PHP for the application and backend.
  • MariaDB/MySQL for relational data storage.
  • Blade, Livewire and Flux UI for the frontend and interactive product interfaces.
  • Tailwind CSS and Vite for styling and frontend builds.
  • Laravel authentication, workspace roles such as owner/member and tenant isolation.
  • Laravel queues and workers for evidence intake and background processing.
  • GitLab and GitHub integrations for source-control workflows.
  • GitLab CI/CD for release packaging, deployments and operations checks.

Evidence and quality assurance

  • SBOMs, vulnerability observations, assessments and remediation/verification.
  • Evidence packages, hashes and detached signatures for verifiable records.
  • Pest, Laravel Pint and Larastan for testing, formatting and static analysis.
  • Frontend builds and MariaDB acceptance tests for release quality.
  • Plesk on Ubuntu with Apache/PHP and Nginx as a reverse proxy for HTTP/2, TLS and caching.

Evidence pilot

The product is being developed around a practical evidence pilot for CRA release processes. The focus is on usability, traceability and a record that teams can actually maintain.

Want to learn more about the product?

Visit the product environment for the current explanation, pilot information and further development of SuperSimple CRA Operations.

View CRA Operations