CRA compliance doesn't end at product launch.
Neither does Lucerna.
AI led, audit ready vulnerability management for your products, built by engineers who live with the same challenge every day.
Rufilla is trusted by teams building smart products for:
The problem.
And if a regulator, a customer’s procurement team or an auditor asks you to prove your security decisions, a spreadsheet won’t cut it.
Smart products live for years.
Vulnerabilities never stop.

Every CVE decision recorded, timestamped, and retrievable
AI that reads your actual build, not just a generic CVE list
The rules have changed. Security compliance is now a legal requirement.
If you sell products with digital elements into the EU and you learn of an actively exploited vulnerability in one of them, you have 24 hours to file an early warning with your CSIRT and ENISA. It applies to products already on the market, not just new ones. Full obligations follow from December 2027, but the reporting duty starts now. Lucerna is built to have you ready.
Download our free guide

See Lucerna in Action
See exactly how Lucerna fits into your workflow and what your audit trail would look like.
What Lucerna actually does
It’s AI led. Lucerna reads your actual software build, your hardware configuration where available and your product spec, so it can show whether a CVE genuinely applies to your product, and explain why. The AI advises. Your engineers decide.
Every triage action is recorded with who made the call, when, why, and what the AI said at the time, creating the documented audit trail that PSTI and EU CRA auditors look for.
It’s not another scanner that floods you with alerts. It’s the place where those alerts get turned into defensible decisions.
Upload and baseline in minutes
Automatic for Yocto teams
Works with SPDX and SBOMs too
Stop reviewing old vulnerabilities twice
Triage that actually sticks
Every decision is recorded
Previously reviewed issues stay closed
Four clear actions
Your AI Triage Assistant
It knows your product
Tell it something once, and it remembers
Context aware scoring with the Lucerna Scoring System
Filter for what actually matters
Prioritise genuine risk
Share views across teams

Overnight alerts without the noise
Once a product has shipped, Lucerna keeps tracking it. Every release is rechecked daily as new CVEs appear, with an email alert the moment something dangerous lands in your software, and a daily reminder of anything still needing attention for CRA reporting.
You can also integrate Lucerna into CI workflows, preventing critical unresolved vulnerabilities from passing through builds unnoticed.
CRA reporting, without the blank page
The 24 hour early warning, handled
The 14 day final report, tracked
Incident reporting, covered
Generate evidence instantly
Export a compliance report in PDF at any point
Built for real world audits
Core capability
Yocto-style JSON and standard SPDX formats, including automatic upload through Rufilla's Yocto meta layer
AI Triage Assistant with context aware scoring through the Lucerna Scoring System (LSS)
Persistent CVE triage with mandatory rationale
Multi-product vulnerability tracking
Role based access and audit history
REST API for CI integration and build gating
Overnight high severity alerts and daily post release monitoring
CSIRT and ENISA reporting with the AI CRA Assistant, early warning within 24 hours
Bulk triage operations
PDF compliance reporting and SBOM generation
Built By People Who Actually Use It
We built Lucerna because we needed it ourselves.
We work on long life embedded products where security audits can happen years after deployment. Explaining every vulnerability decision through spreadsheets and disconnected processes simply wasn’t sustainable.
So we built the platform we wanted to use ourselves, then gave it the AI we wished we’d had from day one.
Lucerna is used internally across Rufilla projects every day, which means the roadmap is driven by real engineering needs, not abstract feature lists or marketing trends.

See Lucerna in Action
See exactly how Lucerna fits into your workflow and what your audit trail would look like.
by Joe Nicholson
Managing Director & Founder
Oxford Instruments sets the standard for embedded security compliance with Rufilla Lucerna
May 1, 2026
The company has taken out an annual licence for Lucerna, putting the infrastructure in place to build the documented, auditable security record that regulators and customers increasingly expect to see, across a product portfolio with deployment timelines measured in years.
“We built Lucerna because we needed it ourselves. Working on long life embedded products, we understood that staying compliant over time is the genuinely hard part. Oxford Instruments has understood this from the outset, and we’re proud to be supporting them in building exactly the kind of structured, continuous security process their products deserve.”
Frequently Asked Questions
Does Lucerna work with build systems other than Yocto?
Does Lucerna need to connect to the internet or our internal systems?
How long does it take to get started?
We're a small team. Is Lucerna going to add a lot of overhead?
Does the AI make our triage decisions for us?
Does Lucerna certify our product as compliant?
What it does provide is a structured, auditable record of the vulnerability decisions your team makes over time, including rationale, ownership, and history. That evidence is increasingly important for PSTI, EU CRA, procurement reviews, and customer security assessments.
What compliance frameworks does the audit trail support?
What happens when a CVE I've already triaged changes?
Can multiple team members and subcontractors use the platform?
How is the Lucerna Score different from CVSS?
See Lucerna in action.
In 30 minutes you’ll see exactly how Lucerna fits into your workflow and what your audit trail would look like.
What to expect: a live walkthrough tailored to your sector and stack, an honest conversation about what compliance looks like for your specific product, and clear next steps with no hard sell.
Prefer to talk first? Call us on +44 (0)1865 601201 or email hello@rufilla.com




