8
Oracles
60+
Python Modules
10
Security Gates
14
Live APIs
54d
CRA Deadline

CRA Compliance Kit

EU Cyber Resilience Act — automated SBOM monitoring, CISA KEV CVE tracking, VEX generation, and ENISA notification drafts.

CRA deadline: loading...

Reporting obligations start September 11, 2026

Open-source Python package. MIT-licensed core with 4 commercial modules for advanced compliance workflows. Free tier available — no credit card required.

pip install cra-compliance-kit
Get the Kit Free Tier API
📦

SBOM Generator

CycloneDX 1.5 SBOM generation from Python packages. Dependency tree resolution, component hashing, and signature verification. MIT-licensed.

MIT
🛡️

CVE Matching Engine

Daily CISA KEV catalog matching against your SBOM components. Alerting on actively exploited vulnerabilities with severity scoring.

URGENT
📋

VEX Generator

Vulnerability Exploitability eXchange documents. Declare affected/not-affected status with justification. CSAF 2.0 format.

Commercial
📨

ENISA Notification

Auto-drafted ENISA notification templates for Article 14 reporting. 24-hour actively-exploited vulnerability disclosure workflow.

COMPLIANCE
🔒

Provenance Audit

Cryptographic audit chain from component to SBOM. Immutable verification trail for regulatory submissions and customer assurance.

Commercial
🤖

Behavioural Anomaly

Runtime behavioural anomaly detection. Baseline deviation alerts for IoT and embedded devices. Cross-Oracle request signing.

Commercial
Full pricing: Free / Developer £500/yr / Professional £1,500/yr / Enterprise £7,500/yr →

Starcaller Security Commons

Join builders shipping secure products. Get help with SBOMs, CRA compliance, and the kit. Zero sales pitch — just solving the same problem together.

💬

Discord Server

Real-time help with SBOM generation, CISA KEV alerts, CRA interpretation. Weekly office hours. #sbom-help, #cve-tracking, #cra-interpretation.

Join Free
💻

GitHub

Open-source repository. MIT-licensed core modules. Good first issues tagged. Contributions welcome — SBOM improvements, CVE feed integrations, docs.

Open Source
🌐

StarTeQ APIs

14 live APIs — weather, finance, news, nutrition, security scanning. Free tier, edge-deployed on Cloudflare, no credit card required.

APIs

Technical Documentation

Architecture overviews, security model, and Oracle reference.

🏗️

System Architecture

Starcaller architecture — how your life is governed
⚖️

Oracle Council

Eight specialist Oracles — Sia, Pythia, Anansi, Nostradamus, Yhi, White Buffalo, Shi Gandang — convened by ICID, who routes every request to the right hand and synthesises a single answer.

Council
📜

Constitutional Governance

Six immutable rules bind every Oracle: Safety, Privacy, Fairness, Transparency, Accountability, Human Dignity. Hardcoded in the kernel — no Oracle or external instruction can override them.

Governance
⚙️

OFP Kernel

The governed execution engine. Every action is routed through consent tiers — AUTO, NOTIFY, CONFIRM, DENY — so nothing executes without authorisation.

Kernel
🛡️

10-Gate Security

Injection detection, PII scanning, cross-Oracle signing, harmful-content filtering, behavioural anomaly detection — ten gates on every query, outbound scan on every response.

Security
🔒

Local-First Vault

Your life data lives in an SQLite vault on your own hardware — HMAC-signed entries, cryptographic provenance, no cloud, no third party.

Privacy
🔌

Telemetry & Autonomy

Self-healing sentinels watch every service, proactive pipelines deliver briefings and reminders, and scheduled runs keep Starcaller working while you sleep.

Autonomy

Real-World Applications

Starcaller in daily operation — use cases that demonstrate the system's breadth.

🌅

Morning Briefing

8 Oracles collaborate to produce a personalised daily briefing: weather, news, calendar, health, and security — synthesised by ICID in under 3 seconds.

Daily Use
🏠

Smart Home Security

Shi Gandang screens all IoT device communications. Physical action blacklist blocks dangerous commands at the kernel level regardless of which Oracle initiated them.

Home Automation
📚

Research Synthesis

Sia cross-references sources against citation networks while Nostradamus identifies trend trajectories. Cited, bias-audited research briefs delivered autonomously.

Research

Injection Attack Defence

A simulated prompt injection via an IoT temperature sensor was blocked by the input sanitisation layer before it reached any Oracle. Audit record produced in 120ms.

Security
🔍

Memory Provenance Audit

Every vault entry carries an HMAC-SHA256 source tag. An audit trace confirmed a recalled preference originated from direct user conversation, not a compromised device.

Privacy
💼

Financial Advisory

Yhi oracle, enhanced with financial capability, analyses spending patterns against energy-physics models. Physics-grounded recommendations, not generic advice.

Finance
× Starcaller architecture — enlarged view