Founding beta · for small commercial software teams

Turn every release into a CRA-ready evidence packet

Generate an SBOM, preserve release evidence, and keep vulnerability work tied to the version you actually shipped — without installing a heavyweight governance platform.

Founding beta for small commercial software teams. No charge until your workspace is active. Cancel any time.

Release record · v4.8.0No. WB-4.8.0
Commit
a3f9c21 · tag v4.8.0
Build
github-actions · run #1842
SBOM
Archived 312 components
Scan
Reviewed 2 exceptions recorded
Watch
1 advisory triage open · owner assigned
Export
evidence-packet-v4.8.0.zip
Illustrative — planned workflow, not a live product.

01 · The problem

You already ship software. The evidence is the messy part.

A release can involve lockfiles, build outputs, Git tags, security scans, dependency updates, and scattered decisions across issues and chat. When a customer asks what was inside version 4.8 — or a vulnerability appears three releases later — reconstructing the answer becomes its own project.

Waybill is a lightweight release-evidence workspace built for small vendors. It is being designed to turn the information your pipeline already produces into a versioned record you can inspect, update, and export.

02 · One record

One release record, not six disconnected tools

  1. Generate the SBOM

    Create a machine-readable software bill of materials for each release, beginning with top-level and resolved dependencies available from the build.

  2. Archive what shipped

    Tie the SBOM, commit, build metadata, scan results, and release notes to one immutable release record.

  3. Watch the released versions

    See when a known vulnerability affects a component in a version you still support.

  4. Record the response

    Capture the decision, owner, remediation, customer notice, and shipped fix without rebuilding the timeline from memory.

  5. Export the evidence

    Produce a clear packet for internal review, customers, assessors, or counsel — with the source artifacts attached.

03 · Who it is for

Built for the teams between spreadsheets and enterprise GRC

Waybill is aimed at plugin businesses, desktop-app teams, developer-tool companies, and small studios that sell software into the EU but do not have a dedicated product-security department.

  • WordPress plugins
  • Desktop apps
  • Developer tools
  • Small software studios

04 · Founding beta

The founding beta

Founding teams will help shape the workflow around real release pipelines. The first beta is planned around GitHub Actions, with a hosted dashboard for release history, component and vulnerability tracking, and evidence-packet export.

$29/month

Founding price

  • One product and its release history
  • SBOM generation from CI
  • Per-release evidence archive
  • Known-vulnerability monitoring for recorded components
  • Exportable evidence packet
  • Direct founder support during onboarding

$29/month founding price. Locked for the first 12 months after launch for founding customers who remain subscribed.

Reserve founding access

Prefer to validate it on a real release? Apply for a paid pilot. A $29 deposit is credited to your first month when your workspace opens.

05 · Handling notes

What Waybill will not do

It will not decide whether your product is in scope, act as a notified body, replace legal advice, or guarantee conformity. It is planned as tooling for generating, preserving, reviewing, and exporting product-security evidence.

06 · Questions

Frequently asked questions

Is this only for companies based in the EU?

No. The Cyber Resilience Act can matter to manufacturers outside the EU when they place covered products with digital elements on the EU market. Scope depends on the product and how it is made available, so confirm your position with qualified counsel.

Does an SBOM make my product compliant?

No. An SBOM supports component and vulnerability documentation, but the CRA includes broader product-security, vulnerability-handling, technical-documentation, conformity-assessment, and reporting obligations.

Which SBOM formats will you support?

The beta plan is to begin with common machine-readable formats and export the original build artifacts. Final format support will be confirmed with founding teams before implementation.

Will this work for WordPress plugins or Electron and Tauri apps?

Those are priority workflows for discovery. The first integration is planned for GitHub Actions; packaging-specific support will follow the evidence from founding users.

Can I leave the beta?

Yes. The planned subscription is month-to-month. You should be able to export your records before closing the workspace.

07 · Reserve

Stop rebuilding release history after the question arrives.

Reserve a founding workspace and help shape a release-evidence workflow that fits a small software team.

$29/month founding price · No charge until your workspace is active · Cancel any time

Reserve founding access — $29/month

Release stack

No charge until you explicitly accept an active workspace.