8
Oracles
60+
Python Modules
10
Security Gates
14
Live APIs
54d
CRA Deadline

CRA Compliance Kit

EU Cyber Resilience Act — automated SBOM monitoring, CISA KEV CVE tracking, VEX generation, and ENISA notification drafts.

CRA deadline: loading...

Reporting obligations start September 11, 2026

Open-source Python package. MIT-licensed core with 4 commercial modules for advanced compliance workflows. Free tier available — no credit card required.

pip install cra-compliance-kit
Get the Kit Free Tier API
📦

SBOM Generator

CycloneDX 1.5 SBOM generation from Python packages. Dependency tree resolution, component hashing, and signature verification. MIT-licensed.

MIT
🛡️

CVE Matching Engine

Daily CISA KEV catalog matching against your SBOM components. Alerting on actively exploited vulnerabilities with severity scoring.

URGENT
📋

VEX Generator

Vulnerability Exploitability eXchange documents. Declare affected/not-affected status with justification. CSAF 2.0 format.

Commercial
📨

ENISA Notification

Auto-drafted ENISA notification templates for Article 14 reporting. 24-hour actively-exploited vulnerability disclosure workflow.

COMPLIANCE
🔒

Provenance Audit

Cryptographic audit chain from component to SBOM. Immutable verification trail for regulatory submissions and customer assurance.

Commercial
🤖

Behavioural Anomaly

Runtime behavioural anomaly detection. Baseline deviation alerts for IoT and embedded devices. Cross-Oracle request signing.

Commercial
Full pricing: Free / Developer £500/yr / Professional £1,500/yr / Enterprise £7,500/yr →

Starcaller Security Commons

Join builders shipping secure products. Get help with SBOMs, CRA compliance, and the kit. Zero sales pitch — just solving the same problem together.

💬

Discord Server

Real-time help with SBOM generation, CISA KEV alerts, CRA interpretation. Weekly office hours. #sbom-help, #cve-tracking, #cra-interpretation.

Join Free
💻

GitHub

Open-source repository. MIT-licensed core modules. Good first issues tagged. Contributions welcome — SBOM improvements, CVE feed integrations, docs.

Open Source
🌐

StarTeQ APIs

14 live APIs — weather, finance, news, nutrition, security scanning. Free tier, edge-deployed on Cloudflare, no credit card required.

APIs

Technical Documentation

Architecture overviews, security model, and Oracle reference.

🏗️

System Architecture

Starcaller System Architecture

Prism Nexus v2 — 8-Oracle orchestration with ICID constitutional governance. The OFP Kernel, Vault, and telemetry pipeline.

Architecture
🔐

Security Model

Every query passes through a 10-gate security pipeline: memory provenance, injection detection, cross-Oracle signing, guardian health scoring, PII detection, secret scanning, harmful content filtering, platform violation checks, contextual risk assessment, and behavioural anomaly detection. Outbound scan active on all Oracle responses. 10 physical actions hard-blocked at the kernel level. HMAC-signed vault entries with cryptographic source verification.

Security
🧠

Oracle Reference

Complete reference for all 8 Oracles: abilities, rings, invocation patterns, and inter-Oracle communication protocols.

Reference
📱

Telegram Bridge

Command reference for the bot interface: /council, /morning, /task, /project, and slash-command integration.

Integration
🌐

API Reference

14 StarTeQ endpoints with authentication, rate limits, and example requests. teq.starcaller.uk

APIs
📜

ICID Constitution

The ICID Constitution is the ethical backbone of Starcaller. All 8 Oracles are bound by six immutable rules: 1. SAFETY — Never generate harmful or dangerous content. 2. PRIVACY — Never expose PII, secrets, or credentials. 3. FAIRNESS — Avoid bias, respect diversity. 4. TRANSPARENCY — Cite sources, acknowledge uncertainty. 5. ACCOUNTABILITY — Maintain audit trail, admit errors. 6. HUMAN DIGNITY — Respect all people, preserve autonomy. These rules are hardcoded into the OFP Kernel and cannot be overridden by any Oracle or external instruction.

Governance

Real-World Applications

Starcaller in daily operation — use cases that demonstrate the system's breadth.

🌅

Morning Briefing

8 Oracles collaborate to produce a personalised daily briefing: weather, news, calendar, health, and security — synthesised by ICID in under 3 seconds.

Daily Use
🏠

Smart Home Security

Shi Gandang screens all IoT device communications. Physical action blacklist blocks dangerous commands at the kernel level regardless of which Oracle initiated them.

Home Automation
📚

Research Synthesis

Sia cross-references sources against citation networks while Nostradamus identifies trend trajectories. Cited, bias-audited research briefs delivered autonomously.

Research

Injection Attack Defence

A simulated prompt injection via an IoT temperature sensor was blocked by the input sanitisation layer before it reached any Oracle. Audit record produced in 120ms.

Security
🔍

Memory Provenance Audit

Every vault entry carries an HMAC-SHA256 source tag. An audit trace confirmed a recalled preference originated from direct user conversation, not a compromised device.

Privacy
💼

Financial Advisory

Yhi oracle, enhanced with financial capability, analyses spending patterns against energy-physics models. Physics-grounded recommendations, not generic advice.

Finance