Terms of Service
Last updated 11 August 2026
These terms govern use of the Skarp CRA service at
cra.skarp.app, operated by Linclaw Consulting AB,
org. nr 559074-9239, Prästkvarn Gamla Skolan 1, 542 94 Mariestad,
Sweden ("we"). By connecting a client and using the service you agree to
them.
1. What the service is
An MCP server that helps you produce and maintain records relating to Regulation (EU) 2024/2847 (the Cyber Resilience Act): classification decisions, risk assessments, requirement status, evidence, vulnerability and incident records with their reporting deadlines, and technical documentation.
2. What it is not
It does not determine compliance. The service records and organises what you tell it and reports what is missing. It cannot establish that a product conforms to the CRA, and no output may be presented as a conformity assessment.
It is not legal advice and does not create a professional relationship. Obligations under the CRA fall on you as the economic operator. You remain responsible for classification decisions, for the adequacy of your risk assessment, for the accuracy of your technical documentation, and for filing reports within their statutory deadlines.
It is not a notified body. Where your product class requires third-party conformity assessment, only a notified body can perform it.
It does not file reports. Notifications are submitted by you on ENISA's Single Reporting Platform under your own credentials. The service drafts and records; it never submits on your behalf, and recording a submission here is not a submission.
3. Deadline alerts are a convenience, not a guarantee
The service calculates statutory deadlines from the information you give it and sends reminders as they approach. Those calculations depend on the accuracy and timeliness of what you record — in particular when you became aware of an exploited vulnerability, which is what the clocks run from. Email delivery is best-effort and may fail for reasons outside our control. Do not treat an absent reminder as evidence that nothing is due. Responsibility for meeting a deadline remains yours.
4. Access and credentials
You can create an account yourself. Connector tokens identify your account and act with its authority: treat one as you would a password, do not share it, and tell us promptly if one may have been exposed so it can be revoked. You are responsible for activity carried out with credentials issued to you, including by AI agents you connect.
5. Your content
What you record stays yours. You grant us only the permission needed to operate the service: to store, process, back up and display it to you and to other members of the products you share. We do not use your compliance records to train models, and we do not sell or share them for marketing.
You are responsible for having the right to record what you record. Evidence is stored by value and retained for a long time — see the privacy page — so avoid placing credentials or unnecessary personal data into it.
6. Acceptable use
- Do not attempt to reach products or records you are not a member of.
- Do not probe, disrupt or overload the service. Rate limits exist; do not work around them.
- Do not use the service to store material unrelated to compliance record keeping, or anything unlawful.
- Do not present the service's output as a conformity assessment, a certification, or legal advice to a third party.
Security research is welcome — see the contact below. Testing that degrades the service for others is not.
7. Availability
The service is provided as-is, with no uptime commitment and no service level agreement. It may be unavailable during maintenance or outages. Because statutory deadlines do not pause for downtime, keep your own record of any deadline you are relying on.
8. Liability
To the extent permitted by law, we are not liable for indirect or consequential loss, nor for regulatory penalties, missed reporting deadlines, or findings arising from your use of the service or from reliance on its output. Nothing here limits liability that cannot lawfully be limited, including for death or personal injury caused by negligence, or for fraud.
9. Suspension and termination
You may stop using the service at any time and ask us to close your account; see the privacy page for what deletion can and cannot reach. We may suspend access for breach of these terms or where continued access threatens the security of the service, and will tell you why unless prevented from doing so.
10. Changes
We may update these terms. Material changes will be dated here and notified to account holders by email. Continuing to use the service after a change takes effect means accepting it.
11. Governing law
These terms are governed by the laws of Finland, and the courts of Finland have jurisdiction, except where mandatory consumer law in your country of residence gives you a different right.
12. Contact
cra@skarp.app — for access requests, questions about these terms, and security reports.