Strategic Initiatives
12425 stories
·
45 followers

Even Claude Is in the Dark About Dario Amodei’s Wife—and Her Influence at Anthropic - WSJ

1 Share

LLM (google/gemini-3.5-flash-lite) summary:

  • Strategic Influence: cami clark acts as a sounding board and strategic adviser for anthropic ceo dario amodei while maintaining a low public profile.
  • Early Support: she introduced key early investor eric schmidt to the company during its foundational period in twenty twenty one.
  • Entrepreneurial Background: her professional history includes co founding an alternative media company and developing health tech applications.
  • Professional Connections: she facilitated important networking introductions across the technology sector including links to prominent industry figures.
  • Corporate Development: anthropic emerged from a split with openai and grew into a major artificial intelligence powerhouse valued significantly.
  • Political Friction: the organization faced regulatory scrutiny and government restrictions regarding the deployment of its advanced models.
  • Public Stance: leadership articulated a mission centered on technological safety and national protection amidst industry competition.
  • Personal History: archival records indicate earlier business ventures financial restructuring events and personal relationships with influential individuals.

Cami Clark and Anthropic CEO Dario Amodei walking together at the AI Impact Summit.Cami Clark and Anthropic CEO Dario Amodei at a summit in New Delhi in February. Ludovic Marin/AFP/Getty Images

By

Keach Hagey

and Luke Jerod Kummer

Aug. 13, 2026 8:42 pm ET

When Indian Prime Minister Narendra Modi invited AI leaders to a meeting in New Delhi earlier this year, security protocols allowed each executive to bring one additional person with them. Most brought colleagues, but Anthropic CEO Dario Amodei brought his wife, Cami Clark.

Clark doesn’t work at Anthropic, but she is often seen sitting in the front row while Amodei talks at events such as Davos or can be found chatting up investors at gatherings such as the Allen & Co. conference in Sun Valley.

She acts as a sounding board and strategic adviser for Amodei, according to people close to the company. She also brought Anthropic a key early investor, former Google CEO Eric Schmidt—whom she had dated—as it was getting off the ground in early 2021, some of the people said. 

Despite her influence, there are scant details about Clark online​—and efforts have been made to remove references to her, according to a Wall Street Journal analysis and a person familiar with the matter.

The pair married in 2022, but Amodei’s Wikipedia page didn’t say he was married until this summer, and still doesn’t say to whom. Searches for “Dario Amodei’s wife” on Google often turn up a photograph of his sister, Daniela Amodei, who helps run the company.

Even Claude, Anthropic’s AI chatbot, responds to queries by saying “Dario Amodei’s marital status doesn’t seem to be clearly confirmed.”

Attendees at Journal House WEF 2026 listen to a discussion.Amodei spoke at a Wall Street Journal event at Davos this year. Clark watched from the audience. Maurizio Martorana for WSJ

As Anthropic hurtles toward an IPO that could top $2 trillion as soon as this fall, Clark is one of the most influential voices shaping the decisions of a CEO at the forefront of the AI industry—a revolution remaking all aspects of work and life that simultaneously thrills and terrifies most of the public. 

It’s a remarkable rise for a woman who didn’t graduate from college, had a previous brief marriage, at age 20, to a man more than 40 years older and once declared bankruptcy. Her career has included co-founding a women-focused “free luxury porn” company that she unsuccessfully tried to persuade convicted sex offender Jeffrey Epstein to invest in, and starting a women’s “social dieting app” that morphed into a women’s healthcare AI company. 

She made connections with powerful people, including Schmidt, whom she brought into Amodei’s orbit. The billionaire left his roles at Google and parent Alphabet in 2020 and transitioned into investing in tech startups, among other things. She also tried to persuade Schmidt to back a venture fund she would run with him to invest in Anthropic and other AI companies, although that didn’t move forward.​ 

Claude, the company’s chatbot, is now the chief rival of OpenAI’s ChatGPT, and its Claude Code tool has been embraced by millions of engineers and everyday consumers for tasks such as software writing and data analysis. 

The company’s powerful Mythos model, capable of finding and exploiting vulnerabilities, rattled markets and stoked calls by some White House officials for more federal oversight of new AI models, and Amodei himself has been a prominent voice in warning the public about the safety risks of AI.

Early partner

Clark, born in Reno, Nev., in 1979, was an entrepreneur and often interacted with the rich and powerful, as well as up-and-comers in Silicon Valley.

The most important would turn out to be Amodei, whom she started dating in 2014. Just previously, beginning in 2011 and lasting for three years, she was in a relationship with Schmidt, who was then executive chairman of Google.

Clark spent time at the group house in San Francisco where Amodei, his friend Holden Karnofsky and his sister, Daniela—who would later marry Karnofsky—lived with other key figures from the AI safety and Effective Altruism worlds. The movement, centered largely in Silicon Valley, aims to use data and reason to determine how to do the most good possible.

When they got together, Amodei was still an academic, working as a postdoctoral scholar at Stanford University School of Medicine, having earned his Ph.D. in computational neuroscience from Princeton. He would go on to stints at Baidu and Google before joining OpenAI in 2016. 

Amodei quickly climbed the ranks, helping lead key research into “scaling laws”—the notion that intelligence increases proportionally with the increase in computing power and data used to train it.

As Amodei ascended within OpenAI, Clark joined him at company events. People who worked with him and knew the couple said she made sure his ideas were given the credit she felt they deserved. 

She introduced Mira Murati, one of her closest friends, to OpenAI co-founder Greg Brockman, according to people familiar with the matter. Clark had worked with Murati at Leap Motion, a company that made a virtual-reality hand-tracking device. Murati joined in 2018 as VP of applied AI and partnerships and later became the company’s chief technology officer.

Clark also introduced Amodei to Schmidt, who became taken with the young scientist. In 2018, Schmidt visited Amodei and Clark’s apartment in San Francisco and was impressed with their ideas, Schmidt told Bloomberg.​ 

Google Chairman and CEO Eric Schmidt delivers the closing keynote speech at the Digital Life Design (DLD) conference.Eric Schmidt at the 2011 Digital-Life-Design conference in Munich. Miguel Villagran/Getty Images
Google Chairman and CEO Eric Schmidt delivers the closing keynote speech at the Digital Life Design (DLD) conference.Eric Schmidt at the 2011 Digital-Life-Design conference in Munich. Miguel Villagran/Getty Images

When tensions arose between Amodei and OpenAI co-founders Sam Altman and Brockman over who wielded power at the startup, Amodei, his sister and five other employees left to found Anthropic, in December 2020. 

Anthropic in May 2021 announced it had raised $124 million for its Series A round of fundraising, led by Skype engineer Jaan Tallinn and including Facebook co-founder Dustin Moskowitz, Jane Street founder James McClave and the Center for Emerging Risk Research, as well as Schmidt.  

Clark, who wasn’t yet married to Amodei, wanted equity in the new company as well, according to documents reviewed by the Journal. In February 2021, Clark pitched Schmidt on creating a new venture fund called the Mother of AGI Fund. Its goal was to be “an elegant solution to formalize Cami’s involvement in Anthropic (Dario’s company), manage Eric’s investment,” and invest in “the AGI ecosystem,” according to a 40-page proposal. 

Others at Anthropic, including Daniela Amodei and other co-founders, didn’t support the plan, according to people familiar with the matter, and it didn’t move forward. 

By the end of that year, associates said they recall seeing what looked like an engagement ring on Clark’s hand, and not long afterward, the couple wed in Italy. 

Clark, known for being social and outgoing, has interacted with politicians and potential investors on behalf of Amodei, chatting with them and bringing them over to meet her bookish husband at conferences and events.

Anthropic drew the ire of the Trump administration earlier this year after Amodei refused to drop restrictions on how Claude could be used by the Pentagon. The government labeled Anthropic a supply-chain risk, and Pentagon partners were effectively barred from using its technology in their work with the Defense Department, a designation the company has challenged in court. The administration added restrictions on additional AI models from Anthropic in June that were later dropped. The standoff brought unwelcome attention to the company ahead of its IPO.

Clark has recently told people involved in politics that the company sees its mission as protecting America and isn’t as “woke” as its detractors might think it is, according to people familiar with the matter. 

At the Sun Valley conference in July, where she spent much of the week by her husband’s side, she had lunch with Ivanka Trump, a friend, and chatted with Jared Kushner, whom Amodei had approached earlier in the year to invest, people familiar with the matter said.

‘Revolutionary porn company’

Clark’s early years show a young woman hustling to succeed at a range of businesses, many she founded, including a porn company targeting women. 

In 1999, at the age of 20, she married 64-year-old Reno architect Waldemar Eklof III, who had designed buildings including the city’s Atlantis Casino Resort. They divorced three years later. On a now-defunct personal website, Clark said she dropped out of architecture school in 1999. 

Property records show she moved to San Francisco in 1999 and spent a decade there before spending time in New York and Los Angeles. In that period she worked for a mortgage brokerage company called OLG Financial. While raising money for a later venture, she would describe herself as the “co-founder of OLG Financial Corp.” The company’s 2005 incorporation documents don’t include her name.

A lender foreclosed on her San Francisco apartment in 2007, and two years later she filed for bankruptcy, according to property records and court filings.

Around 2010, she and Michelle Capocefalo started Eddice, which described itself as a “revolutionary porn company.” Named for Eddice Munson, Clark’s maternal grandmother, it aimed to emphasize sex positivity in a male-oriented porn industry, and carried the tagline: “intellectually promiscuous.” 

Michelle Capocefalo and Cami Clark sitting on a couch.Michelle Capocefalo and Clark at a gallery event in New York in 2010. RYAN MCCUNE/Patrick McMullan/Getty Images

It included a blog that gathered content with titles such as “Lady Porn Day” and “Orgasm, Inc.” It also highlighted the work of intellectuals such as pundit Clay Shirky and marketing expert and author Seth Godin.

At one point, after alerting readers that its PayPal account had been frozen, Clark’s company announced on its website that it was “crowdsourcing” funding. “We are raising $350,000 to produce EDDICE.COM and our first four films, AMERICAN GIRL IN PARIS.”

In one of her pitches, part of which was reviewed by the Journal, Clark said her resume included “real estate + entrepreneurial investments” as well as “distribution + brand strategy consultant, interior design/architectural background.”​

Jeffrey Epstein’s world

Clark and Capocefalo attended the 2011 Digital-Life-Design conference in Munich, a tech, media, science and arts salon that executives often stop by on their way to the World Economic Forum in Davos. That year, the keynote speech was given by Schmidt, then still CEO of Google.

Little is publicly known about the three-year relationship between Clark and Schmidt, who remains married to another woman. Schmidt was also an investor in one of Clark’s startups, which focused on women’s health, according to people familiar with the matter.

At the Munich conference, Clark and Capocefalo met John Brockman, a literary agent of scientific books, who introduced Epstein to academics and Silicon Valley elites, according to Epstein documents recently released by the Justice Department.  

John Brockman introduced the women to Epstein that March.​ Writing that he was headed to a Wired magazine party where Brockman was the guest of honor, he told Epstein, “You should connect for dinner with my girls—Cami and Michelle. They’re in LA raising money for porn movie aimed at women’s market.” He then shared the website for Eddice.​

John Brockman attending the DLD Conference.John Brockman at the Munich digital conference in 2011. Tobias Hase/DPA/ZUMA PRESS

Brockman concluded the March 3 email by noting a birthday party being thrown for him that Saturday, saying Clark and Capocefalo would be there. Clark followed up the email soon after, writing to Epstein, “Hello Jeffrey! We would love to have dinner with you this evening.” She sent him her cellphone number. John Brockman didn’t respond to requests for comment.

The next week, Clark sent Epstein an email with an attachment. “We thought you and the ladies might enjoy the script/treatment for our first 4 films, American Girl in Paris. A little nsfw,” she wrote.

A year later, she reached back out to Epstein. At first he didn’t remember her. She replied that they had been introduced by John Brockman a year earlier. “We have the free luxury porn company. Does that ring a bell?”

Epstein replied: “Yes, a loud gong.”

Clark joked back. “Haha, I was going to say, you would be the first person that didn’t remember us.” 

She pitched him on investing in her company, saying they had just hired someone from Oprah Winfrey’s company and Ashton Kutcher’s Katalyst, the media company behind shows like “Punk’d.” “Are you still interested?”

Epstein, then a registered sex offender, replied, “Can’t do sex TV.”

Email exchange between Jeffrey Epstein and an unidentified correspondent discussing a prior introduction and a "luxury porn company."Emails between Clark and Jeffrey Epstein, released by the Justice Department. Justice Department

She pivoted to pitching him another business, a “social dieting app + website geared toward women” that would combine data from Fitbits and other health monitoring devices, user-entered data about nutrition, menstrual cycles, mood and location, and the ability to share it all, Facebook-style.

Their interaction continued over two years, the government released Epstein files show. Clark invited Epstein to her and Capocefalo’s housewarming party in Manhattan, and connected with him as friends on LinkedIn.

In 2013, Epstein received an automated note from LinkedIn that he should congratulate Clark for her new role as CEO of Female Algorithm Technologies. Traces of it online are scant, except for a Tumblr account with the edgy aesthetic that combined photos of nude women, a portrait of Steve Jobs with an early Macintosh, and all-caps mottos like Great Minds F— Each Other, using the full expletive, and “Let’s Make Lots of Money.”

Copyright ©2026 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

Keach Hagey is a reporter at The Wall Street Journal covering the intersection of media, technology and power. Her reporting explores how institutions and individuals wield influence in the new information economy, with a current focus on artificial intelligence and OpenAI. She is the author of "The Optimist: Sam Altman, OpenAI, and the Race to Invent the Future" (W. W. Norton, 2024) and "The King of Content: Sumner Redstone’s Battle for Viacom, CBS and Everlasting Control of His Media Empire" (Harper Business, 2018).

She was part of the team that broke the Facebook Files, a series that won a George Polk Award for Business Reporting, a Gerald Loeb Award for Beat Reporting and a Deadline Award for public service. Her investigation into the inner workings of Google’s advertising-technology business won recognition from the Society for Advancing Business Editing and Writing (Sabew).

Previously, she covered the television industry for the Journal, reporting on large media companies such as 21st Century Fox, Time Warner and Viacom. She led a team that won a Sabew award for its coverage of the power struggle inside Viacom.

Before joining the Journal, Keach covered media for Politico, the National in Abu Dhabi, CBS News and the Village Voice. She has a bachelor’s and a master’s in English literature from Stanford University. She lives in Irvington, N.Y.

Read the whole story
bogorad
5 hours ago
reply
Barcelona, Catalonia, Spain
Share this story
Delete

Rodalies attributes the crowds on the return to Barcelona after the eclipse to a lack of "rolling stock"

1 Share

Rodalies operations manager David Andrés says that more trains will arrive before the end of this year

  • Passenger congestion: Crowding at stations in Tarragona, Tortosa, and Altafulla followed the return to Barcelona after Wednesday’s total solar eclipse.
  • Stated cause: Rodalies operations manager David Andrés attributed the problem to a shortage of available trains.
  • Service planning: Rodalies had anticipated more travelers from southern Catalonia and reorganized service to add trains on the R15 and R16 lines.
  • Capacity constraints: Andrés said the operator could not stop serving other Catalan passengers in order to concentrate all available trains on the affected routes.
  • Infrastructure disruption: An incident at Castelldefels station around 4 p.m. caused a bottleneck, limiting traffic to two trains per hour in each direction during the disruption.
  • Additional trains: More trains are expected to arrive before the end of this year and enter service next year.
Read the whole story
bogorad
19 hours ago
reply
Barcelona, Catalonia, Spain
Share this story
Delete

Barcelona City Council installs the city's first moving walkway in the Montbau neighborhood

1 Share

The project, with a total cost of €8.34 million, includes a pergola with "allegories to poetry"

  • First mechanical ramp: Barcelona has begun installing the city’s first mechanical ramp on Poesía Street in Montbau, addressing accessibility along a route with a sustained 10% incline.
  • Public investment: The main works cost €7.34 million, with an additional €1 million for a protective pergola, bringing the total intervention to €8.34 million.
  • Neighborhood mobility: The ramp will connect the different elevations of Montbau between Vall d’Hebron Promenade and Vayreda Street, an important route in the hillside district.
  • Broader improvements: The project includes upgraded LED lighting, renovated sidewalks with Montbau-style artificial stone, reorganized vehicle lanes, and improved access for public transportation and emergency services.
  • Traffic changes: Uphill vehicle traffic will be eliminated at the intersections of Poesía Street with Harmonia and Vayreda streets, allowing more space for downhill lanes.
  • Protective pergola: A distinctive umbrella-like structure will shield the ramps from pine needles and resin, with design elements described as “allegories to poetry” and inspired by traditional olive harvesting.
  • Completion schedule: Construction is expected to finish in summer 2027, as part of Barcelona’s Pla de Barris investment program, which now includes hillside neighborhoods.
Read the whole story
bogorad
19 hours ago
reply
Barcelona, Catalonia, Spain
Share this story
Delete

The EU Cyber Resilience Act is coming, and Determinate is the missing link in your supply chain

1 Share

LLM (google/gemini-3.5-flash-lite) summary:

  • Regulatory Timeline: european union cyber resilience act enforcement begins with vulnerability reporting on september 11 2026, followed by comprehensive conformity and marking requirements on december 11 2027. (commie points: extensive bureaucratic mandates with multi-million euro penalties)
  • Scope And Reach: regulation covers products with digital elements including software and physical hardware sold in the eu, imposing due diligence obligations even on external open source components.
  • Core Inventories: nix closures function as complete transitive component inventories, fulfilling software bill of materials demands without post-hoc scanning uncertainty.
  • Build Integrity: nix derivations and sandboxing mechanisms record deterministic builds and prevent ambient machine state from corrupting shipped software packages.
  • Remediation Leverage: interconnected dependency graphs allow unified patching across entire package sets, addressing vulnerability correction windows required by compliance standards.
  • Curated Security: determinate secure packages offer curated package sets, vulnerability remediations backed by service level agreements, and compliance metadata across thousands of components.
  • Automated Generation: flakebom creates cyclonedx json bills of materials recursively from nix flakes, incorporating exploitability exchange metadata and fast evaluation.
  • Policy Gates: flakeaudit enforces vulnerability thresholds, vulnerability database queries, and sbom comparisons to satisfy continuous compliance and reporting timelines.

The European Union’s Cyber Resilience Act (CRA) is now firmly on the horizon, with the first of two implementation stages set to begin on September 11, 2026, just a few weeks from now. In that first stage, manufacturers will need to start reporting actively exploited vulnerabilities and severe incidents to European authorities on a tight 24-hour clock. The rest of the regulation—the essential requirements, the conformity assessment, and the CE marking—will apply beginning December 11, 2027.

If you sell software in the European Union, you’re now well past the point where you can safely put off thinking about the CRA. And because it applies to anything in the extremely broad category of “products with digital elements,” you’ll need to be well prepared even if your company isn’t headquartered in the EU. That category covers physical products just as much as software you deliver over a network: a robot, an industrial controller, or any connected device counts. Most of the CRA urgency we hear about, in fact, comes from robotics companies, and for good reason: the obligations bite hardest when your software runs on hardware that’s already out in the world. We’ll have quite a bit more to say about Nix on physical devices in the near future, so watch this space. In this post, however, I’d like to convince you that nothing in the CRA is truly ominous because Nix and the Determinate platform provide a comprehensive and foundationally sound solution to the software supply chain requirements that the CRA presents.

What the CRA demands

Let’s start with a closer look at what the CRA actually involves for those who aren’t yet familiar. Regulation (EU) 2024/2847 entered into force on December 10, 2024, and most of what it calls for is pretty standard security hygiene. Some parts that touch on the software supply chain:

  • Demonstrating what’s in your product. Annex I, Part II, point 1 requires you to identify and document the components in your product, “including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies.” The Software Bill of Materials (SBOM) has to be kept current and provided to proper authorities on request. Pay attention to the phrase “at the very least,” because top-level dependencies are the bare minimum of what SBOMs need to provide.
  • Shipping without known exploitable vulnerabilities. Annex I, Part I requires products to be made available on the market (a) without any known exploitable vulnerabilities, and (b) with a secure-by-default configuration and a minimized attack surface.
  • Remediation without delay, for at least five years. Annex I, Part II requires you to address vulnerabilities without delay and to provide security updates, while Article 13(8) sets the support period at a minimum of five years unless the product’s expected use is shorter. Five years is a long time to keep a build reproducible, and the clock is especially punishing if you ship to edge or remote devices, where “provide a security update” means rebuilding an image for hardware you no longer physically control.
  • Due diligence even on code you didn’t write. Article 13(5) requires manufacturers to exercise due diligence when integrating third-party components “so that those components do not compromise the cybersecurity of the product with digital elements, including when integrating components of free and open-source software.”
  • Report fast. Article 14 gives you 24 hours for an early warning, 72 hours for a fuller vulnerability notification, and 14 days for a final report, filed with the European Union Agency for Cybersecurity (ENISA) and the relevant Computer Security Incident Response Team (CSIRT). This is the obligation that will kick in next month (September 2026).
  • Getting it wrong is expensive. Article 64 sets penalties for breaching the essential requirements at up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher (yikes!).

There’s also an important nuance for anyone building on open source. Individual maintainers and non-commercial projects are largely outside the CRA’s scope, and “open-source stewards” like foundations are subject to a lighter set of obligations. For Nix shops, note that if you ship a product built using Nixpkgs, you are considered the manufacturer, and the due diligence obligation now rests on your shoulders—not those of Nixpkgs maintainers.

The challenge

To understand these requirements more intuitively, let’s consider a concrete case. Your company ships a product with digital elements into the EU, whether that’s an appliance, a fleet of robots running Linux out in the field, or the remote data processing that one of those products can’t function without. At 9 am on a Tuesday, a vulnerability is disclosed in a low-level compression library. The chatter on Hacker News and Reddit and other forums suggests that this one is really bad.

When the CRA is in full force, you’ll be on the hook to answer a variety of questions. Are you affected? Which of your products? Which versions? And if some of those versions are running on devices you shipped two years ago, which of those do you need to reach, and how fast can you get a fix onto them?

You can’t answer these questions in 24 hours if answering “what is actually in this artifact?” takes you a week of frantically tracking down information after the fact. And yet this after-the-fact approach is still standard practice: scan the artifact, parse the lockfiles you know about, ask around internally, and hope the build machine didn’t contribute anything “exciting” of its own.

This is the “what” problem we described in our FlakeBOM announcement post a while back, and it includes not just final software artifacts but also things like build tools and vendored dependencies. The challenge presented by the CRA boils down to being able to answer “what” questions quickly and with minimal extra engineering effort. But your ability to meet this challenge will be a direct function of fundamental supply chain decisions that you make. This is where Nix enters the picture.

Nix and the “what” question

As I hinted at the beginning, Nix is fundamentally the answer to the “what” questions posed by the CRA. In a recent post, I argued that Nix provides our industry its best chance at solving supply chain security because it provides radical transparency into how software is built. And it provides that not as a feature or add-on but rather by virtue of its core constructs.

So let’s look at four properties of Nix that map directly onto what the CRA asks of you.

Closures are your component inventory. The CRA asks for top-level dependencies as a minimum. A Nix closure is the complete transitive set of everything needed to build or run a piece of software, and completeness is its defining property. You don’t need to reconstruct Nix closures through scanning, inference, or some other method. You examine closures because Nix always uses them to build things.

Derivations codify your build. Every build in Nix is described by an introspectable data structure called a derivation that records the builder, the build arguments, the system, the patches applied, every input, and more. Annex VII of the CRA mandates a description of the design, development, and production of your product. Nix keeps these records as part of its basic functioning, for every dependency in your graph.

Sandboxing is your build integrity story. Nix builds run inside the Nix sandbox, with no arbitrary network or filesystem access, so the built artifact is a function of the declared dependencies and nothing else. Ambient state on a build machine—a compiler in /usr/bin, a header file in /usr/include—can’t quietly corrupt what you ship, so your SBOM faithfully describes the thing you actually shipped.

Package interdependence is your remediation lever. Because packages in a set like Nixpkgs are one vast dependency graph, patching a vulnerable library or package once and rebuilding everything downstream is a single operation rather than a web of updates across a set of repositories. This makes “address and remediate without delay,” as the CRA puts it, a far easier promise to keep than it is in build paradigms outside Nix.

Again, none of this—closures, derivations, and so on—is an optional feature that you need to switch on to get desirable results. It’s just how Nix works. But Nix by itself doesn’t quite cross the chasm from sound core constructs to the concrete deliverables that the CRA requires. This is where the Determinate platform steps in.

Determinate Secure Packages as the basis of your supply chain

Article 13(5) of the CRA mandates that you exercise due diligence with regard to open source components that you integrate. That means that your team owns the security posture of every package in your dependency graph. If you’re using Nixpkgs, which has well over 100,000 packages, that’s a pretty tall order. And due diligence is only half of it, because Annex I asks you to not just report but actually fix what you find, without delay, for five years.

Determinate Secure Packages provides both the due diligence and the remediation, handled for you by our team of Nix security specialists:

  • A curated package set of over 10,000 packages based on Nixpkgs, so the scope of what you’re vouching for is a set that we actively maintain (rather than the entire universe of packages).
  • Common Vulnerabilities and Exposures (CVE) remediation backed by a service-level agreement (SLA), which is pretty close to a contractual version of “without delay.”
  • Packages built, signed, and distributed from SOC-2-Type-II-compliant infrastructure, with full cache coverage in FlakeHub Cache, so provenance is provable rather than assumed.
  • Optional Federal Information Processing Standards (FIPS) variants for teams that are also bound by US federal cryptographic requirements.
  • Curated vulnerability metadata, including Common Platform Enumeration (CPE) identifiers that upstream Nixpkgs mostly lacks, plus triage recorded as Vulnerability Exploitability eXchange (VEX) metadata alongside the packages themselves.

That last point is worth focusing on because it’s what makes automated scanning particularly meaningful with Determinate Secure Packages. A scanner can only match the information that a package provides, and upstream Nixpkgs doesn’t carry identifiers for most of its packages. We add those identifiers ourselves, and when we triage a vulnerability we record the analysis (affected, not affected, in triage, and why) directly in the provenance metadata.

From an ergonomic perspective, adopting all of the above essentially involves swapping a flakeref:

flake.nix
{
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
inputs.nixpkgs.url =
"https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}

No integration, no refactoring, just a new package source backed by our team (and SLAs).

FlakeBOM produces the SBOM the CRA describes

Our tool FlakeBOM, included with Determinate Secure Packages, generates CycloneDX 1.5 JSON SBOMs from any Nix flake. That is, almost word for word, the “commonly used and machine-readable format” that the CRA mandates.

Generating an SBOM for your flake
cd /path/to/my/flake
flakebom

FlakeBOM is great for this specific problem:

It goes far past top-level dependencies. FlakeBOM walks your flake’s schema and recursively collects every derivation it reaches, so that what you get is the full closure rather than a summary of it. It also detects vendored dependencies inside derivations like fetchNpmDeps and fetchCargoVendor, realises them, parses the lockfiles inside, and lists what it finds as sub-components with Package URL (PURL) identifiers attached. Those blobs are precisely where after-the-fact scanners often struggle.

It carries the triage with it. When you run FlakeBOM against Determinate Secure Packages, our VEX analysis “rides along” in the SBOM, so that the document doesn’t just say what you have, it says what we already know about your flake.

It’s fast enough to run every build. We routinely generate a roughly 60MiB SBOM covering the entire secure package set (more than 10,000 components) in under two minutes, thanks to Determinate Nix’s parallel evaluation. The CRA requires the SBOM to be kept up to date, and the reliable way to keep a document current is to regenerate it as a build artifact rather than maintaining it by hand.

FlakeAudit turns the SBOM into a control

An SBOM by itself is a report on what exists. But the CRA mandates something much more exacting: that you don’t ship known exploitable vulnerabilities and that you show your work. FlakeAudit is what makes the SBOM document enforceable, through three subcommands that map onto three CRA obligations.

flakeaudit check is your “no known exploitable vulnerabilities” gate. You express policy in a flakeaudit.toml file, and any violation fails your CI run with a non-zero exit. Here’s an example CRA-friendly config:

flakeaudit.toml
[vulnerabilities]
severity-floor = "high"
[vulnerabilities.state]
exploitable = "deny"
untriaged = "deny"
in-triage = "warn"
resolved = "allow"
not-affected = "allow"

Read that policy as a sentence and it’s close to the regulation’s language: nothing exploitable ships, nothing untriaged ships, anything mid-triage is visible, and anything we’ve already reasoned about passes. The same file also governs license policy through Software Package Data Exchange (SPDX) expressions, component bans with per-component exceptions, and an allowlist of acceptable PURL ecosystems.

flakeaudit scan feeds the 24-hour clock. It queries the National Vulnerability Database (NVD) and osv.dev for advisories affecting your components and writes them back into the SBOM. When a vulnerability lands at 9 am on a Tuesday, the question “which of our products contain this?” becomes a query against documents you already have rather than an investigation you have to kick off.

flakeaudit compare is your change reporting. It diffs two SBOMs, and its deriver and callstack matchers use the Nix-specific metadata FlakeBOM emits to tell you precisely what changed between two builds. That’s the answer to the “what’s different in this release?” question, which is good to know during an incident, during an audit, and into the indefinite future.

Diffing this release against the last one
flakeaudit compare sbom-baseline.cdx.json sbom-target.cdx.json \
--matcher deriver \
--method diff \
--output diff.json

Both tools are Rust binaries available today to Determinate Secure Packages customers. No platform to stand up, no artifacts to upload to somebody else’s cloud, and no policy DSL to re-implement.

Where to start

If the CRA applies to you, here’s what we recommend doing between now and December 2027, in roughly this order:

  1. Before September 11: Make sure you know who files an Article 14 report, how, and from what evidence. Generate an SBOM for everything you ship into the EU today, even a rough one, so that the reporting question has a factual starting point.
  2. This quarter: Move your nixpkgs input to Determinate Secure Packages so that the due diligence obligation has an owner and your packages start carrying identifiers and triage data. Then start running flakebom in CI and storing the output as a release artifact.
  3. Before the December 2027 deadline: Encode your policy in flakeaudit.toml, wire flakeaudit check into CI as a blocking step, and keep a baseline SBOM per release so that flakeaudit compare has something to compare against. Baselines are worth establishing early, since the first one you’ll wish you had is the one from before the incident.

The teams that have the easiest time with the CRA will be the ones that put a solid supply chain pipeline in place well before the deadlines.

Get in touch

If you’d like to see how Determinate Secure Packages, FlakeBOM, and FlakeAudit fit into your pipeline, schedule a demo or ask us questions at sales@determinate.systems, or come find us on Discord.

Read the whole story
bogorad
22 hours ago
reply
Barcelona, Catalonia, Spain
Share this story
Delete

The EU Cyber Resilience Act is coming, and Determinate is the missing link in...

1 Share
Read the whole story
bogorad
22 hours ago
reply
Barcelona, Catalonia, Spain
Share this story
Delete

From the Shire to Mordor: Five Streets at the Gràcia Festival Recreate "The Lord of the Rings"

1 Share

The neighborhood’s most award-winning committees share the same idea for the first time and trace the journey of the Fellowship of the Ring on foot

  • Shared Tolkien theme: Five highly decorated streets at Barcelona’s Festa Major de Gràcia will jointly recreate Middle-earth, while still competing separately for the best-decorated-street prize.
  • Established contenders: Fraternitat de Dalt, Tordera, Progrés, Fraternitat de Baix, and Llibertat include several recent winners, making the collaboration a partnership among experienced competitors rather than casual participants.
  • Route through Middle-earth: Visitors can walk from the Comarca at Fraternitat de Dalt to Rivendell at Tordera, Moria at Progrés, Fangorn and Isengard at Fraternitat de Baix, and Mordor at Llibertat.
  • Independent street designs: The five commissions share the overall narrative but each will create its own decoration and remain eligible for the annual contest.
  • Literary adaptation: The route combines Tolkien’s parallel storylines, linking Frodo and Sam’s journey with Merry and Pippin’s encounters with the ents in a sequence arranged across neighboring streets.
  • Broader festival program: Alongside the Tolkien displays, the weeklong celebration will feature concerts, community meals, children’s activities, crowd-management measures, and one-way pedestrian routes.
Read the whole story
bogorad
1 day ago
reply
Barcelona, Catalonia, Spain
Share this story
Delete
Next Page of Stories