About alloy-it
Built from real embedded and IoT engineering work.
Why alloy-it exists
alloy-it started inside Melqart Systems, not as a product idea, but as a tool we needed ourselves.
At Melqart Systems, we work on IoT integration projects and develop embedded software modules, edge applications, cloud services, and dashboards. Our work often spans the full lifecycle of a connected product: from the software running on the device to the services operating behind it.
As the Cyber Resilience Act moved from regulation to engineering reality, we faced the same questions many manufacturers are now facing:
- What exactly did we ship?
- Which software components are in each product and release?
- Which vulnerabilities affect them?
- When did we become aware of an issue?
- And can we reproduce the environment that built a release years later?
Spreadsheets, one-off vulnerability scans, CI logs, and scattered documentation were not enough. So we built the workflow we needed.
What began as an internal Melqart Systems tool evolved into alloy-it: a platform that connects products, releases, software components, vulnerability monitoring, triage decisions, evidence, and reproducible build environments.
Products and releases are the unit of record. Vulnerabilities can be traced back to what was actually shipped. Awareness and triage become part of the product history. And Blueprints make it possible to reconstruct the environment behind a release when a fix needs to be built months or years later.
Built by engineers, for engineering teams
alloy-it is developed and maintained by Melqart Systems and shaped by people who build and operate embedded and connected products themselves.
It is designed for the people who have to make CRA requirements work in practice: embedded and software engineers, engineering managers, product managers, security teams, and manufacturers of products with digital elements.
Our goal is not to turn engineers into compliance officers.
Make the evidence needed for CRA a natural output of the engineering workflow.
What alloy-it is, and what it is not
What it is not
alloy-it is not CE-marking software, a notified body, or a replacement for your engineering toolchain. It does not make conformity decisions and it does not submit regulatory notifications on your behalf.
What it is
It is the operational layer between your products, releases, software supply chain, vulnerability handling, and build environments. It helps your team understand what was shipped, assess what is affected, prepare the necessary evidence, and reproduce the environment needed to build and maintain it.
Our mission
Make CRA operations practical for the people who actually build and maintain products with digital elements.
Not as a parallel compliance exercise, but as part of everyday product engineering.
Contact Us
Have questions? Want to request a demo? Get in touch with our team.