Start with a product
Create the products and releases you placed on the market, attach their SBOMs, then run monitoring, triage, reporting, and customer advisories from that inventory.
Open the dashboardFree Basic plan, no credit card. See plans
The working loop
Inventory, monitor, decide, then tell people
Every later step reads from the same products and releases. You do not start with a scanner dump or a rebuild toolchain.
Create products and releases
A product is what the CRA holds you accountable for. Give it a name, a support period, and a risk class. Then list every firmware version you have placed on the market. That list is what an authority, and later an advisory, will be scoped against.
Attach SBOMs
Upload CycloneDX or SPDX per release, or have your pipeline push one on every build from GitHub Actions, GitLab CI, or any CI that can call the API. If the vendor document is missing or you do not fully trust it, derive an inventory from the firmware binary.
Monitor SBOMs
Scheduled rescans check every stored inventory against vulnerability intelligence. New high and critical findings go to your PSIRT inbox, never to your customers. KEV and EUVD overlay tells you when something you already shipped is being actively exploited.
Triage discoveries and effects
A scan is not a decision. For each finding, record whether the product is affected, not affected, or a false positive, with justification and history. That log is what assessors, Article 14 packets, and customer advisories all read from.
Report, then publish advisories
When a finding is actively exploited in a shipped release, stamp awareness and prepare the 24-hour, 72-hour, and 14-day packet to copy into ENISA SRP. Alloy does not submit. Separately, turn on your organisation's public security page and publish advisories scoped to the releases that are actually affected.
A public security page for your company
Published advisories are readable without a login at your organisation URL, branded with your logo. Customers see affected and not-affected releases, the recommended version, and the document history, as a page, CSAF JSON, and PDF.
The portal stays off until you enable it. Publishing and sending email are independent: you can publish without mailing, or mail without publishing.
How advisories workNeed to rebuild an affected release later?
Blueprints and the open-source provisioner reconstruct the environment that built a binary. That is the reproduce leg, after triage confirms impact, not where CRA operations start. Blueprints catalog
Would rather talk it through first? Book a CRA walkthrough →