# Get started with alloy-it

> CRA-first onboarding: products, releases, SBOMs, monitoring, triage, and public advisories.

## CRA operations path

1. Open the dashboard and create a **product** (the CRA unit of record).
2. Attach **SBOMs** for the last N shipped releases (CycloneDX or SPDX).
3. Enable continuous monitoring and route alerts to the PSIRT inbox.
4. Triage findings with justification; stamp awareness when actively exploited.
5. Export the Article 14 SRP JSON when required (Alloy does not submit to ENISA).

## Rebuild path (optional, parallel)

When you need to patch a release years later:

```bash
curl -fsSL https://raw.githubusercontent.com/alloy-it/alloy-provisioner-releases/main/scripts/install.sh | bash
alloy-provisioner install community/raspberry-pi/raspberry-pi-5:1.0.3
source alloy-env.sh
```

## Honesty

alloy-it does not CE-mark products, is not a notified body, and does not submit reports to ENISA. Article 14 is a report to CSIRT/ENISA, not automatic customer email.

## Links

- [HTML get-started page](https://www.alloy-it.io/get-started/)
- [Product](https://www.alloy-it.io/product/index.md)
- [CRA hub](https://www.alloy-it.io/compliance/cyber-resilience-act/index.md)
- [llms.txt](https://www.alloy-it.io/llms.txt)
