# alloy-it Platform

> CRA operations for manufacturers of products with digital elements.

## What is alloy-it?

alloy-it helps manufacturers run a living CRA workflow: product inventory, SBOM, continuous monitoring, triage, Article 14 evidence, and a rebuild path when a patch is required.

## Capabilities

- **Monitor** — products, releases, vendor and firmware-derived SBOMs
- **Notify authorities** — Article 14 awareness and SRP payload (does not submit)
- **Trace back** — component → release → evidence
- **Reproduce** — blueprints + provisioner for long-support rebuilds

## Why alloy-it?

- Built for the manufacturer of record, not for notified bodies or other CRA supply-chain roles
- Know what you placed on the market, version by version
- Be ready for Article 14 reporting from 11 September 2026
- Defensible triage decisions and evidence packs
- Reconstruct the environment that built an affected release years later

## Get started

CRA operations: [get-started](https://www.alloy-it.io/get-started/index.md) (products, releases, SBOMs, monitoring, triage, public advisories)

Rebuild path:

```bash
curl -fsSL https://raw.githubusercontent.com/alloy-it/alloy-provisioner-releases/main/scripts/install.sh | bash
alloy-provisioner install community/raspberry-pi/raspberry-pi-5:1.0.3
source alloy-env.sh
```

## Learn more

- [Full documentation](https://alloy-it.github.io/alloy-docs/)
- [Product overview](https://www.alloy-it.io/product/index.md)
- [CRA hub](https://www.alloy-it.io/compliance/cyber-resilience-act/index.md)
- [About (for agents)](https://www.alloy-it.io/about.md)
- [llms.txt](https://www.alloy-it.io/llms.txt)
