# alloy-it Product

> One CRA operations platform: monitor → notify authorities → trace back → reproduce.

## The loop

| Capability | Meaning |
| --- | --- |
| Monitor | Product inventory, vendor and firmware-derived SBOMs, continuous rescan |
| Notify authorities | KEV/EUVD, awareness timestamp, copy-JSON Article 14 SRP (does not submit) |
| Trace back | Component → releases → evidence pack |
| Reproduce | Blueprints + provisioner to rebuild an affected release |

## Entry points (dashboard)

- **Products / SBOMs** — create products and releases; upload vendor CycloneDX/SPDX
- **Firmware** — on-demand derive inventory; compare to vendor SBOM
- **Build-env** — blueprints and toolchain scan for the rebuild path

## Honesty

Not CE-marking software. Not a notified body. Does not submit to ENISA. Blueprints are the reproduce leg, not the Sep 2026 lead.

Built for the manufacturer of record under the CRA, including anyone treated as a manufacturer after a substantial modification.

## Links

- [Website product page](https://www.alloy-it.io/product/)
- [Get started](https://www.alloy-it.io/get-started/index.md)
- [CRA hub](https://www.alloy-it.io/compliance/cyber-resilience-act/index.md)
- [llms.txt](https://www.alloy-it.io/llms.txt)
