# Security & trust

> How alloy-it approaches security for CRA operations data and the rebuild path.

## Principles

- Customer product inventory, SBOM, and triage data are sensitive; access is scoped to the organisation
- Alloy prepares Article 14 evidence packs; the manufacturer remains responsible for submission to CSIRT/ENISA
- Open-source **alloy-provisioner** (Apache 2.0) installs versioned blueprints; review what you run

## Honesty

alloy-it is not a notified body and does not CE-mark products. Security pages describe product practice, not a compliance certification.

## Links

- [HTML security page](https://www.alloy-it.io/security/)
- [Product](https://www.alloy-it.io/product/index.md)
- [About](https://www.alloy-it.io/about.md)
- [llms.txt](https://www.alloy-it.io/llms.txt)
