Skip to content

Get started

There are two ways into alloy-it, and which one you want depends on the job in front of you.

  • CRA operations


    You are responsible for what your company placed on the EU market and for the Article 14 reporting duty that starts on 11 September 2026.

    You will create products, record the releases you shipped, and fill in your reporter identity. No SBOM required to begin.

    Best for: product security, PSIRT, compliance, engineering leads.

  • Build environments


    You need a toolchain that installs identically on your machine, your colleague's machine, and CI, and that can be reconstructed years later.

    You will install alloy-provisioner and pull a blueprint.

    Best for: embedded and platform engineers, CI owners.


Not sure?

If you are trying to… Start with
Answer "which products contain this CVE?" CRA operations
Be ready to file a 24-hour report in September CRA operations
Produce evidence for an assessor or a customer questionnaire CRA operations
Stop losing a day to toolchain setup on every new project Build environments
Make CI use the same toolchain as local development Build environments
Patch a release built four years ago Build environments, then link it as provenance

Most organisations end up doing both. They connect through provenance: a release records which blueprint built it, so when triage says a shipped release is affected, you have a rebuild target instead of an investigation.


What you need

For CRA operations: an account on the dashboard. Community tier is free; product inventory, triage, reporting, advisories, and evidence require a Team or Enterprise plan and membership of an organisation.

For build environments: a Linux environment (native, WSL2, a VM, or a container) with curl or wget, apt, and sudo. See before you start.


Then what?

Once you are set up, the rest of the documentation follows the work:

Products and releases → SBOMs → Monitoring → Triage → Reporting → Advisories → Evidence