For you
Manufacturer
Articles 13 and 14
Track every firmware release you shipped. Get alerted when a component in it is actively exploited. Have the Article 14 report ready to file.
For manufacturers under the EU CRA. Not a CE-marking tool, not a notified body.
You tell alloy-it what you shipped. It keeps watching. When something is exploited, you are ready.
You set up
alloy-it
Product inventory, per release
Rescanned continuously against vulnerability intelligence, every finding triaged
You run
For authorities
Exploit incidents & Article 14 reports
24h / 72h / 14-day packets, ready to file with ENISA
For customers
Security advisories
Your public advisory page, CSAF and PDF
For your team
Alerts, triage & evidence
PSIRT alerts, decisions with reasons, a rebuild path
| Exploit ID | CVE | Product | First aware | 24h early warning | 72h notification | 14d final | Status |
|---|---|---|---|---|---|---|---|
| EXP-2026-004 | CVE-2026-1337 | GW-4200 Gateway | 68h ago | sent | in 4h | in 12d | Reporting |
| EXP-2026-003 | CVE-2026-0912 | TX-90 Sensor | 3d ago | sent | sent | in 9d | Patch in progress |
| EXP-2026-002 | CVE-2025-8841 | GW-4200 Gateway | 22d ago | sent | sent | filed | Closed |
Every exploited CVE gets its 24h / 72h / 14-day clock, with the affected releases already scoped. See what the deadline requires →
For you
Articles 13 and 14
Also for you
Treated as a manufacturer
Not this product
Authorised representatives, importers acting only as importers, distributors, open-source stewards, notified bodies, and authorities are not the buyer.
Not a collection of separate tools. Monitor detects, notify scopes authority reporting, trace-back finds origin, reproduce ships the fix. See the platform overview →
01
Product inventory & continuous scan
02
Article 14 readiness
03
Component → release → evidence
04
Rebuild & ship the fix
No SBOM programme needed to start. Begin with what you shipped.
Start here
Declare an exploitation: the clock starts, affected releases are scoped, and the 24h / 72h / 14-day payloads are built.
Then, automate it
Actively exploited CVEs open an incident before anyone has to notice the news.
What the regulation asks for, and what you get.
Not CE-marking software, not a notified body. alloy-it prepares the Article 14 payload; you submit it to ENISA or your CSIRT.
Monitoring, reporting and rebuilds, before and after.
The provisioner that reconstructs a build environment is free and open source. Product security and CRA operations are the SaaS.
Open source
SaaS
Same manufacturer duties. Different products, teams, and support periods.
No living inventory. Scans dump thousands of CVEs. Article 14 reporting is already in force.
See the PSIRT path →
Spreadsheets for what shipped. Vendor SBOM and binary disagree. 10 to 15 year support with no rebuild plan.
See how OEMs run CRA →
Gateways already in the field with no per-version SBOM when a CVE drops.
See the gateway path →
Basic is free forever. Talk to us when you need enterprise scale for CRA operations.
Manufacturers getting started with product inventory and CRA monitoring
OEMs and gateway makers running CRA operations at scale across the support period
Free forever for Basic · See full plan details →
Start with a product inventory, or book a 15-minute walkthrough of Article 14 readiness.