About

Vellaci turns product-security events into traceable regulatory operations.

We are an engineering, security and compliance-operations team building for European software and connected-product manufacturers. Our conviction: the CRA is not a checklist problem. It is an operations problem — dependency to vulnerability to product impact to human decision to deadline to remediation to evidence.

Vellaci is a product-security and Cyber Resilience Act (CRA) operations platform for manufacturers placing products with digital elements on the EU market. It connects products, SBOMs, vulnerability intelligence, incidents, Article 14 reporting workflows, evidence and readiness in one auditable system. Vellaci is not a CRM, a law firm, a notified body or an authority and does not certify conformity.

What we are

A product security and CRA operations platform, delivered with implementation. One system of record for products, SBOMs, vulnerabilities, incidents, Article 14 reporting, evidence and readiness.

What we are not

A CRM, a law firm, a notified body, ENISA, a CSIRT or an authority. We do not certify conformity and we do not make legal determinations; reportability decisions and official submissions are yours.

How we work

Every feature must survive the question: could a security engineer use this during a real incident, and could an auditor follow the evidence afterwards? We do not claim certifications we do not hold.

Founded
2026, Switzerland — built for the EU market
Focus
Manufacturers of software and connected products under Regulation (EU) 2024/2847
Hosting
EU region (Frankfurt) for database, storage, authentication and functions

Talk to the team.

We run implementation engagements personally.