Your first 15 minutes
Vellaci is designed so that a product security engineer sees a real security insight before filling in a single compliance field.
- Create your organisation — legal name, country and timezone. The CRA scope questions are optional at this point.
- Add a product — name and type are enough. Classification and support period can be completed later.
- Bring in components — either connect GitHub / GitLab (releases and dependency-graph SBOMs are imported automatically) or upload a CycloneDX / SPDX file, or push one from CI with the API.
- Watch the match — within a minute the SBOM is parsed, every component is matched against OSV / GitHub Advisories, enriched with CISA KEV and EPSS, prioritised and listed under Vulnerabilities.
- Open the top finding — you will see severity, exploitation evidence, priority factors, affected versions and a one-click remediation task or Jira/Linear issue.
Compliance fields (classification, support period, reporting contacts) improve readiness scores and reporting drafts, but nothing blocks the first insight.
What to configure next
- Security owners per product (release gate and policies depend on them)
- Reporting contacts and the CRA reporting runbook (Settings → Runbook)
- Slack / Teams / PagerDuty channels for critical findings and CRA deadline thresholds
- A CRA reporting drill — a simulated 24h / 72h exercise that produces readiness findings
Last updated . This page describes the current release.