Your first 15 minutes

Vellaci is designed so that a product security engineer sees a real security insight before filling in a single compliance field.

  1. Create your organisation — legal name, country and timezone. The CRA scope questions are optional at this point.
  2. Add a product — name and type are enough. Classification and support period can be completed later.
  3. Bring in components — either connect GitHub / GitLab (releases and dependency-graph SBOMs are imported automatically) or upload a CycloneDX / SPDX file, or push one from CI with the API.
  4. Watch the match — within a minute the SBOM is parsed, every component is matched against OSV / GitHub Advisories, enriched with CISA KEV and EPSS, prioritised and listed under Vulnerabilities.
  5. Open the top finding — you will see severity, exploitation evidence, priority factors, affected versions and a one-click remediation task or Jira/Linear issue.
Compliance fields (classification, support period, reporting contacts) improve readiness scores and reporting drafts, but nothing blocks the first insight.

What to configure next

  • Security owners per product (release gate and policies depend on them)
  • Reporting contacts and the CRA reporting runbook (Settings → Runbook)
  • Slack / Teams / PagerDuty channels for critical findings and CRA deadline thresholds
  • A CRA reporting drill — a simulated 24h / 72h exercise that produces readiness findings

Last updated . This page describes the current release.