# Vellaci > Vellaci is a product-security and Cyber Resilience Act (CRA) operations platform for manufacturers placing products with digital elements on the EU market. It connects products, SBOMs, vulnerability intelligence, incidents, Article 14 reporting workflows, evidence and readiness in one auditable system. Vellaci is not a CRM, a law firm, a notified body or an authority and does not certify conformity. Disambiguation: Vellaci (vellaci.ch) is a B2B product-security and Cyber Resilience Act operations platform for manufacturers, founded in 2026. It is not a CRM: content published on this domain before 2026 by a previous owner described an unrelated personal-CRM product and has been removed (HTTP 410). ## Key facts - Regulation: Cyber Resilience Act, Regulation (EU) 2024/2847 - CRA Article 14 reporting obligations apply from 11 September 2026. The CRA’s general application date is 11 December 2027. - Reporting stages: early warning within 24 h of awareness, notification within 72 h, final report (14 days after a corrective measure for exploited vulnerabilities; one month after the notification for severe incidents) - Manufacturers submit Article 14 notifications through ENISA’s Single Reporting Platform (SRP). Vellaci can prepare and track a case but does not submit on the manufacturer’s behalf. - Hosting: EU-first hosting. Database, authentication and object storage run in an EU region; the application tier runs on an EU-region serverless platform. - Contact: hello@vellaci.ch · Security: security@vellaci.ch · security.txt: https://www.vellaci.ch/.well-known/security.txt ## Product - [Platform](https://www.vellaci.ch/platform): One operational system organised around a single graph from organisation to evidence. - [Product tour with sample data](https://www.vellaci.ch/demo): Nine screens with fictional sample data: product registry, component inventory, SBOM ingestion, vulnerability queue and prioritisation, incident timeline, reporting case, evidence vault, audit history. - [CRA Reporting Command Center](https://www.vellaci.ch/cra-reporting): 24-hour, 72-hour and final-report deadlines from a confirmed awareness time; submission-ready notifications; recorded ENISA SRP submissions. - [SBOM management](https://www.vellaci.ch/sbom): CycloneDX and SPDX ingestion per product version, deduplicated components, continuous vulnerability matching. - [Vulnerability management](https://www.vellaci.ch/vulnerability-management): Triage with mandatory reasons, exploitation signals, remediation ownership, VEX and an explicit CRA review. - [Incident response](https://www.vellaci.ch/incident-response): Product-security incidents with explicit awareness timestamps and severe-incident reportability review. - [Product security operations](https://www.vellaci.ch/product-security): Product registry, classification, support periods, coordinated disclosure, Annex VII documentation and readiness. - [Pricing](https://www.vellaci.ch/pricing): Evaluation free · Readiness €490/month · Growth €990/month · Enterprise custom; implementation packages from €4,900 (excl. VAT) ## Cyber Resilience Act - [CRA Single Reporting Platform (SRP)](https://www.vellaci.ch/cra/srp): How manufacturers prepare for and submit Article 14 notifications through ENISA’s Single Reporting Platform, with evidence and operational hand-offs. - [CRA awareness time](https://www.vellaci.ch/cra/awareness-time): How to establish, confirm and preserve the awareness time that starts the CRA Article 14 reporting clocks. - [SBOM in CI/CD](https://www.vellaci.ch/sbom/ci-cd): Generate CycloneDX SBOMs in a build pipeline and upload each release artifact to Vellaci's SBOM API. - [SBOM quality checker](https://www.vellaci.ch/tools/sbom-validator): Validate CycloneDX and SPDX SBOM structure, component identifiers, metadata and dependency graph locally in your browser. - [Cyber Resilience Act for manufacturers](https://www.vellaci.ch/cra): What Regulation (EU) 2024/2847 means operationally: scope, classification, vulnerability handling, reporting, support period, documentation. - [CRA for US companies](https://www.vellaci.ch/cra/us-companies): How the EU Cyber Resilience Act may apply to US manufacturers and software companies placing connected digital products on the EU market. - [CRA product cybersecurity risk assessment](https://www.vellaci.ch/cra/risk-assessment): A product-level CRA cybersecurity risk assessment worksheet for use context, scenarios, controls, residual risk and evidence. - [Is my product in scope of the CRA?](https://www.vellaci.ch/cra/scope): How to tell whether a software, hardware or connected product is a product with digital elements, who counts as the manufacturer, and what SaaS means under the CRA. - [CRA product categories](https://www.vellaci.ch/cra/products): Annex III Class I and Class II important products and Annex IV critical products, with conformity routes. - [CRA readiness for software manufacturers](https://www.vellaci.ch/cra/software-manufacturers): What the CRA means for companies shipping applications, operating systems, developer tooling and on-premise software, and how to operationalise it. - [CRA readiness for connected and IoT products](https://www.vellaci.ch/cra/connected-products): Firmware SBOMs, update mechanisms, support periods and reporting for consumer and commercial connected devices. - [CRA readiness for industrial and embedded products](https://www.vellaci.ch/cra/industrial-embedded): IEC 62443 alignment, long support periods, embedded SBOMs and reporting for industrial and embedded manufacturers. - [CRA readiness for network and security products](https://www.vellaci.ch/cra/network-security-products): Why routers, VPNs, firewalls, IAM and SIEM products are important products under Annex III and what that changes operationally. - [CRA glossary](https://www.vellaci.ch/glossary): Plain-language definitions of the Cyber Resilience Act's terms of art with references to the regulation. - [Cyber Resilience Act readiness assessment](https://www.vellaci.ch/assessment): Sixteen questions, about eight minutes: preliminary scope, operational gaps and next actions. - [Resources](https://www.vellaci.ch/resources): Guides and free tools on the Cyber Resilience Act, Article 14 reporting, SBOMs, classification and readiness. - [CRA deadline calculator](https://www.vellaci.ch/resources/cra-deadline-calculator): Compute the 24-hour, 72-hour and final-report deadlines from an awareness time. - [security.txt generator](https://www.vellaci.ch/resources/security-txt-generator): Generate an RFC 9116 security.txt for your vulnerability contact point. ## Cyber Resilience Act guides - [CRA Article 14 reporting obligations: a practical guide for manufacturers](https://www.vellaci.ch/resources/cra-article-14-guide): What must be reported under Article 14 of the Cyber Resilience Act, by whom, to whom and when — the 24-hour early warning, 72-hour notification and final report — and how to operationalise it now that the obligation is in force (since 11 September 2026). - [CRA reporting timeline: 24 hours, 72 hours and the final report](https://www.vellaci.ch/resources/cra-reporting-timeline): How the Article 14 deadlines are computed, where the final-report trigger sits for vulnerabilities versus incidents, how calendar months and daylight-saving time behave, and three worked examples. - [Incident or vulnerability? How the CRA treats the two reportable events](https://www.vellaci.ch/resources/cra-incident-vs-vulnerability): Actively exploited vulnerabilities and severe incidents share the 24-hour and 72-hour steps but differ in definition, notification content and final-report trigger. How to classify an event, when one becomes the other, and what to record. - [SBOM guide for the CRA: formats, minimum content and operations](https://www.vellaci.ch/resources/sbom-guide): CycloneDX versus SPDX, what a CRA-oriented SBOM must contain, which tools generate one per ecosystem, how to keep it current per release, how to share it, and how it feeds vulnerability handling and VEX. - [VEX vs SBOM: component inventory and exploitability context](https://www.vellaci.ch/resources/vex-vs-sbom): A concise technical comparison of SBOM and VEX, how component matching leads to product-specific exploitability statements, and what each artifact can and cannot establish. - [CRA product classification: default, important (Class I / II) and critical](https://www.vellaci.ch/resources/cra-product-classification): How Annex III and Annex IV categories work, the core-functionality test, what changes for conformity assessment under Article 32, edge cases, and how to document a classification decision that will survive scrutiny. - [CRA conformity assessment: Modules A, B + C and H, notified bodies and CE marking](https://www.vellaci.ch/resources/cra-conformity-assessment-routes): The conformity assessment procedures of Article 32 and Annex VIII explained by product class, how harmonised standards give a presumption of conformity, when a notified body is needed, and what the declaration of conformity and CE marking require. - [The CRA support period: how long, how to decide and what to publish](https://www.vellaci.ch/resources/cra-support-period): Article 13(8) requires a support period of at least five years unless the product is used for less, during which vulnerabilities are handled and security updates provided. How to determine it, document the rationale, publish it and manage end of support. - [CRA technical documentation: what Annex VII requires and how to keep it current](https://www.vellaci.ch/resources/cra-technical-documentation-annex-vii): The contents of the technical documentation under Article 31 and Annex VII — product description, design and vulnerability-handling processes, risk assessment, support period, standards, test reports, declaration and SBOM — with a structure you can maintain per product for ten years. - [Coordinated vulnerability disclosure under the CRA: policy, intake and security.txt](https://www.vellaci.ch/resources/coordinated-vulnerability-disclosure-policy): Annex I Part II requires manufacturers to enforce a coordinated vulnerability disclosure policy and publish a contact address. What the policy must contain, how to align it with ISO/IEC 29147 and 30111, how to run intake, and how it connects to Article 14. - [CRA vs NIS2: products versus organisations, and how the reporting duties fit together](https://www.vellaci.ch/resources/cra-vs-nis2): The Cyber Resilience Act regulates products with digital elements; NIS2 regulates essential and important entities. Many manufacturers face both. How scope, obligations and the 24-hour / 72-hour / one-month reporting steps compare, and how to run one runbook for both. - [Open source and the CRA: stewards, commercial manufacturers and upstream duties](https://www.vellaci.ch/resources/cra-open-source-stewards): When open-source software is in scope of the Cyber Resilience Act, what the light-touch regime for open-source software stewards in Article 24 requires, and what commercial manufacturers who integrate open source must do under Article 13. - [CRA readiness checklist for software and connected-product manufacturers](https://www.vellaci.ch/resources/cra-readiness-checklist): A practical CRA checklist across governance, SBOM, vulnerability handling, disclosure, incidents, reporting, support period and documentation, with evidence to keep and current transition milestones. - [CRA vulnerability handling requirements: what Annex I Part II asks of manufacturers](https://www.vellaci.ch/resources/cra-vulnerability-handling-requirements): The eight vulnerability-handling requirements in Annex I Part II, what each one means operationally, the evidence an authority or auditor would expect, and how to run them as one workflow from SBOM to security update. - [CRA evidence management: what to keep, for how long, and how to keep it provable](https://www.vellaci.ch/resources/cra-evidence-management): The Cyber Resilience Act is evidenced with records, not statements. Which records an authority, notified body, customer or auditor will ask for, the ten-year retention rule, and the properties — provenance, integrity, linkage, retrievability — that make a record count. ## CRA product categories (Annex III and IV) - [Identity & access management](https://www.vellaci.ch/cra/products/identity-and-access-management): Important product — Class I — Annex III, Class I (1) - [Browsers](https://www.vellaci.ch/cra/products/browsers): Important product — Class I — Annex III, Class I (2) - [Password managers](https://www.vellaci.ch/cra/products/password-managers): Important product — Class I — Annex III, Class I (3) - [Anti-malware](https://www.vellaci.ch/cra/products/anti-malware): Important product — Class I — Annex III, Class I (4) - [VPN products](https://www.vellaci.ch/cra/products/vpn): Important product — Class I — Annex III, Class I (5) - [Network management systems](https://www.vellaci.ch/cra/products/network-management-systems): Important product — Class I — Annex III, Class I (6) - [SIEM](https://www.vellaci.ch/cra/products/siem): Important product — Class I — Annex III, Class I (7) - [Boot managers](https://www.vellaci.ch/cra/products/boot-managers): Important product — Class I — Annex III, Class I (8) - [PKI & certificate issuance](https://www.vellaci.ch/cra/products/pki-and-certificate-issuance): Important product — Class I — Annex III, Class I (9) - [Network interfaces](https://www.vellaci.ch/cra/products/network-interfaces): Important product — Class I — Annex III, Class I (10) - [Operating systems](https://www.vellaci.ch/cra/products/operating-systems): Important product — Class I — Annex III, Class I (11) - [Routers, modems & switches](https://www.vellaci.ch/cra/products/routers-modems-switches): Important product — Class I — Annex III, Class I (12) - [Secure MPUs & MCUs](https://www.vellaci.ch/cra/products/secure-microprocessors-and-microcontrollers): Important product — Class I — Annex III, Class I (13)–(14) - [Security ASICs & FPGAs](https://www.vellaci.ch/cra/products/security-asics-and-fpgas): Important product — Class I — Annex III, Class I (15) - [Smart home assistants](https://www.vellaci.ch/cra/products/smart-home-virtual-assistants): Important product — Class I — Annex III, Class I (16) - [Smart locks, cameras & alarms](https://www.vellaci.ch/cra/products/smart-home-security-products): Important product — Class I — Annex III, Class I (17) - [Connected toys](https://www.vellaci.ch/cra/products/connected-toys): Important product — Class I — Annex III, Class I (18) - [Health & children's wearables](https://www.vellaci.ch/cra/products/health-and-childrens-wearables): Important product — Class I — Annex III, Class I (19) - [Hypervisors & container runtimes](https://www.vellaci.ch/cra/products/hypervisors-and-container-runtimes): Important product — Class II — Annex III, Class II (1) - [Firewalls, IDS & IPS](https://www.vellaci.ch/cra/products/firewalls-ids-ips): Important product — Class II — Annex III, Class II (2) - [Tamper-resistant MPUs](https://www.vellaci.ch/cra/products/tamper-resistant-microprocessors): Important product — Class II — Annex III, Class II (3) - [Tamper-resistant MCUs](https://www.vellaci.ch/cra/products/tamper-resistant-microcontrollers): Important product — Class II — Annex III, Class II (4) - [Hardware security boxes](https://www.vellaci.ch/cra/products/hardware-security-boxes): Critical product — Annex IV (1) - [Smart meter gateways](https://www.vellaci.ch/cra/products/smart-meter-gateways): Critical product — Annex IV (2) - [Smartcards & secure elements](https://www.vellaci.ch/cra/products/smartcards-and-secure-elements): Critical product — Annex IV (3) ## Glossary - [Cyber Resilience Act (CRA)](https://www.vellaci.ch/glossary/cyber-resilience-act): EU regulation setting cybersecurity requirements for products with digital elements placed on the EU market, including vulnerability handling and incident reporting. - [Product with digital elements](https://www.vellaci.ch/glossary/product-with-digital-elements): Any software or hardware product and its remote data processing solutions, including components placed on the market separately. - [Remote data processing](https://www.vellaci.ch/glossary/remote-data-processing): Data processing at a distance designed by the manufacturer, without which the product could not perform one of its functions. - [Manufacturer](https://www.vellaci.ch/glossary/manufacturer): The party that develops or has developed a product with digital elements and markets it under its own name or trademark. - [Importer](https://www.vellaci.ch/glossary/importer): An EU-established party that places on the market a product from a manufacturer established outside the EU. - [Distributor](https://www.vellaci.ch/glossary/distributor): A supply-chain party other than the manufacturer or importer that makes a product available on the market without affecting its properties. - [Open-source software steward](https://www.vellaci.ch/glossary/open-source-software-steward): A legal person that systematically supports the development of open-source products intended for commercial activities, without being their manufacturer. - [Placing on the market](https://www.vellaci.ch/glossary/placing-on-the-market): The first making available of a product with digital elements on the Union market. - [Substantial modification](https://www.vellaci.ch/glossary/substantial-modification): A change after placing on the market that affects compliance with the essential requirements or changes the intended purpose. - [Essential cybersecurity requirements](https://www.vellaci.ch/glossary/essential-cybersecurity-requirements): Annex I requirements on product properties (Part I) and on vulnerability handling (Part II) that every product must meet. - [Software bill of materials (SBOM)](https://www.vellaci.ch/glossary/software-bill-of-materials): A machine-readable inventory of the software components a product contains, required by the CRA at least for top-level dependencies. - [CycloneDX](https://www.vellaci.ch/glossary/cyclonedx): An OWASP-originated, ECMA-standardised SBOM and VEX format widely used in application-security tooling. - [SPDX](https://www.vellaci.ch/glossary/spdx): The Linux Foundation's SBOM standard, published as ISO/IEC 5962, common in licence compliance and distribution workflows. - [Package URL (purl)](https://www.vellaci.ch/glossary/package-url): A standard identifier for a software package across ecosystems, used to match SBOM components against vulnerability databases reliably. - [VEX (Vulnerability Exploitability eXchange)](https://www.vellaci.ch/glossary/vex): VEX, or Vulnerability Exploitability eXchange, is a machine-readable statement of whether a known vulnerability affects a specific product and why. - [Vulnerability](https://www.vellaci.ch/glossary/vulnerability): A weakness, susceptibility or flaw in a product that can be exploited by a cyber threat. - [Actively exploited vulnerability](https://www.vellaci.ch/glossary/actively-exploited-vulnerability): A vulnerability for which there is reliable evidence that malicious code was executed on a system without the owner's permission — the trigger for Article 14 reporting. - [Severe incident having an impact on the security of the product](https://www.vellaci.ch/glossary/severe-incident): An incident that negatively affects the product's ability to protect sensitive data or functions, or introduces malicious code — reportable under Article 14. - [Incident](https://www.vellaci.ch/glossary/incident): An event compromising the availability, authenticity, integrity or confidentiality of data or of the services offered by network and information systems. - [Awareness (becoming aware)](https://www.vellaci.ch/glossary/awareness): The moment the manufacturer has sufficient information to conclude that an exploited vulnerability or severe incident exists — the start of every Article 14 clock. - [Early warning](https://www.vellaci.ch/glossary/early-warning): The first Article 14 notification, due within 24 hours of awareness, indicating the event and, where applicable, the Member States concerned. - [72-hour notification](https://www.vellaci.ch/glossary/notification-72h): The second Article 14 stage, due within 72 hours of awareness, with general product information, an initial assessment and measures taken. - [Final report](https://www.vellaci.ch/glossary/final-report): The last Article 14 stage: 14 days after a corrective measure for vulnerabilities, one month after the notification for incidents. - [Corrective or mitigating measure](https://www.vellaci.ch/glossary/corrective-measure): A security update or other action that removes or reduces an exploited vulnerability; its availability starts the 14-day final-report timer. - [Single reporting platform (SRP)](https://www.vellaci.ch/glossary/single-reporting-platform): The ENISA-operated platform through which manufacturers submit Article 14 notifications to the coordinating CSIRT and ENISA simultaneously. - [CSIRT designated as coordinator](https://www.vellaci.ch/glossary/csirt-coordinator): The national computer security incident response team designated by each Member State to receive CRA notifications and coordinate. - [Main establishment](https://www.vellaci.ch/glossary/main-establishment): The Member State where decisions on the manufacturer's cybersecurity are predominantly taken — determines the competent coordinator CSIRT. - [Known Exploited Vulnerabilities (KEV) catalogue](https://www.vellaci.ch/glossary/known-exploited-vulnerabilities-catalog): CISA's public list of CVEs with confirmed exploitation in the wild — strong evidence for the CRA's 'actively exploited' test. - [EPSS (Exploit Prediction Scoring System)](https://www.vellaci.ch/glossary/epss): A FIRST-maintained daily probability (0–1) that a CVE will be exploited in the wild in the next 30 days. - [CVSS (Common Vulnerability Scoring System)](https://www.vellaci.ch/glossary/cvss): The standard 0–10 severity score for vulnerabilities, describing technical impact rather than exploitation likelihood. - [OSV (Open Source Vulnerabilities)](https://www.vellaci.ch/glossary/osv): Google's open, purl-indexed database and API aggregating vulnerability advisories across open-source ecosystems. - [Coordinated vulnerability disclosure (CVD)](https://www.vellaci.ch/glossary/coordinated-vulnerability-disclosure): A published policy and process for receiving vulnerability reports from third parties and fixing and disclosing them in coordination — required by Annex I Part II. - [security.txt](https://www.vellaci.ch/glossary/security-txt): A standard text file at /.well-known/security.txt telling researchers how to report vulnerabilities (RFC 9116). - [Vulnerability handling](https://www.vellaci.ch/glossary/vulnerability-handling): The Annex I Part II process requirements: identify, remediate, test, disclose, coordinate, share and update — for the whole support period. - [Support period](https://www.vellaci.ch/glossary/support-period): The manufacturer-defined period, normally at least five years, during which vulnerabilities are handled and security updates are provided. - [Security update](https://www.vellaci.ch/glossary/security-update): An update whose main purpose is to fix vulnerabilities; must be provided free of charge, promptly and securely during the support period. - [Technical documentation (Annex VII)](https://www.vellaci.ch/glossary/technical-documentation): The documentation a manufacturer must draw up before placing a product on the market and keep for at least ten years. - [Cybersecurity risk assessment](https://www.vellaci.ch/glossary/risk-assessment): The documented assessment of a product's cybersecurity risks that drives which essential requirements apply and how. - [Important product with digital elements](https://www.vellaci.ch/glossary/important-product): A product whose core functionality is listed in Annex III (Class I or Class II), subject to stricter conformity assessment. - [Critical product with digital elements](https://www.vellaci.ch/glossary/critical-product): A product in an Annex IV category for which the Commission may mandate European cybersecurity certification. - [Core functionality](https://www.vellaci.ch/glossary/core-functionality): The test that decides whether an Annex III or IV category applies: the listed function must be the product's core purpose, not an incidental feature. - [Conformity assessment](https://www.vellaci.ch/glossary/conformity-assessment): The procedure demonstrating that a product meets the essential requirements — internal control, EU-type examination or full quality assurance — before CE marking. - [Notified body](https://www.vellaci.ch/glossary/notified-body): A conformity assessment body designated by a Member State and notified to the Commission to perform third-party CRA assessments. - [Harmonised standard](https://www.vellaci.ch/glossary/harmonised-standard): A European standard adopted on Commission request and cited in the Official Journal; full application gives a presumption of conformity. - [EU declaration of conformity](https://www.vellaci.ch/glossary/eu-declaration-of-conformity): The manufacturer's formal statement that a product meets the CRA's essential requirements, accompanying the CE marking. - [CE marking](https://www.vellaci.ch/glossary/ce-marking): The visible marking indicating conformity with all applicable Union harmonisation legislation, including the CRA from 11 December 2027. - [Market surveillance authority](https://www.vellaci.ch/glossary/market-surveillance-authority): The national authority that checks CRA compliance, requests documentation and can order corrective action or withdrawal. - [NIS2 Directive](https://www.vellaci.ch/glossary/nis2): Directive (EU) 2022/2555 on cybersecurity of essential and important entities — regulates organisations, whereas the CRA regulates products. - [IEC 62443](https://www.vellaci.ch/glossary/iec-62443): The international standard series for security of industrial automation and control systems, frequently mapped to CRA requirements by OT manufacturers. - [Authorised representative](https://www.vellaci.ch/glossary/authorised-representative): An EU-established party mandated in writing by a non-EU manufacturer to act on its behalf for specified CRA tasks. ## Documentation - [Getting Started — Your first 15 minutes](https://www.vellaci.ch/docs/getting-started/first-15-minutes): Set up a Vellaci workspace, add your first product, upload an SBOM and see vulnerability exposure and CRA review in about fifteen minutes. - [Getting Started — Roles and permissions](https://www.vellaci.ch/docs/getting-started/roles): What each Vellaci role can see and do: owner, admin, security, compliance, engineer, auditor and external advisor, with the permission matrix. - [Products — Product registry](https://www.vellaci.ch/docs/products/registry): How the product registry models products, versions, lifecycle states, CRA classification with reasoning, support periods and exposure context. - [SBOM — SBOM ingestion](https://www.vellaci.ch/docs/sbom/ingestion): Every way to get SBOMs into Vellaci — UI upload, GitHub App, GitLab, CI/CD pipelines and the REST API — with supported formats and validation rules. - [SBOM — VEX](https://www.vellaci.ch/docs/sbom/vex): Record per-product exploitability statements with justifications and export signed CycloneDX VEX documents for customers and downstream integrators. - [Vulnerabilities — Intelligence and priority](https://www.vellaci.ch/docs/vulnerabilities/intelligence): Where Vellaci's vulnerability data comes from (OSV, GitHub advisories, CISA KEV, EPSS), how provenance is shown and how the explainable priority model works. - [Vulnerabilities — Triage workflow](https://www.vellaci.ch/docs/vulnerabilities/triage): The triage workflow in Vellaci: statuses, mandatory reasons, CRA review states, bulk actions, remediation ownership and ticket links. - [Incidents — Incident handling](https://www.vellaci.ch/docs/incidents/handling): Recording product-security incidents with confirmed awareness times, running the reportability review and moving into a CRA reporting case. - [CRA Reporting — Reporting cases and deadlines](https://www.vellaci.ch/docs/cra-reporting/cases): How CRA reporting cases work: case types, the 24-hour early warning, 72-hour notification and final-report deadlines, staged forms and submission records. - [CRA Reporting — Runbook and drills](https://www.vellaci.ch/docs/cra-reporting/runbook-and-drills): Configure the organisation's reporting runbook — roles, contacts, SRP access — and rehearse Article 14 reporting with simulated drill cases. - [Evidence — Evidence vault](https://www.vellaci.ch/docs/evidence/vault): The evidence vault: private checksummed files and links, versions, review dates, legal hold and retention categories tied to products and requirements. - [API — API overview](https://www.vellaci.ch/docs/api/overview): Authenticate with scoped API tokens, paginate with cursors, respect rate limits and handle errors in the Vellaci public REST API. - [API — CI/CD SBOM ingestion](https://www.vellaci.ch/docs/api/ci-cd): Upload SBOMs from CI/CD with copy-paste examples for GitHub Actions, GitLab CI, Jenkins and CircleCI, including release gates on critical findings. - [API — Outgoing webhooks](https://www.vellaci.ch/docs/api/webhooks): Outgoing webhooks from Vellaci: event catalogue, HMAC-SHA256 signature verification, retries and idempotency guidance for receivers. - [Integrations — Integrations](https://www.vellaci.ch/docs/integrations/overview): Connect GitHub, GitLab, Jira, Linear, Slack, Microsoft Teams and PagerDuty to Vellaci — what each integration imports, pushes and never accesses. - [Admin — Security settings](https://www.vellaci.ch/docs/admin/security-settings): Organisation security settings in Vellaci: MFA enforcement, SAML/OIDC SSO, two-person approvals, API tokens, auditor access, retention and deletion. - [Security — Security architecture](https://www.vellaci.ch/docs/security/architecture): How Vellaci is built to hold undisclosed vulnerabilities: tenant isolation, encryption, the hash-chained audit log and a summary of the threat model. - [CLI — Vellaci CLI](https://www.vellaci.ch/docs/cli/usage): Install and use the Vellaci CLI: authenticate, list products, upload SBOMs with release gates, list vulnerabilities, create incidents and check status. - [OpenAPI 3 document](https://www.vellaci.ch/openapi.json): Public REST API specification - [security.txt](https://www.vellaci.ch/.well-known/security.txt): Machine-readable vulnerability reporting contact (RFC 9116) ## Company and trust - [Pricing](https://www.vellaci.ch/pricing): Evaluation, Readiness, Growth and Enterprise plans plus implementation packages, and which one fits which manufacturer. - [Security](https://www.vellaci.ch/security): How Vellaci protects vulnerability, incident and evidence data. - [Trust Center](https://www.vellaci.ch/trust): Hosting regions, security controls, privacy, subprocessors, disclosure programme and live status. - [Status](https://www.vellaci.ch/status): Live service status, availability computed from recorded probes, and incident history. - [Changelog](https://www.vellaci.ch/changelog): Meaningful product changes, with security-relevant changes marked. - [About](https://www.vellaci.ch/about): Who builds Vellaci, what it is and what it is not. - [Contact](https://www.vellaci.ch/contact): Book a CRA readiness review, request an implementation engagement, a demo or a security review. - [Responsible disclosure](https://www.vellaci.ch/security/disclosure): How to report a vulnerability in Vellaci. - [Privacy policy](https://www.vellaci.ch/privacy): How Vellaci processes personal data for the website and the application. - [Terms of service](https://www.vellaci.ch/terms): Summary terms for the Vellaci platform. - [Imprint](https://www.vellaci.ch/imprint): Legal notice: provider identification and contact. ## Optional - [Full text](https://www.vellaci.ch/llms-full.txt): All guides, glossary entries and documentation pages concatenated as Markdown