Skip to content

Notification preferences

Resilic emails notifications per user, per category. Every teammate manages their own preferences from the settings screen; mail always goes to your account email address (there is no per-category address override).

Alongside email, the bell in the top bar carries an in-app inbox. It shows a real unread counter (never a decorative dot), and its panel lists the latest alerts with a mark-all-read action and a click-through to the relevant screen. The inbox is shared across your team — compliance alerts are team work, so one teammate marking them read clears the counter for everyone, like a shared PSIRT mailbox. The bell is always on and independent of your personal email preferences below.

Two things reach the bell without any email counterpart: Article 14 deadline nudges land there exactly once per approaching or missed stage (in addition to the reminder emails below, if subscribed), and a supplier SBOM arrival — a supplier uploading against an open request — posts a bell notification linking to the suppliers screen, since the upload itself happens anonymously via the share link.

  • Actively-exploited vulnerability alerts — new actively-exploited (CISA KEV) vulnerabilities match deployed products. One email per sync run listing every new match — a backfill SBOM full of old firmware becomes one loud alert, never an inbox avalanche. This is a CRA Article 14 awareness trigger for you to assess — not a legal determination that a reporting obligation exists. See correlation & triage.
  • Article 14 reporting-deadline reminders — reminders as a reporting deadline on an open reportable event approaches (the 24h early warning, the 72h notification, or a final report whose clock is running). See reports & deadlines.
  • Supplier re-qualification reminders — a supplier’s re-qualification comes due, with a 30-day lead. See suppliers & qualification.
  • Risk assessment review needed — new evidence (an exploited match, a new SBOM, or a new deployment) has flagged an approved risk assessment for review.
  • New vulnerability matches (digest) — the scheduled correlation found new matches on your fleet that are not known to be actively exploited. One digest per sync run (never one email per CVE), listing the top matches by severity with a link to the triage queue. A heads-up for fleet managers — not an Article 14 trigger. See correlation & triage.
  • CSAF hosting domain drifted — a verified CSAF hosting domain’s DNS no longer delegates to us, so publishing to it is paused until you fix the CNAME and re-verify. A security/ops alert. See CSAF hosting.
  • Disclosure surface unreachable — an approved CVD policy is no longer reachable at its published URL, so researchers following your security.txt can’t read it. An ops nudge to fix the public surface.
  • CRA classification re-review — the CRA product-category lists (Annex III/IV) changed, so one or more of your signed product classifications need re-review. The signed record stands until you re-review and re-sign it.
  • Component end-of-life risk — a component inside a product reaches end-of-life before the support period you committed to, so the product promises support past the life of a part inside it. A readiness nudge, never a block. See SBOMs & components.
  • Support-period re-review — a signed support-period determination needs re-review because an input it rested on changed: a new exploited match, an earlier component end-of-life, or a revised SBOM. The signed record is kept until you re-review and re-sign it. See products & support period.
  • Policy attestations outstanding — staff were sent AI-use policy attestation links that they haven’t confirmed yet. A weekly nudge to the compliance owner to chase them; the coverage view shows exactly who. See AI literacy.
  • Training outstanding — staff were sent AI-literacy training links that they haven’t completed yet. A weekly nudge to the compliance owner to chase them; the training matrix shows exactly who. See AI literacy.
  • Default is on. A new member is subscribed to every category until they switch one off; only your deviations from the default are stored.
  • Toggling a category off stops the emails for you — teammates keep their own settings, and the underlying event is still recorded in Resilic either way. Opting out of an email never hides anything in the product.
  • Only active members receive mail. Invited or suspended members never do.

Open Settings → Notification preferences, toggle the categories you want, and save. The matrix shows a short description next to each category so it is clear what you are turning off before you do it.

One framing note, because it matters: notification emails are conveniences layered over the workflows, not the workflows themselves. In particular, an exploited-match email does not start the Article 14 clock — only a person declaring a reportable event and confirming the awareness time does that — and a missed deadline reminder does not move a deadline. Treat the emails as nudges toward the screens where the recorded, human-signed decisions happen.