Skip to content

First steps

  1. Create your organisation on first sign-in. You then receive the email “Set the password for your organisation” — it names your organisation and is not the verification email from your registration. Your organisation has its own account with its own sign-in area; the link sets that account’s password.
  2. Register a product and its versions under Products.
  3. Ingest an SBOM (CycloneDX or SPDX JSON) per version — or request one from a supplier.
  4. Record deployments (customer × site) so fleet correlation and the evidence pack know where machines run.
  5. Review Vulnerabilities — Resilic correlates your fleet against EUVD, NVD and the CISA KEV catalogue continuously.

On your first sign-in a short tour points out the essentials — products, vulnerabilities, the Article 14 workflow, the setup checklist and the Copilot. Skip it anytime; Show tour in the top bar replays it whenever you like.

Press ⌘K (Ctrl-K on Windows/Linux) — or tap the search icon — to open the search palette, a centered overlay available from every screen (including on mobile). It finds products (by name or manufacturer) and incident reports (by title or CVE); a CVE-shaped term like CVE-2026-1487 offers a direct jump into the vulnerabilities view.

You can filter with wildcards: * matches any sequence of characters and ? exactly one — for example VIC-?00 finds VIC-100 and VIC-200, and *Controller finds everything ending in “Controller”. Without wildcards, the search simply matches anywhere in the name.

The palette also navigates. Open it without typing and every screen you can reach is listed under Navigate — arrow keys and Enter are enough, the mouse stays where it is. Typing filters the list too: vuln goes straight to vulnerabilities.

It only ever lists what you are permitted to use: screens your role does not grant simply do not appear, rather than sitting there greyed out. The palette describes what you can do, not the shape of the organisation.

At the top, Recently opened lists the last products and vulnerabilities you looked at — for the commonest move of all: getting back to what you were just working on. That list stays in your browser and is kept separately per organisation, so it changes when you switch organisations.

Actions, last, are things you can start straight away — Add product, Invite member. They don’t just take you to the right screen: they land with the dialog already open. As everywhere in the palette, you only see what your role permits.

The dashboard checklist tracks seven steps — from registering a product to seeing your first vulnerability match and creating your first evidence artifact. Each step completes automatically from your data; loading demo data completes the first-match moment instantly.

Getting a real SBOM can take days inside a machine builder’s organisation. Use Load demo data (offered on the dashboard checklist and the empty products view) to seed a clearly badged demo product whose bill of materials contains genuinely vulnerable components — including an actively-exploited match — so you see the full correlation workflow in minutes. The demo product is marked with a Demo badge everywhere and Remove demo data deletes it completely; your real products and data are never affected.