Security update policy & Vulnerability reporting

Security Update Policy & Support Period Information

The vulnerability reporting process and this security policy are publicly available on our website at www.remootio.com/security-policy

Product Name:

  • Remootio 3
  • Remootio 2

    (hereinafter referred to as "The Products")

1. Commitment to Security

We are committed to ensuring the security and resilience of The Products throughout their lifecycle. In line with the EU Cyber Resilience Act (CRA) and the UK Product Security and Telecommunications Infrastructure (PSTI) requirements, we will monitor, assess, and address vulnerabilities that may impact the confidentiality, integrity, or availability of the Products.

2. Support Period

  • Security updates will be provided for a minimum of 5 years from the date the product was first placed on the EU market, until at least 31 December 2030
  • During this period, we will:
    1. Monitor for reported vulnerabilities.
    2. Provide necessary security updates and patches.
    3. Make updates available e.g., over-the-air software updates for The Products in the Remootio app either via Bluetooth or Wi-Fi.

3. Availability of Updates

  • All security updates released within the support period will remain accessible for at least 10 years after publication (or for the remainder of the support period, whichever is longer).
  • Updates will be provided free of charge to customers within the support period.

4. End of Support

  • At the end of the declared support period, we will publicly announce the end-of-support date for The Products, but the support period will be at least the minimum period specified in 2. Support Period.
  • After that date, no further security patches or vulnerability management will be guaranteed.

5. Contact & Vulnerability Reporting

Customers, security researchers, and partners are encouraged to report any suspected vulnerabilities in The Products via:

We will acknowledge receipt of vulnerability reports within 7 days via e-mail to the reporter's e-mail address. We will provide an estimated remediation timeframe to the reporter based on the severity of the vulnerability. High-severity issues are addressed as a priority. We may coordinate with reporters on responsible disclosure and publicly communicate patches when appropriate.

The Products are considered relevant connectable products under the UK PSTI requirements. This policy is publicly available to meet the accessibility requirements of both EU CRA and UK PSTI.