← Back to Home
EU Cyber Resilience Act (CRA) • Regulation (EU) 2024/2847

Security Policy & CRA Compliance

BravoBox commitment to connected product security, cyber resilience, and coordinated vulnerability disclosure.

Edge-First Secure Architecture: All BravoBox devices (relays, DIN modules, dimmers, sensors, and Edge Hub controllers) are engineered adhering to Security by Design and Security by Default. Home automation commands operate natively offline on the local network, drastically minimizing external attack surfaces.

1. Scope and Applicability

This security policy applies to the entire BravoBox ecosystem featuring digital elements:

2. Coordinated Vulnerability Disclosure (CVD)

BravoBox welcomes responsible disclosure from security researchers, partners, and users to discover and mitigate vulnerabilities before they can impact customer security.

How to report a vulnerability

Please send an encrypted or confidential report directly to our dedicated security response team:

🔒 security@bravobox.net

Information to include in your report:

📄 Machine-readable RFC 9116 security contact: /.well-known/security.txt

Our commitment to reporters

3. Product Security Lifecycle & Support Period

In compliance with EU Cyber Resilience Act requirements:

4. Key Security Architecture Principles

A. IoT Devices & Edge Hardware

B. Network & Cloud Security

C. Software Supply Chain & SBOM

5. Security Contacts

For cybersecurity compliance, vulnerability inquiries, or data protection questions: