EU Cyber Resilience Act (CRA) • Regulation (EU) 2024/2847
Security Policy & CRA Compliance
BravoBox commitment to connected product security, cyber resilience, and coordinated vulnerability disclosure.
Edge-First Secure Architecture: All BravoBox devices (relays, DIN modules, dimmers, sensors, and Edge Hub controllers) are engineered adhering to Security by Design and Security by Default. Home automation commands operate natively offline on the local network, drastically minimizing external attack surfaces.
1. Scope and Applicability
This security policy applies to the entire BravoBox ecosystem featuring digital elements:
- BravoBox Hardware & Edge Hub: DIN rail controllers, 503 flush-mount modules, embedded firmware (RS-485 Modbus, encrypted ESP-NOW, Zigbee 3.0, Matter bridge).
- Cloud Services & Network Infrastructure: MQTT TLS 1.3 broker, encrypted synchronization backend, and web APIs.
- Mobile Applications: BravoBox App for Android and iOS mobile devices.
2. Coordinated Vulnerability Disclosure (CVD)
BravoBox welcomes responsible disclosure from security researchers, partners, and users to discover and mitigate vulnerabilities before they can impact customer security.
How to report a vulnerability
Please send an encrypted or confidential report directly to our dedicated security response team:
Information to include in your report:
- Clear description of the vulnerability and affected components (device model, firmware revision, app version, or API endpoint).
- Step-by-step reproduction instructions or Proof of Concept (PoC).
- Assessment of potential impact and exploitability.
📄 Machine-readable RFC 9116 security contact:
/.well-known/security.txt
Our commitment to reporters
- Acknowledgment: Response and initial triage within 24 – 48 business hours.
- Remediation & Patching: Technical investigation and prioritized fix deployment according to CVSS severity scoring.
- Coordinated Disclosure: Public disclosure only after mitigations have been deployed to safeguard users.
- Authority Reporting: In compliance with the CRA, actively exploited vulnerabilities and severe incidents will be reported to national CSIRTs and ENISA within 24 hours of confirmation.
3. Product Security Lifecycle & Support Period
In compliance with EU Cyber Resilience Act requirements:
- Guaranteed Support Period: BravoBox commits to delivering security updates and vulnerability remediation for a minimum of 5 years from the commercial launch of each hardware revision.
- Secure Over-The-Air (OTA) Updates: Firmware updates are digitally signed with asymmetric ECDSA keys and validated by the secure hardware bootloader prior to flashing.
- End-of-Support Notice: Users will receive notifications via app alerts and email at least 6 months prior to the end of security support.
4. Key Security Architecture Principles
A. IoT Devices & Edge Hardware
- No Universal Default Passwords: Every BravoBox device utilizes unique cryptographic credentials generated during factory provisioning.
- Robust Wireless Encryption: Proprietary RF channels communicate with AES-128 (CCMP) encryption and continuous RF jamming supervision.
- Wired Bus Supervision: RS-485 serial communication detects wire-cuts, short circuits, and bus tamper events in real time.
- Hardware Whitelist: Only authorized devices registered in the local coordinator whitelist can join the automation ecosystem.
B. Network & Cloud Security
- End-to-End Encrypted Transport: All remote interactions traverse TLS 1.3 and WSS (WebSocket Secure).
- Anti-Injection Input Filters: Recursive payload sanitization neutralizes NoSQL injections, prototype pollution, and malformed inputs.
- Time-Fenced Guest Access: Temporary privileges for guests with automatic expiry and granular permission controls.
C. Software Supply Chain & SBOM
- Automated generation of Software Bill of Materials (SBOM in CycloneDX and SPDX international standards).
- Continuous dependency vulnerability auditing to remediate known CVEs prior to production deployments.
5. Security Contacts
For cybersecurity compliance, vulnerability inquiries, or data protection questions:
- Security & CRA Officer: security@bravobox.net
- General Inquiries: box@bravobox.net