🔔 Security Advisories

Published security notices for Cloud Spectra products. This is the canonical channel through which we inform users of vulnerabilities and security incidents, and of the mitigations available.

No advisories have been published to date. This page is maintained so that a stable, citable location exists before it is needed. When an advisory is published it appears here, and impacted customers are additionally notified by email.

To report a vulnerability, see Responsible Disclosure or write to security@CloudSpectra.Ai. Our machine-readable policy is at /.well-known/security.txt (RFC 9116).

What each advisory contains: the affected product and versions, a description of the issue and its severity and impact, the corrective or mitigating measures we have taken, the measures you can take, and the release that remedies it.
🔄 Product Support Period

The period during which we provide security updates for each product, as required of manufacturers under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

Cloud Spectra provides security updates for five (5) years from the release date of each product version. Security updates are provided free of charge, are delivered without undue delay, and are separable from feature updates -- you can take a security fix without taking new functionality.

Security updates are delivered through the product's built-in update mechanism. Where a release reaches the end of its support period, we publish notice on this page ahead of that date.

Reporting obligations continue after support ends. Where we become aware of an actively exploited vulnerability or a severe security incident affecting a product, we notify the relevant authorities and impacted users irrespective of whether that product is still within its support period.