INOGENI is committed to designing, maintaining, and supporting secure professional AV products throughout their lifecycle. This page explains our approach to the Cyber Resilience Act, provides access to relevant cybersecurity resources, and offers a responsible channel to report potential vulnerabilities in our products.

What is the Cyber Resilience Act?

The Cyber Resilience Act is a European Union regulation that introduces mandatory cybersecurity requirements for products with digital elements, including connected hardware, software, and related digital components placed on the EU market. Its objective is to improve the security of digital products by requiring manufacturers to consider cybersecurity throughout the design, development, production, and post-market support phases.

The CRA also reinforces obligations for handling vulnerabilities. Manufacturers must maintain processes to identify, assess, remediate, and communicate security vulnerabilities during the product support period. Reporting obligations for actively exploited vulnerabilities and severe security incidents begin on 11 September 2026, while the main CRA obligations take effect on 11 December 2027.

 

INOGENI’s approach to cyber resilience

INOGENI is preparing its product security processes to align with the CRA’s lifecycle-based approach to cybersecurity. Our objective is to provide clear security information, support coordinated vulnerability disclosure, and maintain appropriate corrective actions for affected products when a confirmed cybersecurity issue is identified.

  • Security-by-design practices during product development
  • Cybersecurity risk assessment for applicable products
  • Vulnerability monitoring and coordinated vulnerability disclosure
  • Security update planning during the defined product support period
  • Clear communication with customers, partners, and relevant authorities when required

 

What the portal offers

The INOGENI Product Security Portal is intended to be the central location for cybersecurity-related information about INOGENI products. It should help users find relevant product security documentation, understand current security advisories, and submit vulnerability reports through a structured and secure process.

  • CRA overview: A plain-language explanation of how the regulation affects connected products and product lifecycle support
  • Product security resources: Access to cybersecurity notices, product security documentation, firmware update information, and support guidance
  • Vulnerability reporting: A secure form for researchers, customers, and partners to report suspected vulnerabilities
  • Disclosure process: Information about how INOGENI reviews, validates, prioritizes, and communicates confirmed vulnerabilities

Report a vulnerability

If you believe you have discovered a potential security vulnerability in an INOGENI product, please submit a report by contacting us at the following email address: security@inogeni.com. We ask that you provide enough technical details to allow our team to reproduce, validate, and assess the issue.

Here is the information we need to include in your email when submitting a report:

  • Name
  • Organization
  • Email address
  • Product affected (Include the serial number and firmware version)
  • Vulnerability title
  • Technical description
  • Steps to reproduce
  • Potential impact
  • Proof of concept
  • Disclosure status
  • Preferred communication method

Please do not publicly disclose the vulnerability until INOGENI has had a reasonable opportunity to investigate and provide guidance or corrective action when applicable.

 

What happens after submission?

  1. Acknowledgement: INOGENI reviews the submission and confirms receipt when sufficient contact information is provided.
  2. Initial assessment: Our team evaluates whether the report affects an INOGENI product and whether the technical details are sufficient for investigation.
  3. Validation: When applicable, we attempt to reproduce the issue and assess its severity and scope.
  4. Remediation planning: If the vulnerability is confirmed, INOGENI determines appropriate corrective actions, which may include firmware or software updates, documentation, configuration guidance, or customer communication.
  5. Coordinated disclosure: INOGENI coordinates communication with the reporter and relevant stakeholders, including regulatory or cybersecurity authorities when required.

 

Responsible disclosure guidelines

To help protect customers and maintain a constructive disclosure process, we ask reporters to follow responsible security research practices.

  • Act in good faith and avoid actions that could disrupt services, damage systems, or expose customer data.
  • Do not access, modify, delete, or exfiltrate data that does not belong to you.
  • Provide clear technical details so the issue can be validated efficiently.
  • Allow INOGENI reasonable time to investigate and address confirmed issues before public disclosure.
  • Do not use the vulnerability for unauthorized access, persistence, lateral movement, or exploitation beyond what is necessary to safely demonstrate the issue.

FAQ

Which products are covered? ^

The CRA generally applies to products with digital elements that are made available on the EU market. This may include connected hardware products, software components, firmware, and related digital elements. INOGENI will provide product-specific information where applicable.

Can I report a vulnerability if I am not in the European Union? ^

Yes. INOGENI welcomes vulnerability reports from customers, partners, integrators, researchers, and other stakeholders regardless of location.

Will INOGENI publish security advisories? ^

When appropriate, INOGENI may publish product security advisories, firmware or software update notices, mitigation guidance, or other customer communications related to confirmed cybersecurity issues.

Is this page legal advice? ^

No. This page is intended to provide general information on product security and vulnerability reporting. It does not replace the official CRA legal text, regulatory guidance, or professional legal advice.

Search
×
Close