Getting Started Cameras & Video Detection & Recording Industry & Edge Automation & Events Actions Integration & Connectivity Network & Discovery AI & Remote Control MQTT Modbus Pi4J & Raspberry Pi GPIO ZeroMQ System & Administration Comparisons Use Cases Troubleshooting About & Legal
Home / Documentation / Product Security and EU CRA Readiness
Product security CRA readiness

Product security and Cyber Resilience Act readiness

Current product-security controls and the work Banalytics has not yet completed for EU CRA conformity.


Readiness, not conformity

Banalytics is preparing its product-security programme for the EU Cyber Resilience Act. It does not currently claim CRA conformity, completed conformity assessment or CE marking based on the CRA.

What exists today

  • Versioned Agent modules and public release information.
  • A maintained inventory of product components and dependencies.
  • A published channel for vulnerability reports.
  • Local configuration ownership and separation of Portal signalling from operational data.
  • Release decisions agreed by both co-founders and technically performed by the designated technical co-founder.
  • Security and product issues recorded in Jira.

Controls still being formalised

ControlCurrent status
Machine-readable SBOM for each supported releasePlanned; release information is not an SBOM
Signed update packages and signature verificationNot currently implemented
Documented threat modelling and secure-development gatesPlanned before production pilots
Formal vulnerability severity and remediation targetsReports are handled on a best-effort basis; no fixed Community SLA
Published support period for each productNot yet fixed; Enterprise commitments require a written contract
CRA reporting owner and submission procedureTo be established before reporting obligations apply
Conformity technical fileRelease documentation exists; formal file not yet complete
Automated dependency and vulnerability scanningAd hoc review exists; a repeatable toolchain is still required

Product controls and deployment controls

Banalytics remains responsible for vulnerabilities and security properties of software it distributes to the extent required by applicable law. The Agent owner remains responsible for the host operating system, local network, connected equipment, credentials, storage, custom modules, optional integrations and operational configuration.

A user-controlled setting does not remove a product-security obligation that applies to Banalytics. Conversely, Banalytics cannot validate or secure customer equipment and custom code that it cannot access and does not operate.

Community and contracted support

Community Edition security corrections are currently provided on a best-effort basis without a fixed remediation or support SLA. A pilot or Enterprise agreement may define supported versions, update method, response targets and a minimum support period.

See the Vulnerability Disclosure Policy to report a concern.

Last updated: 23 July 2026.