Product security and Cyber Resilience Act readiness
Current product-security controls and the work Banalytics has not yet completed for EU CRA conformity.
Readiness, not conformity
Banalytics is preparing its product-security programme for the EU Cyber Resilience Act. It does not currently claim CRA conformity, completed conformity assessment or CE marking based on the CRA.
What exists today
- Versioned Agent modules and public release information.
- A maintained inventory of product components and dependencies.
- A published channel for vulnerability reports.
- Local configuration ownership and separation of Portal signalling from operational data.
- Release decisions agreed by both co-founders and technically performed by the designated technical co-founder.
- Security and product issues recorded in Jira.
Controls still being formalised
| Control | Current status |
|---|---|
| Machine-readable SBOM for each supported release | Planned; release information is not an SBOM |
| Signed update packages and signature verification | Not currently implemented |
| Documented threat modelling and secure-development gates | Planned before production pilots |
| Formal vulnerability severity and remediation targets | Reports are handled on a best-effort basis; no fixed Community SLA |
| Published support period for each product | Not yet fixed; Enterprise commitments require a written contract |
| CRA reporting owner and submission procedure | To be established before reporting obligations apply |
| Conformity technical file | Release documentation exists; formal file not yet complete |
| Automated dependency and vulnerability scanning | Ad hoc review exists; a repeatable toolchain is still required |
Product controls and deployment controls
Banalytics remains responsible for vulnerabilities and security properties of software it distributes to the extent required by applicable law. The Agent owner remains responsible for the host operating system, local network, connected equipment, credentials, storage, custom modules, optional integrations and operational configuration.
A user-controlled setting does not remove a product-security obligation that applies to Banalytics. Conversely, Banalytics cannot validate or secure customer equipment and custom code that it cannot access and does not operate.
Community and contracted support
Community Edition security corrections are currently provided on a best-effort basis without a fixed remediation or support SLA. A pilot or Enterprise agreement may define supported versions, update method, response targets and a minimum support period.
See the Vulnerability Disclosure Policy to report a concern.
Last updated: 23 July 2026.