Cybersecurity
Report a vulnerability – how to reach us and how we handle your report.
Our sensors, gateways and lighting controls operate in buildings that rely on them. If you have discovered a potential security vulnerability in one of our products or on this website, please report it directly to us. We review every report, keep you informed of its status and fix confirmed vulnerabilities as quickly as possible.
1. Contact point
- Email: security@deuta-controls.de
- Subject: “Security vulnerability” and the product name
- Languages: German or English
Please send details of a vulnerability only to this address, not via the contact form, social networks or public forums. Please send confidential attachments such as proof-of-concept code as an encrypted ZIP archive. We will agree on the password with you through a separate channel.
The contact point is also available in machine-readable form in our security.txt file at www.deuta-controls.net/.well-known/security.txt.
2. What your report should contain
- the affected product with its type designation and firmware or software version
- a description of the vulnerability and its possible impact
- the steps to reproduce it, ideally with a proof of concept, screenshots or logs
- the prerequisites, such as configuration, required access, radio or network access
- your contact details for questions and whether we may name you in the security advisory
We take incomplete reports seriously too. Anonymous reports are possible. In that case, however, we cannot keep you informed of the status.
3. How we proceed
| Step | What happens | Target time |
|---|---|---|
| Receipt | We confirm receipt of your report. | within 3 working days |
| Assessment | We check whether the vulnerability can be reproduced, which products and versions are affected and how severe it is. We inform you of the result. | within 10 working days |
| Remediation | We develop and test an update or a mitigation. | target: 90 days after the report |
| Status updates | As long as the report is open, we keep you informed of the progress. | at least every 30 days |
| Disclosure | We publish a security advisory and inform affected customers. | as soon as an update or mitigation is available |
These times are targets, not guarantees. If a vulnerability is already being actively exploited, we give it priority over all other reports.
4. Scope
Included
- all products with digital elements that we develop and sell: the EnoSense and EnoPuck sensors, the EnoSign room display, the EnoDisc radio receiver, the VL-700 BASE gateway with the ECS Dashboard and the lighting controls of the BL and AL series
- the associated firmware and the software we provide in the download center
- this website
If a vulnerability affects a supplier’s component in our devices, such as a radio module, we treat it like a vulnerability in our own product and coordinate with the supplier.
Not included
- products and services of other manufacturers that are not part of our devices
- problems caused by incorrect configuration or improper operation, for example a gateway connected to the internet without protection contrary to the instructions
- plain results of automated scanners without a demonstrable impact
- interference with the radio transmission by jammers. Such interference cannot be prevented in radio systems as a matter of principle.
5. Rules and legal protection
Please follow these rules when searching for vulnerabilities:
- Access systems or data only to the extent necessary to demonstrate the vulnerability.
- Do not modify or delete any data and do not disrupt any operation, including through denial-of-service attacks.
- Do not test in third-party buildings or installations without the operator’s permission.
- Refrain from social engineering, phishing and physical attacks on our employees and sites.
- Keep the vulnerability confidential until we have disclosed it together.
Anyone who follows these rules and acts in good faith need not fear legal action from us. This cannot, however, restrict the rights of third parties, such as the operators of installations.
6. Disclosure and security advisories
We publish fixed vulnerabilities on this page. Each security advisory states the affected products and versions, the severity of the vulnerability, the update or mitigation and, with your consent, your name. For significant vulnerabilities, we request a CVE identifier. We agree the date of publication with you.
Published security advisories: none so far
7. Cyber Resilience Act
The EU Cyber Resilience Act (Regulation (EU) 2024/2847, CRA) sets requirements for products with digital elements. Since 11 September 2026, manufacturers have been reporting actively exploited vulnerabilities and severe security incidents to the competent authorities via the ENISA single reporting platform. We report such cases via this platform within the deadlines. The remaining requirements apply from 11 December 2027. Until then, we are gradually switching our radio components to encrypted transmission.
8. Data protection
We use the information in your report only to process the report and to meet our legal obligations. We publish your name only with your consent. Details can be found in our privacy policy.
Version 1.0, as of: 27 September 2026
Found a vulnerability?
Write to security@deuta-controls.de. We confirm receipt within 3 working days.