Device access control
Home accounts access their own devices; enterprise users need explicit device grants. Signaling and TURN apply the same authorization model.
As we develop remote access for energy and industrial IoT sites, we are making our software inventory and security preparation visible too.
Implemented technical controls and remaining work are shown separately.
Home accounts access their own devices; enterprise users need explicit device grants. Signaling and TURN apply the same authorization model.
Direct P2P over WebRTC, with authorized TURN relaying encrypted traffic when direct connectivity is unavailable. Real field network acceptance remains open.
A security owner and contact are identified; an incident procedure and technical tabletop review are prepared. Backup coverage, account access and a human exercise remain open.
Internal planning targets, not product launch dates or promises of conformity.
Product inventory, a classification draft and reporting procedure are prepared. Backup coverage, access checks and final license approval remain open.
Threat modeling, automated security checks, platform-specific SBOMs and signed releases. The initial source inventory is available below.
Secure updates, a support policy, real field tests, independent review and the applicable conformity assessment.
For in-scope manufacturers, CRA reporting duties started on 11 September 2026; the main product obligations apply from 11 December 2027. EdgeSocket’s final scope and classification still need confirmation. Official sources: Commission CRA overview · Reporting rules.
An SBOM lists software components in a machine-readable format. It is a starting point for technical procurement and dependency review, not a vulnerability scan or security certificate.
CycloneDX 1.6 JSON: direct and transitive Go modules, test dependencies and the Go standard library used for analysis. Commit: 562ad9549eaa.
Container and operating system packages, CDN services and platform-specific release binaries are excluded. This is not a full inventory of the live server. Detected licenses are preliminary evidence; reviewed licensing and signed release SBOMs are future work.
This initial inventory is unsigned. Review the source revision and scope alongside the download.
We do not make that claim yet. This page shows preparation and open work; the final conformity assessment is not complete.
It covers EdgeSocket’s product security, dependency tracking, security updates and vulnerability reporting processes. This page distinguishes completed work from planned work.
Yes. Product security preparation is being designed for both models. The complete product and management app are not generally available yet.
Product security owner: Ege Meriç Erdoğan. Email the affected component/version, impact and a short reproduction privately. Do not use the sales form or public comments.
[email protected] ↗Do not send passwords, tokens or customer data. No encryption key is currently published; agree a secure channel before sharing sensitive evidence. Test only in your own authorized environment. No stable release/support period, backup responder or guaranteed response SLA has been announced yet.
security.txtShare your field access needs and supplier security expectations. The product is in development; your feedback can inform the preparation plan.