edgesocket.
SECURITY · TRANSPARENCY

Security is part
of the product.

As we develop remote access for energy and industrial IoT sites, we are making our software inventory and security preparation visible too.

What exists today?

Implemented technical controls and remaining work are shown separately.

Device access control

Home accounts access their own devices; enterprise users need explicit device grants. Signaling and TURN apply the same authorization model.

Encrypted connectivity

Direct P2P over WebRTC, with authorized TURN relaying encrypted traffic when direct connectivity is unavailable. Real field network acceptance remains open.

Reporting preparation

A security owner and contact are identified; an incident procedure and technical tabletop review are prepared. Backup coverage, account access and a human exercise remain open.

Readiness roadmap

Internal planning targets, not product launch dates or promises of conformity.

  1. P0 · NowIn progress

    Scope and reporting

    Product inventory, a classification draft and reporting procedure are prepared. Backup coverage, access checks and final license approval remain open.

  2. P1–P2 · October–December 2026Planned

    Risk and release evidence

    Threat modeling, automated security checks, platform-specific SBOMs and signed releases. The initial source inventory is available below.

  3. P3–P6 · January–November 2027Planned

    Support and assessment

    Secure updates, a support policy, real field tests, independent review and the applicable conformity assessment.

For in-scope manufacturers, CRA reporting duties started on 11 September 2026; the main product obligations apply from 11 December 2027. EdgeSocket’s final scope and classification still need confirmation. Official sources: Commission CRA overview · Reporting rules.

What is in the software?

An SBOM lists software components in a machine-readable format. It is a starting point for technical procurement and dependency review, not a vulnerability scan or security certificate.

CYCLONEDX 1.6 · JSON

Initial inventory · Go source module

CycloneDX 1.6 JSON: direct and transitive Go modules, test dependencies and the Go standard library used for analysis. Commit: 562ad9549eaa.

Scope limits

Container and operating system packages, CDN services and platform-specific release binaries are excluded. This is not a full inventory of the live server. Detected licenses are preliminary evidence; reviewed licensing and signed release SBOMs are future work.

This initial inventory is unsigned. Review the source revision and scope alongside the download.

Quick answers

Is EdgeSocket CRA compliant?

We do not make that claim yet. This page shows preparation and open work; the final conformity assessment is not complete.

What does CRA preparation cover?

It covers EdgeSocket’s product security, dependency tracking, security updates and vulnerability reporting processes. This page distinguishes completed work from planned work.

Does the plan cover cloud and on-premises deployment?

Yes. Product security preparation is being designed for both models. The complete product and management app are not generally available yet.

Report a vulnerability

Product security owner: Ege Meriç Erdoğan. Email the affected component/version, impact and a short reproduction privately. Do not use the sales form or public comments.

[email protected]

Do not send passwords, tokens or customer data. No encryption key is currently published; agree a secure channel before sharing sensitive evidence. Test only in your own authorized environment. No stable release/support period, backup responder or guaranteed response SLA has been announced yet.

security.txt

Evaluating a supplier?

Share your field access needs and supplier security expectations. The product is in development; your feedback can inform the preparation plan.

Share your requirements