Coordinated Vulnerability Disclosure Policy

Effective date:11/09/2026
Last updated: 11/09/2026
Version: 1.0

1. Our Commitment

ENANCER ELECTRÓNICA, LDA (hereinafter referred to as "ENANCER") designs and manufactures connected devices and products with digital elements for home automation and building automation
applications.

We are committed to improving the security of our products throughout their supported lifecycle. We recognise that security researchers, customers, partners, integrators and other members of the security
community can help us identify vulnerabilities and improve the security of our products.

This Coordinated Vulnerability Disclosure (CVD) policy describes how security vulnerabilities in ENANCER products can be reported and how we will handle those reports.

The policy is intended to support our vulnerability handling processes and our applicable obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

2. Products Covered

This policy applies to our current product range, including products that use legacy communication or security mechanisms.

Products that have reached end-of-support may still be reported. Remediation and response options for such products may differ depending on technical and lifecycle considerations.

3. How to Report a Vulnerability

If you believe you have discovered a security vulnerability affecting a ENANCER product, please contact our security team:
Email: security@only-smartbuildings.com
Please use the subject: Security Vulnerability Report — [PRODUCT / ISSUE]

We accept vulnerability reports in english or portuguese.
Please do not disclose vulnerability details publicly before contacting us, where reasonably possible.
Coordinated disclosure gives us an opportunity to investigate the issue and, where appropriate, develop remediation or mitigation measures.

4. What to Include

Please provide as much of the following information as is reasonably available:

  • Product name
  • Serial Number
  • Product version
  • Firmware or software version, if applicable
  • Description of the vulnerability
  • Security impact and potential consequences
  • Steps required to reproduce the issue
  • Proof of concept, if available
  • Network or communication conditions required to reproduce the issue
  • Whether physical access to the device is required
  • Whether authentication or user interaction is required
  • Whether the issue affects other products or versions
  • Whether the vulnerability is publicly known or appears to be actively exploited

You do not need to have all of this information before contacting us. Reports will be accepted and
assessed based on the information available.

5. Examples of Security Issues We Accept

Examples of vulnerabilities that may be reported include:

  • Authentication or authorisation bypass
  • Unauthorised control of a device or system
  • Insecure or unauthenticated device communications
  • Replay, spoofing or message manipulation
  • Command injection
  • Remote code execution
  • Privilege escalation
  • Insecure firmware or software updates
  • Exposure of credentials, keys or sensitive information
  • Vulnerabilities in APIs or cloud services
  • Vulnerabilities in mobile applications
  • Vulnerabilities in third-party components affecting a ENANCER product

The examples above are illustrative and do not limit the types of vulnerabilities that may be reported.

6. Testing and Good-Faith Security Research

We welcome good-faith security research on ENANCER products.
Researchers should:

  • Test only products, systems and accounts that they own or are explicitly authorised to test
  • Limit testing to what is reasonably necessary to demonstrate the vulnerability
  • Avoid accessing, modifying, deleting or disclosing data belonging to other users
  • Avoid intentional disruption of services or devices
  • Avoid testing against other customers, users or third-party systems
  • Stop testing once sufficient evidence has been obtained to demonstrate the vulnerability
  • Report the vulnerability to ENANCER before public disclosure where reasonably possible

Hardware security research, including analysis of firmware or device interfaces, may be performed on devices lawfully owned or explicitly authorised for testing, provided that the research does not target other users or systems.

7. Safe Harbour

ENANCER does not intend to pursue civil or criminal action solely on the basis of good-faith security research conducted in accordance with this policy.

This commitment applies to research that is proportionate, conducted on authorised systems or devices, and does not involve malicious activity, intentional disruption, unauthorised access to third-party systems, data theft, extortion or other activity outside the scope of responsible security research.

If you are uncertain whether a planned research activity is covered by this policy, please contact us before proceeding.

8. Our Response Commitment

We process vulnerability reports promptly and transparently in accordance with our obligations under the EU Cyber Resilience Act.

Our target response milestones are:

Timelines and Extensions: The actual time required to investigate, remediate, and validate a vulnerability may vary based on technical complexity, hardware revisions, safety considerations, and involvement of third-party suppliers.

If an extension to these targets is required, we will proactively notify the reporter and provide a revised timeline. Where contact information is provided, we will keep the reporter informed at each milestone.

For vulnerabilities that meet the threshold for Article 14 notification under the CRA (actively exploited or severe security incidents), ENANCER will additionally notify the competent authorities within the prescribed timelines.

9. Vulnerability Assessment and Remediation

We assess reported vulnerabilities based on factors including:

  • Potential impact on users and products
  • Exploitability
  • Required access or privileges
  • Network exposure
  • Required user interaction
  • Number and type of affected products
  • Availability of mitigations
  • Evidence of exploitation

Where appropriate, we may address a vulnerability through:

  • Firmware or software updates
  • Security configuration changes
  • Protocol or communication changes
  • Workarounds or mitigations
  • Customer guidance
  • Product replacement or lifecycle measures

For vulnerabilities affecting legacy communication mechanisms or products undergoing security improvements, we may implement remediation progressively across affected product generations.

10. Third-Party Components

Our products may contain third-party hardware and software components.

If a reported vulnerability originates in a third-party component but affects a ENANCER product, we will assess the impact and, where appropriate, coordinate with the relevant supplier, manufacturer or maintainer.

Researchers reporting such vulnerabilities are encouraged to provide the component name, supplier and version where known.

11. Coordinated Disclosure

We follow a coordinated vulnerability disclosure process.

We ask researchers to allow reasonable time for investigation and remediation before publicly disclosing vulnerability details.

The appropriate disclosure timeline depends on the circumstances of each vulnerability, including:

  • Severity
  • Exploitability
  • Evidence of active exploitation
  • Availability of remediation
  • Customer exposure
  • Dependencies on third-party suppliers

If a vulnerability is already publicly known or is being actively exploited, please indicate this clearly in the report so that we can prioritise the response appropriately.

12. Security Advisories

Where appropriate, ENANCER may publish security advisories describing confirmed vulnerabilities and available remediation measures.

An advisory may include:

  • Affected products and versions
  • Description of the vulnerability
  • Security impact
  • Severity
  • Remediation or mitigation information
  • Relevant vulnerability identifiers, where available
  • Researcher acknowledgment, with the researcher's permission

We will take reasonable steps to avoid unnecessarily exposing sensitive information that could increase security risks to customers.

13. Researcher Recognition

We are happy to acknowledge researchers who responsibly report vulnerabilities.

Researchers may request:

  • Public credit
  • Anonymous credit
  • No public acknowledgment

We will not publicly identify a researcher without their permission, except where required by applicable law.

14. Bug Bounty and Researcher Rewards

ENANCER does not operate, and does not intend to establish, a bug bounty program.

Vulnerability reports submitted under this Coordinated Vulnerability Disclosure (CVD) policy are not eligible for monetary rewards, payments, or other financial compensation.

We nevertheless welcome and value good-faith security research and are committed to responsibly assessing and addressing vulnerability reports submitted in accordance with this policy.

Researchers may request public acknowledgment, anonymous credit, or no public acknowledgment, as described in this policy.

15. Confidentiality and Personal Data

Researchers should avoid accessing personal data, credentials, customer information or other confidential information unless this is unavoidable to demonstrate the vulnerability.

If such information is encountered accidentally, researchers should stop accessing additional information and notify us promptly.

Please do not include unnecessary personal data or confidential customer information in vulnerability reports.

16. Regulatory Reporting

ENANCER maintains internal processes for assessing whether vulnerabilities or security incidents trigger applicable regulatory reporting obligations.

Where applicable regulatory criteria are met, ENANCER will make the required notifications through the applicable regulatory reporting mechanisms and within the applicable regulatory timelines.

A vulnerability report submitted under this policy does not, by itself, determine whether a regulatory reporting obligation is triggered.

17. Policy Updates

We may update this policy from time to time to reflect changes to our products, security processes, regulatory requirements and industry practices.

The current version of this policy is available at: https://only-smartbuildings.com/cvd-policy/

18. Contacts

For security vulnerability reports:
security@only-smartbuildings.com

For general product support, please use:
info@only-smartbuildings.com

Only Smart Buildings

We do make

your life smarter

Contact Us

Enancer Electrónica, Lda.
Rua Max Grundig, 9
4705-820 Braga
PORTUGAL

tel. +351 253 221 484
info@only-smartbuildings.com
projects@only-smartbuildings.com (área comercial)
marketing@only-smartbuildings.com (área marketing)