Skip to content
SiteWorx
  • Plate-forme
    • Ce que nous faisons
      • Présentation de la plateforme
      • Pourquoi SiteWorx
      • Qui nous servons
    • Matériel
      • Commandes d'éclairage
      • Appareils intelligents
      • Appareils de connectivité
    • Logiciel
      • SiteWorx Plateforme Cloud
      • API Intégrations
    • Prêt à réduire le gaspillage d’énergie dans votre installation ?Commencer →
  • Solutions
    • Eau et débit
      • Débitmètre
      • Détection des fuites
    • HVAC & Air
      • HVAC Contrôle
      • Surveillance de la température et de l'humidité
      • Contrôle de l'air comprimé
    • Gaz & Vapeur
      • Comptage de gaz
      • Dosage de vapeur
    • Électricité
      • Contrôle de l'éclairage
      • Contrôle de charge
      • Mesure de puissance
    • Prêt à réduire le gaspillage d’énergie dans votre installation ?Commencer →
  • Ressources
    • Documentation
      • Brochures et notes techniques
      • Fiches techniques et dessins
      • Instructions d'installation
      • Politiques et conditions
    • Apprentissage
      • Articles
      • Témoignages de clients
      • Informatique et sécurité
    • Soutien
      • Centre d'aide
      • Contact
    • Prêt à réduire le gaspillage d’énergie dans votre installation ?Commencer →
  • À propos
    • Entreprise
      • Qui nous sommes
      • Notre équipe
      • Contact
    • Presse
      • Bulletin
      • Rédaction
    • Carrières
      • Travailler à SiteWorx
      • Emplois ouverts
    • Prêt à réduire le gaspillage d’énergie dans votre installation ?Commencer →
EnglishEspañolFrançaisDeutsch
Contactez-nousCommencer

Politiques et conditions

  • Aperçu
  • Termes
  • Conditions d'utilisation
  • Conditions de vente
  • Déclaration de garantie limitée
  • Politiques
  • politique de confidentialité
  • Politique de données
  • Politique en matière de cookies
  • Security
  • Security

Security

Download Coordinated Vulnerability Disclosure Policy (PDF) ↗

Effective September 11, 2026

Policy Overview

At SiteWorx, cybersecurity and hardware integrity are fundamental to our operations. We recognize the vital role that independent security researchers, customers, and the broader global white-hat community play in identifying vulnerabilities.

This document describes our policy for informing customers and partners of potential security vulnerabilities in supported products and services.

Scope

This policy covers all commercial products and connected services made available by SiteWorx, in accordance with the EU Cyber Resilience Act (Regulation EU 2024/2847).

Out-of-scope assets

  • Physical & Social Engineering: Physical access attacks on SiteWorx facilities, offices, or personnel, as well as phishing or social engineering.
  • Service Disruption: Any form of Denial of Service (DoS/DDoS) attack intended to exhaust system resources or disrupt physical hardware and cloud services.
  • Low-Impact Web Flaws: Missing non-critical HTTP response headers without a demonstrated exploit path, or CSRF on non-sensitive, public forms.
  • Third-Party Systems: Independent third-party cloud applications, external APIs, or upstream software components not directly maintained or customized by SiteWorx.

Safe Harbor

SiteWorx permits individuals to conduct non-commercial security research and testing on our hardware, firmware, and cloud services, provided such activities are performed in good faith to identify, analyze, or remediate potential security vulnerabilities.

SiteWorx will not initiate or support legal action against any researcher who makes a genuine, good-faith effort to adhere to our Coordinated Vulnerability Disclosure (CVD) process and complies with all applicable local and international laws.

This authorization strictly excludes any security testing that disrupts, degrades, or damages SiteWorx devices, software, or infrastructure, or is conducted with malicious intent or in bad faith. Furthermore, this safe harbor protection does not extend to unauthorized security testing performed on third-party services, external APIs, or upstream dependencies integrated with SiteWorx products.

Reporting Channel & Submission Requirements

Please submit all discovered security issues directly to our monitored security intake:

  • Primary Email: security@siteworx.io
  • RFC 9116 Metadata: https://siteworx.io/.well-known/security.txt

Submission Checklist

  1. Target Identification: Device model (e.g., SGW1), firmware version, build tag, or specific cloud API endpoint.
  2. Vulnerability Classification: Category (e.g., Remote Code Execution, Privilege Escalation, Command Injection).
  3. Reproduction Steps: Step-by-step instructions or proof-of-concept scripts to reproduce the vulnerability safely.
  4. Impact Assessment: Your analysis of how an attacker could leverage the flaw and its potential operational impact.
  5. Attribution: Your name, handle, or organization for public credit (or explicitly note if you prefer to remain anonymous).

Regulatory Compliance

SiteWorx complies with the European Union Cyber Resilience Act (Regulation EU 2024/2847).

  • Mandatory Disclosure: Under Article 14 of the CRA, if a reported vulnerability is determined to be actively exploited in the wild, SiteWorx is legally required to notify the European Union Agency for Cybersecurity (ENISA) and relevant national Computer Security Incident Response Teams (CSIRTs) via the ENISA Single Reporting Platform (SRP).
  • Reporting Schedule: This regulatory process operates on a multi-stage timeline: an Early Warning within 24 hours of confirmed active exploitation awareness, a Detailed Notification within 72 hours, and a Final Report within 14 days of patch availability.
  • Independent Execution: Regulatory filings to ENISA operate independently of our direct coordination commitments with reporting researchers.
SiteWorx
SiteWorx Logiciel USA LLC
6-10 Ek CT
Shrewsbury, MA 01545
États-Unis
1 (857) 357-4200
info@siteworx.io
  • LinkedIn

Plate-forme

Ce que nous faisons

  • Aperçu
  • Pourquoi SiteWorx
  • Qui nous servons

Matériel

  • Commandes d'éclairage
  • Appareils intelligents
  • Appareils de connectivité

Logiciel

  • SiteWorx Plateforme Cloud
  • API Intégrations

Solutions

Eau et débit

  • Débitmètre
  • Détection des fuites

HVAC & Air

  • HVAC Contrôle
  • Surveillance de la température et de l'humidité
  • Contrôle de l'air comprimé

Gaz & Vapeur

  • Comptage de gaz
  • Dosage de vapeur

Électricité

  • Contrôle de l'éclairage
  • Contrôle de charge
  • Mesure de puissance

Ressources

Documentation

  • Brochures et notes techniques
  • Fiches techniques et dessins
  • Instructions d'installation
  • Politiques et conditions
  • Security

Apprentissage

  • Articles
  • Témoignages de clients
  • Informatique et sécurité

Soutien

  • Centre d'aide
  • Contactez-nous

À propos

Entreprise

  • Qui nous sommes
  • Notre équipe
  • Contactez-nous

Presse

  • Bulletin
  • Rédaction

Carrières

  • Travailler à SiteWorx
  • Emplois ouverts

© 2026 SiteWorx Logiciel USA LLC. Tous droits réservés.

  • Politiques et conditions
  • Security

Nous accordons une grande importance à votre vie privée

Nous utilisons des cookies pour gérer ce site, analyser le trafic et améliorer votre expérience. Choisissez les cookies que nous pouvons utiliser. Politique en matière de cookies