Reporting vulnerabilities, our response, and how long each version is supported.
Last updated: 2026-09-30 · Version 1.0
SyncTide monitors water, energy and industrial installations, so we treat its security as part of our customers' operations. This page is our coordinated vulnerability disclosure policy and our statement of support under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Email [email protected]. Please do not report security issues in public channels. Include, if you can:
Machine-readable contact details are in /.well-known/security.txt.
Actively exploited vulnerabilities and severe incidents are reported to the Portuguese national CSIRT (CERT.PT) and to ENISA within the deadlines of Article 14 of the Cyber Resilience Act.
Security updates for SyncTide 1.x are provided until at least 31 December 2031, for the latest release of the 1.x line. Updates are delivered as signed packages; customers should stay on the latest release. The end of the support period will be announced at least 12 months in advance.
Security fixes are described in the release notes of the version that contains them, with the affected versions and the recommended action. A software bill of materials (CycloneDX) accompanies each release and is available to customers on request.
In scope: the SyncTide backend and API, web interface, data-collection
and protocol workers, updater, Windows installer, Docker images, and the
hosted service at *.synctide.app. Out of scope: denial of
service by volume, social engineering, physical access, issues in
third-party components with no impact on SyncTide, and installations
configured against the documented hardening guidance. Do not access or
modify customer data beyond what is needed to demonstrate an issue; for
the hosted service, use only an instance you are entitled to use.
We will not pursue legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us reasonable time to fix an issue before disclosing it.