Soljacast
/

Security Policy

Last updated: August 2026

Solja Tech S.L. takes the security of SoljaCast OS and the devices that run it seriously. This policy supports our obligations under the Radio Equipment Directive (2014/53/EU, Art. 3.3(d) and 3.3(e)) and the vulnerability-handling expectations of the EU Cyber Resilience Act. The machine-readable version is at /.well-known/security.txt.

1. Reporting a vulnerability

Email security@soljacast.com with:

  • a description of the issue and its impact,
  • steps to reproduce (a proof of concept if you have one),
  • the affected software version(s) and device type (SC1L, SC1P, SC1B, TRV1-8, TRV1-16).

Please do not open a public issue for security reports, and give us reasonable time to fix the problem before any public disclosure. Encrypt sensitive reports with our PGP key: /pgp-key.txt — fingerprint 35FB 9408 1654 543D 6903 FBD6 1A28 04C8 C604 93DB (valid until 22 August 2028).

2. Scope

In scope: the SoljaCast OS image, the device backend and web interface, the update and enrolment mechanisms, and the cloud enrolment and heartbeat interface.

Out of scope: findings that require physical disassembly beyond normal use, social engineering of our staff, and volumetric denial-of-service.

3. Supported versions

The current release train is supported. Before reporting against older firmware, update the device via Manage → Settings → System → Check Updates.

Security updates are provided for at least 3 years after the last unit of a product type is sold. Fixes ship in the monthly release train, or out of band for critical issues, and are flagged as security updates in the device interface.

4. Contact

Solja Tech S.L., Carrer de Tamarit 155 Bis, esc. D, 3º, pta. 2, 08015 Barcelona, Spain. Company details are in our legal notice; how we handle personal data is in our privacy policy.