VENTEX CONNECT / PRODUCT SECURITYPUBLIC CONTROL RECORD · 2026-09-06

Support boundaries are part of the product.

This page connects product state, the security-update path, support boundaries, vulnerability handling and regulatory preparation. It publishes only what is genuinely committed today—and what deliberately remains open.

01 / RELEASE STATE

What “Controlled Production Release” actually means.

01 / AVAILABLE

A genuinely deployed product state

Core communication, device, cryptographic and operating workflows are deployed in production and bounded through the published release and evidence path.

02 / CONTROLLED

Not an anonymous mass rollout

Access, operating context, deployment and responsibilities are reviewed before use. The status is not an open self-service release.

03 / PRE-GA

General availability remains a separate gate

Broad availability, general support commitments and standardised commercial terms are not automatically part of this product state.

04 / ASSURANCE

No certification by wording

Controlled Production Release does not mean an independent security audit, certification, regulatory approval or approval for classified information.

02 / SUPPORT LIFECYCLE

The current public support framework.

No implied lifetime promises: version, update path and ownership must be reviewable for every deployment.

  1. SUP-01

    Current release line

    The current deployed state is identified through the Release Centre, signed runtime manifest and dated product evidence. Public website releases remain separate from product versions.

    ACTIVE
  2. SUP-02

    Security updates

    Security-relevant changes pass through the controlled build, test, release and rollback path. Specific timelines are committed only contractually or in a published advisory.

    CONTROLLED
  3. SUP-03

    Previous versions

    VENTEX currently publishes no blanket multi-version or long-term-support commitment. The applicable update path is agreed before deployment.

    NO BLANKET COMMITMENT
  4. SUP-04

    End of support

    A general EOL calendar has not yet been published. Organisation-specific lifetime, migration and support commitments require an explicit agreement.

    OPEN BEFORE GA
03 / VULNERABILITY RESPONSE

From report to reviewable update.

  1. 01

    Report

    Observations enter triage through the published responsible-disclosure channel with the minimum necessary data.

  2. 02

    Triage

    Scope, reproducibility, impact, affected version and remaining uncertainty are assessed separately.

  3. 03

    Remediate and verify

    Remediation, negative tests, regression, migration impact and rollback together form the release gate.

  4. 04

    Publish in coordination

    Where public notice is required, the advisory connects impact, affected versions and remediation without overstated security guarantees.

04 / REGULATORY READINESS

Preparation without pre-empting conformity.

The Cyber Resilience Act turns product security, vulnerability handling and update ownership into an ongoing product process. This public record is neither a declaration of conformity nor legal advice.

PUBLICLY IMPLEMENTED TODAY
  • Public responsible-disclosure policy and security.txt
  • Dated claim ledger and explicit security boundaries
  • Release Centre and signed runtime manifest
  • Public status API with an explicit measurement boundary
  • Machine-readable security-advisory register
  • Hybrid PQXDH session establishment with ML-KEM-1024 for capable devices in the controlled version-3 rollout
  • Controlled disclosure of detailed protocol and implementation material for expressly agreed confidential reviews or audits
OPEN GATES
  • Formally reviewed SBOM generation and release process
  • Generally published support lifetime and EOL policy
  • Independent external product and cryptography review
  • External multi-region end-to-end monitoring
  • Formal conformity assessment where applicable
05 / PROCUREMENT

Review the concrete operating context.

Public material enables preliminary review. Architecture, privacy, contract terms and support commitments must then be assessed for the individual organisation.

Procurement Room Request security review