Delta IBT (Europe) Product Security Policy

Scope of Policy

This policy applies to all aspects of Delta IBT (Europe) products under the LOYTEC brand, including the development, deployment, and maintenance of our building automation devices and management systems. It covers the security of our products, the protection of building data, and the protocols for responding to security incidents.

Our security objectives are:

  • Protection of the confidentiality, integrity, and availability of our products and services.
  • Ensuring the privacy and security of our customers’ data.
  • Compliance with relevant legal and regulatory requirements.

Product and Service Security

Delta IBT (Europe) products and services employ various security technologies and practices to safeguard our products, including:

  • Encryption: We use robust encryption standards to protect data in transit and at rest.
  • Authentication: Multi-factor authentication is available on the BMS system to ensure that only authorized users can access sensitive systems.
  • Access Control: Access control mechanisms are in place to restrict access to critical functions and data based on user roles.
  • Security Testing: Regular security testing and vulnerability assessments are conducted to identify and mitigate potential threats. Standard automatic security tests are conducted during testing and the release process.
  • Common Vulnerability Scoring System (CVSS v4.0): We use CVSS scores to categorize the severity of vulnerabilities identified during security assessments

CVSS Score

9.0 – 10.0

7.0 – 8.9

4.0 – 6.9

0.1 – 3.9

Category

Critical

High

Medium

Low

Detailed information about product security and secure device configuration can be found in the LOYTEC Security Hardening Guide.

Secure Software Lifecycle

Delta IBT (Europe) develops software in a secure environment based on cybersecurity standards. These include:

  • ISO 27001 (Information security, cybersecurity and privacy protection)
  • IEC 62443-3-3 (System security requirements and security levels)
  • IEC 62443-4-1 (Secure product development lifecycle requirements)
  • IEC 62443-4-2 (Technical security requirements for IACS components)
  • EN 18031 (Common security requirements for radio equipment Internet connected radio equipment)

Delta IBT (Europe) is planning for external certifications on those standards in 2027.

Vulnerability Reporting

Delta IBT (Europe) offers the following responsible vulnerability reporting process. We encourage our users and third parties to report vulnerabilities found in our products and services. We accept findings following common responsible disclosure processes via This email address is being protected from spambots. You need JavaScript enabled to view it..

Please provide the following information to help us to reply quickly:

  • Software/Firmware title
  • Version
  • Hardware model and serial number (if applicable)
  • Any description, logs, backups, sample exploits, packet traces, that help us understand your report
  • Whether and how we can contact you for further information
  • Whether you want to be recognized in the final report (opt-in)

The better we understand the findings, the better and faster we can react.

Our approach to handling vulnerabilities is as follows:

  1. Receiving your report via This email address is being protected from spambots. You need JavaScript enabled to view it.: We will assign a member of the security team to handle the request. You will receive confirmation as soon as possible.
  2. Verification: We will verify the vulnerability based on the data you provided to us. You will be informed of the verification result.
  3. Identification and classification: We will evaluate the CVSS score to determine the severity and impact of vulnerability. The reporter will be informed of the result of the analysis. Based on the CVSS score, the following measures will be taken:
    1. Critical/High: A release resolving the vulnerability will be scheduled as quickly as possible. We aim for a resolution within 96 hours. In case that target cannot be met, the reporter will be notified on the schedule on a regular basis.
    2. Medium: A release resolving the vulnerability will be scheduled for 30 workdays in advance.
    3. Low: A fix will be contained in the next regular release.
      Actively exploited vulnerabilities: Independently of the CVSS score, a vulnerability for which there is reliable evidence of active exploitation is handled with the highest priority. A release resolving it will be scheduled as quickly as possible, and we aim for a resolution within 96 hours. Where a corrective update cannot be made available within that time, we publish mitigating measures that reduce or remove exploitability until the update is released. Our regulatory reporting obligations also apply, as described under Regulatory Reporting below.
  4. Publishing: When a security-related release is published, the vulnerability will be disclosed on this web page, including its description, the reporter (opt-in), and possible mitigations for those users who cannot update immediately.
  5. Notification: Subscribers to the Delta IBT (Europe) security mailing list will be informed.

Regulatory Reporting

As the manufacturer of LOYTEC-brand products, Delta Intelligent Building Technologies (Europe) GmbH is subject to the reporting obligations of Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 14, which apply from 11 September 2026.

These obligations arise regardless of how we become aware of an event, whether through a report from a third party, our own monitoring and testing, a customer notification, or an advisory concerning a component we ship.

We report two categories of event to the coordinating CSIRT and to ENISA:

  • Actively exploited vulnerabilities: a vulnerability in one of our products for which there is reliable evidence that it is being exploited by a malicious actor.
  • Severe incidents having an impact on product security: an event that severely affects the availability, authenticity, integrity or confidentiality of one of our products, or of a service integral to its operation. This includes compromise of our firmware signing or software update infrastructure, and attacks on our backend services that degrade the security of deployed products.

For either category we will:

  • Submit an early warning under Article 14(2)(a) within 24 hours of becoming aware of it.
  • Submit a notification under Article 14(2)(b) within 72 hours of becoming aware of it, including any mitigating measures available to users at that time.
  • Submit a final report under Article 14(2)(c). For a vulnerability, this is submitted within 14 days after a corrective or mitigating measure becomes available. For a severe incident, it is submitted within one month of the notification.

Where users are affected, we inform them of the vulnerability or incident and of the corrective or mitigating measures they should apply. A corresponding public advisory is published on this page.

Regulatory notification precedes public disclosure. Where the coordinating CSIRT requests that technical details be withheld, or where publication would create a disproportionate security risk, we may delay publication of specific details.

Review and Updates

This policy is reviewed annually and updated as necessary to ensure its continued relevance and effectiveness in addressing new security challenges.

Security Advisory Communication

Delta IBT (Europe) maintains a public list of all published security advisories at Product Security Advisories. Customers can also choose to receive advisories by email: when registering for the Delta IBT (Europe) mailing list, select the security advisories option to opt in. Opted-in subscribers will be notified as soon as a new advisory is published.

Contact Information

If you have any questions or concerns regarding this security policy, please contact our security team at:

  • Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

For confidential transmissions please encrypt data using the following PGP public key

PGP Public Key

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQGNBGp55qkBDADQrqJ0N9PTL3Vx/HoB5IuHcMqv37DLunTVeLFZkq19LdEOFFa3
3YxQSJzttIjcGBPqIqspdGKCP1jLen4z3mQqWBZzdlAUqbFvmXbtpDai45ZuHndY
W1+ZZjxmDafsh2DOaggVUnq0uMq4xjb3ZK24BRDRcVE9K6Mj5WbqEDjoj8U1/w+I
37KVZkzjpQkq7hI146ZDBYByaqL3FUod8WkCQ+j5T76+7liZvT6g2wZNDDCvp+dv
XzBUMBFR46OoP3SCgHbbOcyjQ53qRXTiuptc0SSRXFY/kH/kravfzzEALoq9k0AR
UTODDdY+gUO/LsdOP8CmEenzjGaKvF1L4kB94nmwcJs8zC6heEg1tI60uo3q7wo5
7kaXk53blEpqTMa5KfQjUsE4qzJLesYOB/W/o8pUCVQ2bRMgO3BkCFmvacGAtEVK
ojQEbiXVB9Soir3UlQthZHlJZscnEis7/lPg4qGH1w8h6C3AQZmMany69hrrrLzv
tR+RmwxwXg9YcE0AEQEAAbQtTE9ZVEVDIFNlY3VyaXR5IDxsb3l0ZWMuc2VjdXJp
dHlAZGVsdGF3dy5jb20+iQHUBBMBCgA+FiEE84wSPriSC5qIEHYCqkXnZSvAcxgF
Amp55qkCGwMFCQPCZwAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQqkXnZSvA
cxhyPwv/VcMTvmnisXqy0TPUP2Flo3SaDv7X4YAW+aokEDS9qB79K2ZdZfUQVjAN
+fzw6eSk/EC19q/a8BjyyPcXlvPTfTjBy7qltYlnhy0HPpdJjtGOiIMHaOfgVsWM
NFvCo7IE/0DeG79Qp+qwM09hbznH2Hw8s3lrv8FdaGODxUJRYaRn2gGs13N1Clmx
XoO+D7E3Q9ByyzgTfIv7I9Ga1PXYzBaDLEmtr2yBjeYV/Ize1QGbwBEpjdjNmjbx
5cnQwgYy/wilV1nFYFtVRIgj+e0eLrQqaM5Pfw6A13e/HwMPiHGmk/QNPwJu9S8j
k3HkLMdYQ+HJ2xc//HQWK48EQAMplCQ6uodU2fS0ZOFevkRHWYaDqIilRmWaSdAU
mh6m2hfTb9xc2P7zYnt0BmGDIMYwAbFr87wVnwvnNYYSHkpzHyq3/YjUlJVP+UmC
mLip4ZWSZZAmvHUS7vi+oMsfzrhonICs4dOAg4ZqhjLOD/AHwfSB+q00RDvIAXdz
EsT1JHh3uQGNBGp55qkBDACyrbKKRZG7uncDF0FJW8w5kaG+af5y5rZapk4iVgtD
nZw1HvAvwasHMpLMjwEF1ff4uSWuC6Ix6yODYxgyoDnJiYZPUeiVhDd3qGP2HWU2
vXx2zuNXs8mUPTXOhgq1q83pRd+v2Az1fzmmT6VR/YQroHSTvMzVsfZWQwJ6IocV
YJkHScKIJXr7QKCMXReGAda0DKgqRwfv7Fk5ClS2c7ftOV2uNEizYQRdw3ynYp++
AkHqWSXn0wY43elKAZtfm6qFeEQRc/RQhUQ0zv1GlVIDtCWr8bg3s0yVNR+yOhUg
v4vVgeil+X9HOuNP6lgMcUK3ALH/ushlNYM1AoKOwZPlQN7PDzitGG23Znavr4Do
0kHDeCzKXPCxYqRiYkRgSbsWrvuo7mcEY5fKIT25jOLtEfy/16XJi/9xqHCn9Rkh
B9o0jvmlp5UUboc8MiN/PaGUcOPVBRDa1A/mZ8+IGj2CjzqmZiU8MjCG0YqdsD2W
gevhdH6VsuKciCj7q1oBGyMAEQEAAYkBvAQYAQoAJhYhBPOMEj64kguaiBB2AqpF
52UrwHMYBQJqeeapAhsMBQkDwmcAAAoJEKpF52UrwHMYIJgMALyC8OKR3kwL3YO6
BtFWlDlOceRvtNm7oan2KIW8efIYruDD1mfTMReFe4rGLyoBYoCVA/SNIRf4kNPw
GiNFDtU0IKk+lfN/1e84amaRPt4sTwzB+woJz/pP+JCu4WOwZkbOvUHGzEQV/53S
+yUTbYzXOxLOklBbzPshqHJYckCvOaFsoZ5F8yL1EPHwxlSZewkiEi/AWpbD8HQz
DbkdyQKudSWCMG/p6fyOJtxDh81iFDBP7SLiu+O8XgQ6D3IWufV5Z8aKaCAnw7ct
FpGgkLvluyxguXFUuHAv48Ay6UoEAsI+tMi4DGj0hfeY1W4GxMpEvrjEbit4kk/f
FlPiTlC405o06XLoHchSVt2y0/tOm29uB7hMmie9PKa8g+2bpmbbLP05kbuOsGnI
r/6nxKdsNPVYP+1sdWqd333SYGYEOUkisyAA69GxtAAa2Tt2m4Mc23oZEfEBgM8v
Uh3mVjmnLQ+lAiYX/lnX9ijhyckYQNVjLzJjRBfSuqJOMj7H1A==
=ymRt
-----END PGP PUBLIC KEY BLOCK-----

Document Information

 Doc.-Nr.  71051703
 Version  1.2
 Date  2026-09-09

 

History

 Version Changes
1.2 Updated for regulatory reporting
1.1.1 Corrections only, no scope changes
 1.1

Corrected standard names
Added Cyber Resilience Act, Article 14 documentation

 1.0 Initial Version