Delta IBT (Europe) Product Security Policy
Scope of Policy
This policy applies to all aspects of Delta IBT (Europe) products under the LOYTEC brand, including the development, deployment, and maintenance of our building automation devices and management systems. It covers the security of our products, the protection of building data, and the protocols for responding to security incidents.
Our security objectives are:
- Protection of the confidentiality, integrity, and availability of our products and services.
- Ensuring the privacy and security of our customers’ data.
- Compliance with relevant legal and regulatory requirements.
Product and Service Security
Delta IBT (Europe) products and services employ various security technologies and practices to safeguard our products, including:
- Encryption: We use robust encryption standards to protect data in transit and at rest.
- Authentication: Multi-factor authentication is available on the BMS system to ensure that only authorized users can access sensitive systems.
- Access Control: Access control mechanisms are in place to restrict access to critical functions and data based on user roles.
- Security Testing: Regular security testing and vulnerability assessments are conducted to identify and mitigate potential threats. Standard automatic security tests are conducted during testing and the release process.
- Common Vulnerability Scoring System (CVSS v4.0): We use CVSS scores to categorize the severity of vulnerabilities identified during security assessments
|
CVSS Score |
9.0 – 10.0 |
7.0 – 8.9 |
4.0 – 6.9 |
0.1 – 3.9 |
|
Category |
Critical |
High |
Medium |
Low |
Detailed information about product security and secure device configuration can be found in the LOYTEC Security Hardening Guide.
Secure Software Lifecycle
Delta IBT (Europe) develops software in a secure environment based on cybersecurity standards. These include:
- ISO 27001 (Information security, cybersecurity and privacy protection)
- IEC 62443-3-3 (System security requirements and security levels)
- IEC 62443-4-1 (Secure product development lifecycle requirements)
- IEC 62443-4-2 (Technical security requirements for IACS components)
- EN 18031 (Common security requirements for radio equipment Internet connected radio equipment)
Delta IBT (Europe) is planning for external certifications on those standards in 2027.
Vulnerability Reporting
Delta IBT (Europe) offers the following responsible vulnerability reporting process. We encourage our users and third parties to report vulnerabilities found in our products and services. We accept findings following common responsible disclosure processes via
Please provide the following information to help us to reply quickly:
- Software/Firmware title
- Version
- Hardware model and serial number (if applicable)
- Any description, logs, backups, sample exploits, packet traces, that help us understand your report
- Whether and how we can contact you for further information
- Whether you want to be recognized in the final report (opt-in)
The better we understand the findings, the better and faster we can react.
Our approach to handling vulnerabilities is as follows:
- Receiving your report via
This email address is being protected from spambots. You need JavaScript enabled to view it. : We will assign a member of the security team to handle the request. You will receive confirmation as soon as possible.
In the case of an actively exploited vulnerability, and in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 14, we will:- Submit an early warning notification under Article 14(2)(a) within 24 hours of becoming aware of it.
- Submit a vulnerability notification under Article 14(2)(b) within 72 hours of becoming aware of it.
- Verification: We will verify the vulnerability based on the data you provided to us. You will be informed of the verification result.
- Identification and classification: We will evaluate the CVSS score to determine the severity and impact of vulnerability. The reporter will be identified on the result of the analysis. Based on the CVSS score, the following measures will be taken:
- Critical/High: A release resolving the vulnerability will be scheduled as quickly as possible. We aim for a resolution within 96 hours. In case that target cannot be met, the reporter will be notified on the schedule on a regular basis.
- Medium: A release resolving the vulnerability will be scheduled for 30 workdays in advance.
- Low: A fix will be contained in the next regular release.
- Publishing: When a security-related release is published, the vulnerability will be disclosed on this web page, including its description, the reporter (opt-in), and possible mitigations for those users who cannot update immediately.
Where Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 14(2)(c) applies, we submit a final report to the coordinating CSIRT and ENISA within 14 days after a corrective or mitigating measure becomes available. A corresponding public advisory is published on this page. - Notification: Subscribers to the Delta IBT (Europe) security mailing list will be informed.
Review and Updates
This policy is reviewed annually and updated as necessary to ensure its continued relevance and effectiveness in addressing new security challenges.
Contact Information
If you have any questions or concerns regarding this security policy, please contact our security team at:
For confidential transmissions please encrypt data using the following PGP public key
PGP Public Key
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGp55qkBDADQrqJ0N9PTL3Vx/HoB5IuHcMqv37DLunTVeLFZkq19LdEOFFa3
3YxQSJzttIjcGBPqIqspdGKCP1jLen4z3mQqWBZzdlAUqbFvmXbtpDai45ZuHndY
W1+ZZjxmDafsh2DOaggVUnq0uMq4xjb3ZK24BRDRcVE9K6Mj5WbqEDjoj8U1/w+I
37KVZkzjpQkq7hI146ZDBYByaqL3FUod8WkCQ+j5T76+7liZvT6g2wZNDDCvp+dv
XzBUMBFR46OoP3SCgHbbOcyjQ53qRXTiuptc0SSRXFY/kH/kravfzzEALoq9k0AR
UTODDdY+gUO/LsdOP8CmEenzjGaKvF1L4kB94nmwcJs8zC6heEg1tI60uo3q7wo5
7kaXk53blEpqTMa5KfQjUsE4qzJLesYOB/W/o8pUCVQ2bRMgO3BkCFmvacGAtEVK
ojQEbiXVB9Soir3UlQthZHlJZscnEis7/lPg4qGH1w8h6C3AQZmMany69hrrrLzv
tR+RmwxwXg9YcE0AEQEAAbQtTE9ZVEVDIFNlY3VyaXR5IDxsb3l0ZWMuc2VjdXJp
dHlAZGVsdGF3dy5jb20+iQHUBBMBCgA+FiEE84wSPriSC5qIEHYCqkXnZSvAcxgF
Amp55qkCGwMFCQPCZwAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQqkXnZSvA
cxhyPwv/VcMTvmnisXqy0TPUP2Flo3SaDv7X4YAW+aokEDS9qB79K2ZdZfUQVjAN
+fzw6eSk/EC19q/a8BjyyPcXlvPTfTjBy7qltYlnhy0HPpdJjtGOiIMHaOfgVsWM
NFvCo7IE/0DeG79Qp+qwM09hbznH2Hw8s3lrv8FdaGODxUJRYaRn2gGs13N1Clmx
XoO+D7E3Q9ByyzgTfIv7I9Ga1PXYzBaDLEmtr2yBjeYV/Ize1QGbwBEpjdjNmjbx
5cnQwgYy/wilV1nFYFtVRIgj+e0eLrQqaM5Pfw6A13e/HwMPiHGmk/QNPwJu9S8j
k3HkLMdYQ+HJ2xc//HQWK48EQAMplCQ6uodU2fS0ZOFevkRHWYaDqIilRmWaSdAU
mh6m2hfTb9xc2P7zYnt0BmGDIMYwAbFr87wVnwvnNYYSHkpzHyq3/YjUlJVP+UmC
mLip4ZWSZZAmvHUS7vi+oMsfzrhonICs4dOAg4ZqhjLOD/AHwfSB+q00RDvIAXdz
EsT1JHh3uQGNBGp55qkBDACyrbKKRZG7uncDF0FJW8w5kaG+af5y5rZapk4iVgtD
nZw1HvAvwasHMpLMjwEF1ff4uSWuC6Ix6yODYxgyoDnJiYZPUeiVhDd3qGP2HWU2
vXx2zuNXs8mUPTXOhgq1q83pRd+v2Az1fzmmT6VR/YQroHSTvMzVsfZWQwJ6IocV
YJkHScKIJXr7QKCMXReGAda0DKgqRwfv7Fk5ClS2c7ftOV2uNEizYQRdw3ynYp++
AkHqWSXn0wY43elKAZtfm6qFeEQRc/RQhUQ0zv1GlVIDtCWr8bg3s0yVNR+yOhUg
v4vVgeil+X9HOuNP6lgMcUK3ALH/ushlNYM1AoKOwZPlQN7PDzitGG23Znavr4Do
0kHDeCzKXPCxYqRiYkRgSbsWrvuo7mcEY5fKIT25jOLtEfy/16XJi/9xqHCn9Rkh
B9o0jvmlp5UUboc8MiN/PaGUcOPVBRDa1A/mZ8+IGj2CjzqmZiU8MjCG0YqdsD2W
gevhdH6VsuKciCj7q1oBGyMAEQEAAYkBvAQYAQoAJhYhBPOMEj64kguaiBB2AqpF
52UrwHMYBQJqeeapAhsMBQkDwmcAAAoJEKpF52UrwHMYIJgMALyC8OKR3kwL3YO6
BtFWlDlOceRvtNm7oan2KIW8efIYruDD1mfTMReFe4rGLyoBYoCVA/SNIRf4kNPw
GiNFDtU0IKk+lfN/1e84amaRPt4sTwzB+woJz/pP+JCu4WOwZkbOvUHGzEQV/53S
+yUTbYzXOxLOklBbzPshqHJYckCvOaFsoZ5F8yL1EPHwxlSZewkiEi/AWpbD8HQz
DbkdyQKudSWCMG/p6fyOJtxDh81iFDBP7SLiu+O8XgQ6D3IWufV5Z8aKaCAnw7ct
FpGgkLvluyxguXFUuHAv48Ay6UoEAsI+tMi4DGj0hfeY1W4GxMpEvrjEbit4kk/f
FlPiTlC405o06XLoHchSVt2y0/tOm29uB7hMmie9PKa8g+2bpmbbLP05kbuOsGnI
r/6nxKdsNPVYP+1sdWqd333SYGYEOUkisyAA69GxtAAa2Tt2m4Mc23oZEfEBgM8v
Uh3mVjmnLQ+lAiYX/lnX9ijhyckYQNVjLzJjRBfSuqJOMj7H1A==
=ymRt
-----END PGP PUBLIC KEY BLOCK-----
Document Information
| Doc.-Nr. | 71051702 |
| Version | 1.1.1 |
| Date | 2026-08-07 |
History
| Version | Changes |
| 1.1.1 | Corrections only, no scope changes |
| 1.1 |
Corrected standard names |
| 1.0 | Initial Version |

