Appearance
OEM supplier information #
Use this page when Dataplicity is a software component in a connected Linux product you place on the EU market. It summarises what Dataplicity publishes for supplier due diligence. It is not a contractual security assurance, warranty, or claim that your finished product is CRA-conformant.
Dataplicity intends to meet applicable EU Cyber Resilience Act expectations for the device agent and the remote processing the agent needs to function.
What OEMs usually ask for #
| Ask | Where to get it |
|---|---|
| Agent SBOM | CycloneDX JSON (dataplicity-agent-<version>.cdx.json) on the matching tagged release in the public agent releases repository |
| Vulnerability reporting and handling | This page; email support@dataplicity.com with subject Security vulnerability |
| Security update policy | Summary below (kept in sync with the agent repository update policy) |
| Device privilege / trust model | Modern agent security and Trust on someone else's network |
| Platform controls / certification status | Security and compliance |
Prefer release assets that match the exact agent version baked into your image or factory process.
If your organisation requires signed contractual commitments beyond these published materials, confirm those separately. Dataplicity is not offering contractual security assurances through this page.
Agent software bill of materials #
For each tagged agent release, Dataplicity generates a CycloneDX SBOM from an isolated install of that release's declared dependencies and publishes it with the install packages (filename pattern dataplicity-agent-<version>.cdx.json).
Use the SBOM that matches the exact agent version you ship. Do not reuse an older SBOM after upgrading the agent in an image.
Vulnerability handling #
- Report suspected agent or platform vulnerabilities to support@dataplicity.com with subject
Security vulnerability. - Do not open a public issue for unfixed vulnerabilities.
- Dataplicity aims to acknowledge reports within two business days and to coordinate disclosure while assessing and remediating.
- Actively exploited vulnerabilities and severe incidents are handled through Dataplicity's incident process, including any mandatory authority notifications that apply.
Security updates #
- Current tagged agent release lines are the default priority for security fixes.
- Deliver updates through published install packages, or through your signed RAUC / image path when the agent is baked into the rootfs.
- Until a longer support window is published for a major line, treat the current tagged line as supported and plan image refreshes accordingly.
- Platform-side fixes for services the agent depends on are deployed by Dataplicity; they are not shipped as agent package files.
- On RAUC image-managed fleets, ship agent fixes in the next signed image; bootstrap package install remains recovery-only.
Scope reminder for your technical file #
| Component | Typical CRA relevance for OEMs |
|---|---|
| Dataplicity agent on the device | Software component / PDE you integrate; include version, SBOM, and update path |
| Dataplicity cloud services required for agent functions | Remote data processing associated with the agent product; cite this supplier pack and Dataplicity security docs |
| Your product application, image, bootloader, and hardware | Your manufacturer obligations for the finished product |
Dataplicity documentation does not replace your product cybersecurity risk assessment, conformity assessment, CE marking, or support-period declaration for the finished device.