Enclustra FPGA Solutions | Security (CRA) | Security

Security (CRA)

Enclustra Coordinated Vulnerability Disclosure (CVD) Policy — v1.0

Aligned with ISO/IEC 29147 and ISO/IEC 30111. Supports Regulation (EU) 2024/2847 (CRA), Annex I Part II(5).

1. Our commitment

Enclustra GmbH develops FPGA and SoC modules, base boards, IP cores, and accompanying software. We take the security of our products seriously and welcome reports from security researchers, customers, and partners. We will not take legal action against anyone who reports a vulnerability to us in good faith and in accordance with this policy (safe harbor, Section 6).

2. Scope

This policy covers security vulnerabilities in:

  • Enclustra hardware products: System-on-Modules and FPGA modules (Mercury, Mercury+, Mars, Andromeda, Pluto families and successors), base boards, design-in kits, and add-on cards
  • Software supplied by Enclustra with these products: Linux BSPs and reference designs (meta-enclustra-amd and related Yocto layers, the Enclustra Build Environment for AMD and Altera devices), U-Boot and Linux forks published under github.com/enclustra and github.com/enclustra-bsp, the Module Configuration Tool, PE3 Configuration Tool, System Controller firmware, Design-in Kit software and firmware, and Enclustra IP cores.

Out of scope:

  • Vulnerabilities in third-party silicon (AMD, Altera, Microchip, SiMa.ai, Effinix, Qualcomm devices): please report these to the respective vendor PSIRT. We gladly coordinate where an Enclustra product is affected
  • The enclustra.com corporate website and Enclustra’s internal IT infrastructure: reports are nevertheless appreciated and will be forwarded to the responsible internal team, but they are handled outside this product-security process
  • Denial-of-service testing against Enclustra infrastructure, social engineering of Enclustra staff, and physical attacks on Enclustra premises.

3. How to report

  • Email: security@enclustra.com
  • Languages: English or German
  • Please include the affected product and hardware revision, software/BSP version or git commit, a description of the issue and its impact, steps to reproduce or a proof of concept, and your contact details.
  • Please do not include confidential third-party data. Reports may be made anonymously; we then cannot provide status updates or credit.

4. What you can expect from us

  • Acknowledgement within 3 business days
  • An initial assessment (accepted / duplicate / out of scope, preliminary severity) within 10 business days
  • A named contact and status updates at least every 30 days while open
  • Remediation of confirmed vulnerabilities without undue delay, including free security updates for supported products throughout their published support period (see the Enclustra Product Security Support Period Policy)
  • A published security advisory (ENCSA series, with CVE IDs where applicable) once a fix or mitigation is available, and credit to the reporter unless anonymity is requested.

5. Coordinated disclosure

Our default coordinated disclosure period is 90 days from acknowledgement, extendable by mutual agreement where a fix requires hardware changes, silicon-vendor coordination, or affects many product variants, and shortened where a vulnerability is actively exploited. Where a vulnerability originates in an upstream component (Linux kernel, U-Boot, Yocto/Buildroot packages) or vendor silicon, we coordinate with the upstream project or vendor and may align our disclosure with theirs.

6. Safe harbor

Enclustra will not initiate legal action or law-enforcement referral for security research and reporting conducted in good faith that respects this policy’s scope, avoids privacy violations, data destruction and service degradation, uses only systems under the researcher’s control, and does not exploit findings beyond what is necessary to demonstrate the issue.

7. Regulatory note

As a manufacturer of products with digital elements placed on the EU market, Enclustra reports actively exploited vulnerabilities and severe incidents to the EU authorities (ENISA and the competent CSIRT) as required by Article 14 of Regulation (EU) 2024/2847. Reporter identities are not disclosed without consent unless required by law.

8. Contact and document control

Enclustra GmbH
Räffelstrasse 28
CH-8045 Zürich, Switzerland
Tel. +41 43 343 39 43
security@enclustra.com