security@pseven.io - vulnerability reports and product-security questions, for all pSeven products. For general technical support, use support@pseven.io. The machine-readable pointer for security researchers is at https://www.pseven.io/.well-known/security.txt (RFC 9116, the standard location where automated tools and researchers look for a security contact).
If you believe you have found a security vulnerability in a pSeven product - pSeven Desktop or pSeven Enterprise - report it to security@pseven.io. Reports concerning our website or infrastructure are welcome at the same address. Please include the product and version, a description of the issue and, where possible, steps to reproduce it.
What we commit to. We acknowledge your report within five business days. We then remediate without undue delay - the fix is shipped, a mitigation is applied and published, or we document why the finding does not affect the products - and keep you informed until the case is closed.
Good faith. We will not initiate legal action against anyone who discovers and reports a vulnerability in good faith - without exploiting it beyond what is needed to demonstrate the issue, without compromising data or disrupting service for others, and without demanding payment for the report. We do not operate a bug bounty program; we gladly credit reporters.
Coordinated disclosure. We ask that you do not publish details of the vulnerability before a fix or mitigation is available. We agree the disclosure timing with you and credit you in the security advisory, if you wish to be credited.
For every vulnerability we fix, we publish a security advisory once the fix is available: the affected products and versions, the severity as a CVSS score (Common Vulnerability Scoring System, the industry 0-10 severity scale), the release that fixes it, and a workaround where one exists. We do not publish exploitation details, and we defer publication where it would put deployed installations at risk, as the Regulation allows. The advisories themselves are listed in the Security advisories section at the end of this page.
Regulation (EU) 2024/2847 (EUR-Lex)
|
What the CRA asks of us |
CRA deadline |
pSeven |
|---|---|---|
|
Product classification and the conformity assessment route (Module A - self-assessment) |
2027.12.11 |
Established 2026.08, in a CRA readiness assessment with DIGITEMIS |
|
Reporting actively exploited vulnerabilities and severe incidents to CERT-FR and ENISA (Article 14) |
2026.09.11 |
Operational since 2026.09.11 |
|
A published Coordinated Vulnerability Disclosure policy and a reporting contact |
2027.12.11 |
Live with this page- more than a year early |
|
Security advisories for fixed vulnerabilities |
2027.12.11 |
Live with this page |
|
Security by design - the product requirements of Annex I, Part I: secure defaults, authentication and access control, encryption in transit, security logging, isolation of user-supplied scripts, signed installers and controlled distribution |
2027.12.11 |
Reviewed in the 2026 assessment; remaining items in progress, ahead of the deadline |
|
Vulnerability handling -monitoring the components we ship for known vulnerabilities, triage, and remediation free of charge during the support period |
2027.12.11 |
Per-release scanning of product deliverables in place; coverage being extended to all products |
|
A Software Bill of Materials (SBOM) per release, provided on reasoned request |
2027.12.11 |
Available on request |
|
A declared support period of at least five years, and end-of-support dates per version |
2027.12.11 |
Published with this page |
|
User information required by the Regulation (Annex II): instructions for secure installation and operation, and the known circumstances of significant cybersecurity risk |
2027.12.11 |
In progress, ahead of the deadline |
|
Technical documentation - the CRA technical file (Annex VII): the internal conformity evidence we compile and keep for market surveillance authorities. It is not the product manual, the administrator guide, or any documentation shipped to you |
2027.12.11 |
In progress, ahead of the deadline |
|
EU Declaration of Conformity and CE marking |
2027.12.11 |
In progress, ahead of the deadline - the declaration texts are published on this page as previews; signed and CE-marked as soon as issued |
|
Beyond the Regulation - VEX (Vulnerability Exploitability eXchange): machine-readable statements of which scanner findings actually affect the product |
not required by the CRA |
In progress |
|
Beyond the Regulation - security hardening guide, shared responsibility model, disaster recovery guidance |
not required by the CRA |
In progress |
|
Beyond the Regulation - https://www.pseven.io/.well-known/security.txt (RFC 9116) |
not required by the CRA |
Live with this page |
Informational: this table states where we stand against the Regulation's own dates, not a declaration of conformity. Where a row reads "in progress", we are working to be ready before the date in the middle column, not on it.
pSeven Desktop and pSeven Enterprise are products with digital elements under Regulation (EU) 2024/2847 - the EU Cyber Resilience Act (CRA). We are the original manufacturer of pSeven and take full responsibility for its conformity - the security requirements, the incident handling, and the conformity assessment - including for the open-source components our products build upon. Both products fall into the default category: neither the important-products list (Annex III) nor the critical-products list (Annex IV) applies, and none of the Article 2 exclusions apply. Conformity is therefore assessed under Module A (internal control - the Regulation's self-assessment route), as provided for default-category products. This classification was established in a CRA readiness assessment performed in 2026 with DIGITEMIS, a French cybersecurity consultancy. Our home Member State is France; our coordinating CSIRT (national computer security incident response team) is CERT-FR, operated by ANSSI, the French national cybersecurity agency.
When. CRA conformity will be reached ahead of the regulatory deadline of 11 December 2027, as part of a regular pSeven release: the same price, the same licensing, no separate "CRA edition".
Versions you already run. Versions placed on the market (that is, first made available in the EU) before 11 December 2027 fall under the CRA's vulnerability and incident reporting obligations, which we operate from 11 September 2026; the full set of product requirements applies to versions placed on the market after that date. You can keep using your version; security fixes reach you through regular releases, free of charge during the support period.
Support period. Each product release is supported for at least five years from its release date, with security updates provided free of charge during the support period regardless of your maintenance status. End-of-support dates: see Support & Lifecycle below.
Reporting a vulnerability. Use security@pseven.io under our Coordinated Vulnerability Disclosure policy (see Product Security above). We are ready for the notification obligations towards ENISA and CERT-FR that apply from 11 September 2026.
Preview - to be issued and signed at the first CRA-conforming release; not yet a declaration of conformity. Published in advance so you can see exactly what will be signed.
To be signed by Laurent Chec, CEO, at the first CRA-conforming release (place and date to be stated at signature).
Preview - to be issued and signed at the first CRA-conforming release; not yet a declaration of conformity. Published in advance so you can see exactly what will be signed.
To be signed by Laurent Chec, CEO, at the first CRA-conforming release (place and date to be stated at signature).
The CE marking is affixed to pSeven Desktop and pSeven Enterprise under Article 30 of Regulation (EU) 2024/2847. For software, the Regulation permits affixing the CE marking either to the EU Declaration of Conformity or to the website accompanying the product - it is affixed here, on this page accompanying pSeven products, next to the EU Declarations of Conformity above.
For every release of every product we maintain the Software Bill of Materials (SBOM) and the conformity documentation required by the Regulation. Both are provided on reasoned request - to market surveillance authorities, and to customers through their account manager. Deeper due-diligence documentation - the cybersecurity risk assessment, the security architecture description, and test reports - can be shared with customers under a non-disclosure agreement, through the same channel.
Support period. Each pSeven product release is supported for at least five years from its release date - the minimum the EU Cyber Resilience Act requires. During the support period you receive security updates free of charge, regardless of your maintenance status.
The support period is a statutory commitment under the CRA ("support period" is the Regulation's own term, Article 3(20)) and is independent of our commercial Annual Technical Maintenance: security updates are free during the support period whether or not you subscribe to maintenance; maintenance additionally covers technical support services and access to new product versions.
End-of-support dates. The end-of-support date of every released version is published in the product documentation in the section Changelog:
Availability of updates. Every security update we release remains available for at least ten years after its publication. Since a security update of ours is always a release - a patch release or a regular one - this is, in practice, a ten-year retention commitment for our releases.
How security fixes are delivered. Security fixes ship in regular releases. Where upgrading is not practical, we decide case by case whether to issue a patch release for the version you run or to provide a license for the release that carries the fix - free of charge during the support period, on request.
Older versions. Versions past their support period keep working - nothing stops or expires; we simply no longer provide security updates for them. CRA-conforming releases will be available well ahead of the 11 December 2027 deadline, so whenever you choose to upgrade, a conforming version will already be there. One consequence of the Regulation's transitional rules: after 11 December 2027 we will no longer be able to issue or renew term licenses for versions that do not conform to it - supplying such a version anew counts as "making available on the market", which the Regulation reserves for conforming products. Perpetual licenses are unaffected: you keep running what you have. And if you specifically need an older build, the route is a license for the current release with a contractual right to run the older version (a downgrade right) - arranged through your account manager.
Yes. pSeven Desktop and pSeven Enterprise are "products with digital elements" made available on the EU market. They fall into the default category - neither the important-products (Annex III) nor the critical-products (Annex IV) list applies - so conformity is assessed by self-assessment (Module A). See the statement above.
No. Both products are deployed and operated entirely on your own infrastructure; we do not host them or process your data remotely.
Versions placed on the market before 11 December 2027 are covered by the CRA's vulnerability and incident reporting obligations, which we operate from 11 September 2026; the full set of product requirements applies to versions placed on the market after that date. You keep using your version; security fixes come through regular releases. Perpetual licenses are unaffected; for how term licenses on older versions are affected after 11 December 2027, see Support & Lifecycle below.
Ahead of the 11 December 2027 deadline, as a regular release - the same price, the same licensing, no separate "CRA edition".
Email security@pseven.io. Our Coordinated Vulnerability Disclosure policy (above) describes what happens next and what we commit to. The machine-readable pointer is at https://www.pseven.io/.well-known/security.txt.
Every fixed vulnerability is announced as a security advisory on this page: affected products and versions, severity, and the release that fixes it. The product changelog marks security fixes as well.
Each release is supported for at least five years from its release date, and every security update we release remains available for at least ten years. See Support & Lifecycle below for the end-of-support dates.
Yes. We maintain a Software Bill of Materials per release for every product and provide it, together with conformity documentation, on reasoned request through your account manager. Deeper due-diligence documentation - the risk assessment, the security architecture description, test reports - can be shared under a non-disclosure agreement.
CERT-FR (the French national CSIRT, our coordinator) and ENISA, the European Union Agency for Cybersecurity - through the EU Single Reporting Platform, the EU's central portal for vulnerability and incident notifications, within the CRA timelines (24-hour early warning, 72-hour notification, final report). Affected customers are notified in parallel.
The information an integrator needs for its own CRA compliance (Annex II (8)(f)): security properties, the SBOM, and vulnerability coordination. Contact us via your account manager.
No security advisories have been published to date. When one is issued, it will appear here.
|
Advisory |
Published |
Affected products and versions |
Severity (CVSS) |
Fixed in |
Workaround |
|---|---|---|---|---|---|
location_on 17 Av. Didier Daurat, Parc des Algorithmes Immeuble Platon, 31700 Blagnac, France
phone +33 (0) 5 82-95-59-68
mail_outline info@pseven.io
Contact us Resellers navigate_next