top of page

Corporate Information Security and Coordinated Vulnerability Disclosure Policy

Updated: 20 August 2026

About This Policy

This document sets out two complementary commitments. Part A describes RubyComm's corporate information security governance, operated through an Information Security Management System certified to ISO/IEC 27001:2022. Part B describes RubyComm's product security and Coordinated Vulnerability Disclosure (CVD) practice for the products we manufacture, aligned with the vulnerability handling and reporting framework of the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

The two parts operate at different levels. Part A defines how RubyComm as an organization protects corporate data, including the confidentiality of customer and partner information entrusted to us. Part B defines how we protect the users of our products with digital elements once those products are deployed in the field. Where this policy refers to a product with digital elements, that term carries the meaning given to it in the EU Cyber Resilience Act.

RubyComm is an Israeli operational technology (OT) cybersecurity company. References to EU regulation in this policy reflect our commitment to serve European customers and partners to the standard those markets expect; they do not change the country of origin or establishment of the company. 

PART A: Corporate Information Security Policy

As a service to our external stakeholders, this section provides a general overview of the purpose, direction, principles, and basic rules of our corporate information security management policy. The policy applies to the entire Information Security Management System (ISMS), which is certified to ISO/IEC 27001:2022 and supported by RubyComm's ISO 9001:2015 quality management system. The detailed control set is maintained in RubyComm's internal information security system documentation.

1. Objectives

The purpose of our information security policy is to establish a framework for the protection of the organization's information assets. It is designed to:

  • Protect the organization's information from all threats, whether internal or external, deliberate or accidental.

  • Facilitate secure information sharing between RubyComm and external stakeholders or other third parties.

  • Encourage consistent and professional use of information.

  • Ensure that all employees and third parties understand their roles in using and protecting information.

  • Ensure business continuity and minimize business damage.

  • Protect the organization from legal liability and from the inappropriate use of information.

  • Strive for a continual improvement of our Information Security Management System (ISMS)

2. Roles and Responsibilities

The Chief Information Security Officer (CISO) has overall responsibility for the development, implementation, and ongoing management of RubyComm's corporate information security policy and all associated procedures. The CISO ensures that security controls remain effective, oversees compliance with regulatory standards, and leads the strategic direction for information security throughout the company.

3. Policy Review and Update Frequency

This policy is reviewed and updated whenever significant changes occur within the organization's structure, operations, or applicable regulations, or as necessitated by evolving cyber threats. The CISO is responsible for initiating and overseeing the review process to ensure the policy's ongoing relevance and effectiveness.

4. Ongoing Employee Training

RubyComm provides ongoing security awareness and training programes for all employees to support and maintain compliance with this policy. This includes regular education on current cyber threats, safe information handling, and best practices that foster a culture of security and minimize risk from human error.

5. Communication of Policy Changes

All material changes, upgrades, or incident-driven revisions to this policy are communicated promptly to affected stakeholders, including employees, third parties, and external partners as appropriate. RubyComm disseminates policy updates and key learnings from incidents in a timely manner to foster transparency, awareness, and continued organizational compliance.

For more information regarding our information security system policy, please contact ciso@rubycomm.com.

PART B: Product Security and Coordinated Vulnerability Disclosure Policy

At RubyComm we promote the security of our products through open collaboration with the security community. We welcome and appreciate vulnerability reports, and we value the role that independent security researchers, upstream suppliers, and users play in keeping our products and the wider OT ecosystem safe. This part describes how to report a vulnerability in a RubyComm product, what you can expect from us in return, and how we handle disclosure and patching. Our Product Security Incident Response Team (PSIRT) coordinates this process.

This practice is designed to align with the vulnerability handling and reporting framework of the EU Cyber Resilience Act (CRA). The CRA's mandatory reporting obligations for manufacturers take effect on 11 September 2026; RubyComm is establishing this process in advance of that date so that the capability is operational and proven before the obligation begins.

6. Scope and Covered Products

This part applies to all active RubyComm hardware, software, and associated remote data processing components, including the Rubyk product family. It covers vulnerabilities in the products themselves. Vulnerabilities affecting RubyComm's corporate IT systems fall under Part A and may also be reported through the channel below.

7. Security Support Period

RubyComm defines a Security Support Period for each product with digital elements during which security updates are provided. Unless a longer period is stated for a specific product, the Security Support Period is at least five (5) years from the date the product is first placed on the market, except where the expected in-use lifetime of the product is shorter, in which case the support period corresponds to that lifetime.

8. How to Report a Vulnerability

Designated reporting channel Email: ciso@rubycomm.com 

Postal address: 26 Zarchin Street, Ra'anana, 4366250, Israel 

Anonymous and indirect reporting

If you prefer to remain anonymous, or wish to route your findings through an intermediary, you may submit them to a Computer Security Incident Response Team (CSIRT) designated as a coordinator under the EU framework. The coordinator CSIRT can then notify RubyComm of an actively exploited vulnerability or severe incident while protecting your identity, where anonymity has been requested.

What to include in your report

To help our PSIRT triage the issue quickly, please include where possible:

  • The specific product name, hardware revision, and firmware or software version affected.

  • A clear, concise summary of the vulnerability.

  • Step-by-step instructions to reproduce the issue, with any proof-of-concept code, scripts, or screenshots.

  • Your assessment of the potential risk or impact.

9. Our Commitment to You

When you report a vulnerability to RubyComm, you can expect a structured response:

  • Acknowledgment: we acknowledge receipt of your report within three (3) business days.

  • Status updates: we keep you informed of remediation progress at reasonable intervals, and without undue delay where there is a material development.

  • Resolution: validated vulnerabilities are prioritized for prompt resolution by our engineering and security teams.

  • Recognition: if you wish, we will credit you in our public acknowledgments, unless you request anonymity.

10. Regulatory Reporting under the EU Cyber Resilience Act

Where RubyComm becomes aware that a vulnerability in one of its products is being actively exploited, or of a severe incident affecting the security of one of its products, RubyComm will report through the single reporting platform established under the CRA. The notification is addressed to the relevant CSIRT designated as coordinator, determined in accordance with the CRA, and is made simultaneously accessible to the European Union Agency for Cybersecurity (ENISA). The applicable statutory timelines differ for the two cases, as set out below.​​​​​​​​​​​

Reporting stage
Actively exploited vulnerability
Severe incident affecting product security
Early warning
Within 24 hours of becoming aware
Within 24 hours of becoming aware
Notification
Within 72 hours of becoming aware
Within 72 hours of becoming aware
Final report
No later than 14 days after a corrective or mitigating measure is available
Within one month after submission of the 72-hour incident notification

Routine bugs and ordinary security patches are not in scope of this reporting obligation. A vulnerability that RubyComm discovers and fixes before it is exploited is handled through the normal vulnerability handling process described above, not through this regulatory channel.​​​​​​​

11. Safe Harbor and Rules of Engagement

We appreciate the work of ethical security researchers. RubyComm pledges not to initiate legal or administrative action against researchers who discover weaknesses in our products, provided you act in good faith and adhere to the following principles:

  • Follow the policy: submit your findings to us directly, or through official CSIRT channels, and follow this CVD policy.

  • Do no harm: avoid privacy violations, destruction of data, unauthorized access, and disruption of RubyComm infrastructure or end-user services.

  • Coordinate disclosure: do not publicly disclose technical details of a vulnerability until an official security update is available, or unless an alternative timeline is mutually agreed in writing with the RubyComm PSIRT.

12. Coordinated and Public Disclosure

RubyComm encourages responsible, coordinated disclosure to protect our users and the broader digital ecosystem. We ask that researchers do not publicly disclose the technical details of a vulnerability until an official security update is available, or until a mutually agreed timeline for coordinated disclosure has been reached. Once a corrective measure has been made available, RubyComm is committed to openly sharing clear information about the resolved vulnerability, including its description, severity, impact, and the remediation steps available to users. We respect the security community's timeline expectations and will not pursue legal action against researchers who act in good faith and adhere to these principles.

13. Secure Update and Patch Distribution

As part of our post-market lifecycle commitments, RubyComm provides secure update and patch distribution for its products with digital elements throughout the declared Security Support Period. To ensure the integrity of our fixes and to prevent tampering or interception in transit, firmware modifications and security patches are compiled, digitally signed, and distributed over secured channels in coordination with our partners and customers. When technically feasible, security updates are separated from standard functionality updates, provided free of charge, and may be accompanied by machine-readable advisories to support rapid risk mitigation.

14. Contact

For general security inquiries or to submit a vulnerability report or to request active firmware versions, contact our team at ciso@rubycomm.com

 

Thank you for helping us keep RubyComm products secure.​

bottom of page