Cyber Resilience Act & Software Supply Chain Security

CRA & SBOM Validation: Security, Transparency and Guaranteed Lifecycle

AIDOCS Enterprise incorporates Security-by-Design principles, machine-readable Software Bill of Materials (SBOM), containerized network isolation, and early compliance with the EU Cyber Resilience Act (Regulation EU 2024/2847).

European Regulatory Framework

Cyber Resilience Act & Software Bill of Materials (SBOM)

The European Union has established a unified cybersecurity baseline for enterprise software. Under Regulation (UE) 2024/2847, digital resilience and supply chain transparency are mandatory requirements throughout the entire product lifecycle.

Regulation EU 2024/2847 (CRA)

The Cyber Resilience Act mandates essential cybersecurity standards, Security-by-Design, coordinated vulnerability handling, and ongoing security patching across all digital products in the EU single market.

View Regulation (EU) 2024/2847 on EUR-Lex →

Timeline, ENISA & CSIRT

Entering into force in 2024, the CRA mandates 24-hour reporting for actively exploited vulnerabilities to ENISA and CSIRTs by 2026, with full CE compliance and essential requirements becoming enforceable by 2027.

ENISA CRA Guidelines →

Official Regulatory & Institutional References

NIS 2 Directive (Digital Supply Chain Security):
Directive (EU) 2022/2555 (NIS 2)
EU AI Act (AI Governance & Resilience):
Regulation (EU) 2024/1689 (EU AI Act)

Security Architecture

Intended Security Environment and Product Identification

AIDOCS Enterprise is engineered for high confidentiality and secure local execution within customer on-premise servers and dedicated private cloud clusters.

Official Identification

Product & Manufacturer

Official registry data and formal security channels for AIDOCS Enterprise.

  • Product: AIDOCS Enterprise
  • Manufacturer: OFFICINA TECNOLOGICA SRL
  • Official Website: https://officinatecnologica.com/
  • General Inquiries: info@officinatecnologica.com
  • Security & Vulnerability Point: security@officinatecnologica.com

Intended Security Environment

Isolation & Access Control

Hardened architectural defenses preventing unauthorized exposure.

  • Network Isolation: Internal processing services (PostgreSQL, Redis, Qdrant, MinIO, workers, Python backend) remain isolated inside the aidocs-network Docker bridge with no public exposure.
  • TLS Termination: Frontend interfaces and API endpoints are terminated behind an enterprise reverse proxy (Nginx, Traefik, Caddy, Ingress) with up-to-date TLS/HTTPS encryption.
  • Access Control & RBAC: Strong JWT authentication combined with granular Role-Based Access Control enforcing strict separation of duties.

Support Period & Distribution

Security Lifecycle and Update Verification

Officina Tecnologica ensures deterministic, non-destructive, and cryptographically verified updates, guaranteeing long-term maintenance in alignment with CRA standards.

5-Year Support Period

AIDOCS Enterprise adopts a nominal 5-year Security Support Period for continuous CVE vulnerability monitoring and prompt patch delivery.

Continuous CVE Monitoring

Structured processes for early detection of vulnerabilities and continuous integration of corrective security patches and mitigations.

SHA-256 Checksum Validation

Each release package (aidocs-update.tar.gz) includes an SHA-256 checksum allowing IT admins to verify file integrity deterministically (sha256sum -c aidocs-update.tar.gz.sha256).

Zero Telemetry & Air-Gapped

Zero telemetry collection and zero mandatory outbound connections: updates run smoothly in isolated, offline, or heavily firewalled enterprise environments.

Deterministic Deployment

Update packages include deterministic database migration scripts designed to protect existing knowledge bases without risking data loss.

Independent Product Support

Product security lifecycle guarantees remain independent from any optional commercial helpdesk or professional service contracts.

Vulnerability Management

Coordinated Vulnerability Disclosure & Security Advisories

Officina Tecnologica follows structured Coordinated Vulnerability Disclosure (CVD) workflows to rapidly address emerging threats and inform customers.

Advisory Notifications

Formal Security Advisories

Whenever a security patch or mitigation is published, Officina Tecnologica releases a formal Security Advisory.

  • Comprehensive technical summary of the affected component;
  • Impacted AIDOCS release versions and commit hashes;
  • Standardized CVSS severity rating and exploitability assessment;
  • Step-by-step instructions for deploying mitigations or updates.

Single Point of Contact

Vulnerability Reporting

Any suspected security weakness, defect, or unexpected runtime anomaly can be reported directly to:

security@officinatecnologica.com

  • Active AIDOCS version and commit hash (from Settings → Security Information);
  • Detailed reproduction steps or technical defect description;
  • Sanitized logs and configuration samples (excluding passwords and personal data).

Frequently Asked Questions

Questions & Answers on CRA, SBOM and AIDOCS Security

Guidance for CISOs, IT Security Managers, and Compliance Officers on enterprise AI compliance and security architecture.

What is the Cyber Resilience Act (CRA) and why does it matter for AIDOCS?

The EU Cyber Resilience Act (Regulation EU 2024/2847) establishes mandatory cybersecurity and Security-by-Design requirements for all products with digital elements. For AIDOCS Enterprise, it guarantees high resilience standards, transparent software supply chains, continuous vulnerability handling, and guaranteed long-term security support.

What is a Software Bill of Materials (SBOM)?

An SBOM is a formal, machine-readable inventory of all software components, third-party libraries, and open-source modules utilized within an application. It allows enterprise security teams to track CVE vulnerabilities instantly and audit the software supply chain.

What is the duration of the Security Support Period for AIDOCS Enterprise?

AIDOCS Enterprise adopts a nominal 5-year Support Period for continuous vulnerability monitoring and prompt security patching.

Can AIDOCS operate in fully air-gapped or isolated environments?

Yes. AIDOCS Enterprise is architected for isolated on-premise and private cloud infrastructures. The platform and its deployment scripts do not transmit telemetry and require no outbound Internet connection.

How is the integrity of update packages verified?

Every update archive (aidocs-update.tar.gz) is distributed alongside its SHA-256 cryptographic checksum (.sha256). System administrators can deterministically verify package integrity prior to deployment using standard sha256sum tooling.

How can we report a potential vulnerability or request a Security Advisory?

Officina Tecnologica provides a single point of contact for security: security@officinatecnologica.com. In the event of recommended mitigations or patches, a formal Security Advisory is issued outlining severity metrics and implementation steps.