Product security · Coordinated disclosure

Found a flaw in the HAI-P200? Write to us.

A single point of contact, a human reply, and no legal action against anyone who reports a problem in good faith. That is our coordinated disclosure policy — and it is also what the EU Cyber Resilience Act expects from a manufacturer.

securite@hexa-ai.fr → +33 6 66 74 04 58

or copy the address: securite@hexa-ai.fr

Subject line: [SECURITY]

What a useful report contains

The more precise the report, the faster the fix. The useful minimum:

The product and its version

Enclosure reference, HAI-OS version (the “Update System Manager” page), and the add-on involved where relevant.

How to reproduce

The steps, the minimal request or script, the network setup used. A screenshot or a trace file helps a lot.

The impact you see

What an attacker would gain: data disclosure, authentication bypass, code execution, denial of service…

How to credit you

The name or handle you want credited in the fix — or your preference to stay anonymous.

In scope

  • The HAI-P200-4G gateway and HAI-OS (web interface, acquisition services, notifications, VPN, networking)
  • Our sites hexa-ai.fr, edge.hexa-ai.fr and codesys.hexa-ai.fr
  • The packages and images we distribute, including our Node-RED nodes

What we ask of you

  • Test on your own hardware only: a live installation is an industrial site, not a lab.
  • No exploitation beyond proof, no access to third-party data, no denial of service, no social engineering.
  • Keep the report confidential until the fix ships.

On those terms we treat your work as legitimate research and will take no action against you. We run no bounty programme — but we are grateful, and we say so publicly.

Regulatory context

Cyber Resilience Act: what we must do, and what it changes for you

Regulation (EU) 2024/2847, the Cyber Resilience Act, places cybersecurity obligations on manufacturers of products with digital elements — an industrial gateway is one of them. It applies in stages:

From 11 September 2026

Every manufacturer must report to ENISA and the national CSIRT any actively exploited vulnerability or severe incident affecting the security of its product: early warning within 24 h, notification within 72 h, then a final report — within 14 days of a fix becoming available for a vulnerability, within one month of the notification for a severe incident. In France reporting is centralised through CERT-FR.

From 11 December 2027

The full set of obligations applies to products placed on the market from that date: essential security requirements, technical documentation, vulnerability handling over the support period, and CE marking.

What it changes for you

The reporting duty sits with the manufacturer, not the operator. You have nothing to notify for a gateway you use — that is our job. Yours is to apply the updates we publish.

This page describes how we receive and handle reports. It does not replace our contractual terms and is not a legal interpretation of the regulation: for the official reading in France, refer to ANSSI's publications.

Not a flaw, just a bug?

Use support: it is tracked and it lands directly with the team building the product. The security channel is reserved for issues with a security impact.

Open a support ticket Read the documentation