SV_REMOTE / SECURITY
Security, retention and vulnerability disclosure
Technical pilot boundaries, recipients, deletion limits and a coordinated security-reporting process.
Version 2026-08-23-pilot · 23.08.2026
Security model
Devices generate Ed25519 keys locally; registration and heartbeat are signed. Pairing uses a five-minute one-time code. A session requires local approval and the OS capture dialog. Frames are E2E encrypted with an ephemeral session key.
Relay/control plane sees necessary routing, time, size and metadata but is not given the content key. The pilot has no remote input, clipboard, files, recording or unattended access.
Recipients and retention
Contabo GmbH provides isolated VPS/network/storage infrastructure in Germany. Carriers and customer networks transport IP metadata and encrypted packets. No advertising or behavioral analytics is used.
Code hash: five-minute validity plus purge in about 24 hours; request: 120 seconds; ticket/relay: at most 15 minutes; Redis short-lived; session metadata, source IP and audit: up to 180 days; device/tree until deletion/end; backup residue targeted at no more than 30 additional days.
Report a vulnerability
Email s@st-in.eu with subject [sv_remote security], affected version, impact and safe reproduction in an owned expressly authorized test system. Do not send keys, credentials, personal screen content or exploit dumps in the first message.
Social engineering, DoS, mass scanning, persistence, malware, third-party access, testing other st-in.eu services and premature disclosure are prohibited. No bounty is promised. Complete reports are targeted for acknowledgement within five business days; this is not an SLA.
CRA readiness
sv_remote is expected to be a product with digital elements; remote-support software is not expressly listed as an important class in CRA Annex III. The preliminary default classification must be confirmed before market placement.
The pilot is not an EU declaration of conformity and makes no CE claim. Before commercial EU launch, the risk file, SBOM, vulnerability lifecycle, authenticated updates, support end date, incident reporting, technical documentation and applicable conformity assessment must be completed.