Notification of vendor-identified incidents
If we identify a cyber security incident that affects CIP Sentry software, a release, or our build and release systems, we notify affected customers' designated security contacts without undue delay and no later than 72 hours after we confirm it, with what we know, what to do, and when we will update you.
Coordination of incident response
A named security contact (security@cipsentry.com) coordinates with your incident response team, shares indicators and remediation steps, and supports your CIP-008 process. We follow your lead on communications inside your organization.
Notification when vendor access should end
CIP Sentry runs on your servers and we have no standing remote or onsite access to your systems. If you grant temporary access for support, you control it, and we tell you as soon as a named representative no longer needs it (for example, on role change or departure).
Disclosure of known vulnerabilities
We publish a vulnerability disclosure policy, accept reports through security.txt, and notify customers of confirmed vulnerabilities in CIP Sentry with severity, affected versions, fixes and workarounds.
Software integrity and authenticity
Every release is published with SHA-256 hashes, on this site and by email to your designated contact, so you can verify identity and integrity under CIP-010 R1.6. Code-signed installers and signed update packages are on our roadmap.
Coordination of remote access
There is no vendor-initiated remote access. Support sessions are customer-initiated screen shares that you start, supervise and end, under your own remote access controls.