Security
Control that stays in the building
The AReCoS controller is designed to make every control decision on the machine it runs, with no command path from the internet. This page sets out how our products are designed to be secure, how they are designed to meet the EU Cyber Resilience Act, and how to report a security flaw to us.
By design
No command path from the internet.
A cloud optimizer commands equipment from outside the building, so whoever breaches that service can command the equipment too. Our design leaves that path out.
- Every command stays local
- The optimizer, and every command to your equipment, is designed to run inside the units: setpoints, starting and stopping, and sharing the load. There is no AReCoS service online that can command your units.
- The cloud only monitors
- A cloud connection is optional, for your visibility and data collection, and monitoring can stay offline at the store or building. Our cloud never sends a command to a unit.
- Signed firmware, installed on site
- Firmware is designed to be updated only on site, never through our cloud, and each controller is designed to install only firmware that AReCoS has signed, after checking that signature itself.
- Working without the internet
- The controller is designed to keep optimizing when the connection is gone, and no site data has to leave the site for it to run.
- The building network
- Your building’s own network still needs protecting. We plan BACnet Secure Connect, which encrypts and authenticates the link between units.
More than a cloud optimizer
Local control is designed to do more, not less.
A cloud optimizer sends setpoints, and start and stop commands, from outside the building. That changes what each controller aims at and when it runs, not how it runs: the compressor, valves, fans and pumps are still driven by separate loops, each tuned on its own, and the optimizing stops when the link drops.
The AReCoS controller is designed to set them together, on the machine and at the machine’s own pace, for the least total power, and to keep doing it with the internet down. How the controller works.
EU Cyber Resilience Act
Designed to meet the Act’s essential requirements.
The EU Cyber Resilience Act, Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements sold in the EU, and applies in full from 11 December 2027. Among them, products are to be designed, developed and produced to limit attack surfaces, including external interfaces
. A controller that takes no command from the internet starts from that principle.
We are designing our controllers and our rooftop heat pump, with their optional cloud monitoring, to meet the Act’s essential cybersecurity requirements. That includes firmware the controller checks for our signature before installing it, the way to report a vulnerability set out below, and ten years of security updates planned for each product.
No AReCoS product has been assessed for conformity with the Act, and none is sold in the EU. Before our first sale there, we will complete that assessment, publish the EU declaration of conformity and state each product’s support period.
Reporting a vulnerability
Found a security flaw? Tell us.
This policy covers AReCoS products and their firmware, our cloud monitoring service and this website.
- How to report
- Email info@arecos.net with Security in the subject line. A person reads every report. If you would like to encrypt yours, say so first and we will arrange a way.
- What to include
- The product and its firmware version, or the web address; what you found and how to reproduce it; what an attacker could do with it; and how to reach you. Send only the data needed to show the flaw.
- What happens next
- We aim to acknowledge your report within three business days, tell you whether we can reproduce the flaw, and keep you updated until it is fixed.
- Disclosure
- Please keep the flaw private until a fix is available. We will agree a date for making it public with you, normally within 90 days of your report. When the fix is released, we publish an advisory that describes the flaw and how to install the fix, and we credit you by name if you wish.
- Please don’t
- Test equipment you do not own or have permission to test, including units at customer sites; run tests that could disrupt a service or stop a machine heating, cooling or refrigerating; try to trick our staff or customers, or get physical access; or access, keep or share more data than you need to show the flaw.
- Good faith
- If you act in good faith and follow this policy, we will treat your research as authorized, will not take or support legal action against you for it, and will say so if anyone asks. That covers research on our products and firmware, including a unit you own, on our cloud monitoring service and on this website. We cannot authorize testing of equipment or systems that belong to someone else, such as a customer’s installed unit.
- Rewards
- We do not run a bug bounty, but we thank everyone who reports a flaw to us.
- In the EU
- Once our products are sold in the EU, we will report any actively exploited vulnerability in them to the authorities, as the Act requires, and tell the users affected.
- Machine-readable
- Our security contact is also published in security.txt, as RFC 9116 describes.
Questions?
Write to us and we will answer.
Grand Rapids, Michigan 49546