Software updates
To protect your infrastructure against evolving cyber threats, North strongly advises keeping all compatible products updated with the latest software and firmware releases.
In compliance with the UK PSTI and EU Cyber Resilience Act (CRA) regimes, North provides guaranteed minimum periods for critical security updates free of charge across our connected product lines:
- North Commander: All North Commander units receive a minimum support period of at least five years of security updates from your date of purchase. For the latest Version 3 hardware (serial number 80007000 onwards), this guaranteed support lifecycle extends until at least December 2031.
Critical security updates are delivered free of charge. To ensure your Commander is fully protected, please utilize the Cloud Update feature. Refer to the Updating Commander's Firmware section in the Commander Manual. - North ObSys: First released in 1999 and continually developed, ObSys remains a core part of our product line. We guarantee that ObSys will receive critical security updates free of charge until at least December 2029.
Note: North Zip modules and accessories, do not possess network connectivity, cannot receive software updates, and fall outside the scope of connected product security regulations.
Details of specific software versions, firmware releases, and historically resolved vulnerabilities can be found on our release notes page.
Coordinated vulnerability disclosure program
We collaborate openly with security researchers, system integrators, and customers to identify, mitigate, and patch vulnerabilities in line with global standards and EU CRA vulnerability handling rules. If you believe you have discovered a security vulnerability in a North product, please report it to our dedicated monitoring team.
What to include in your report
To help us investigate efficiently, please provide:
- A technical description of the potential vulnerability or concern.
- Details of the environment, tools, or proof-of-concept code used.
- The specific product model, software, or firmware version affected.
- (Optional) Your preferred contact information if you wish to receive status updates.
Our commitment & timelines
- Acknowledgment: We will formally acknowledge receipt of your vulnerability report within 3 business days.
- Status Updates: We will provide progress updates at least once every 14 days while our engineering team investigates and works on a resolution.
- Remediation: Once verified, we will coordinate the release of a patch or mitigation advice and will credit your contribution (if desired) upon public disclosure.