North
  • What we do
  • Products
  • Partners
  • Support
  • Contact us
  • Your downloads
  • Sign out
  • Sign in
  • Commander Hub
    • Your downloads
    • Sign out
    • Sign in

    • Commander Hub
  1. Support
  2. North product security

North product security & regulatory compliance

At North Building Technologies, we are committed to ensuring the ongoing safety, resilience, and security of our building automation and control systems.

On this page
Software updates Disclosure program

Software updates

To protect your infrastructure against evolving cyber threats, North strongly advises keeping all compatible products updated with the latest software and firmware releases.

In compliance with the UK PSTI and EU Cyber Resilience Act (CRA) regimes, North provides guaranteed minimum periods for critical security updates free of charge across our connected product lines:

  • North Commander: All North Commander units receive a minimum support period of at least five years of security updates from your date of purchase. For the latest Version 3 hardware (serial number 80007000 onwards), this guaranteed support lifecycle extends until at least December 2031.
    Critical security updates are delivered free of charge. To ensure your Commander is fully protected, please utilize the Cloud Update feature. Refer to the Updating Commander's Firmware section in the Commander Manual.
  • North ObSys: First released in 1999 and continually developed, ObSys remains a core part of our product line. We guarantee that ObSys will receive critical security updates free of charge until at least December 2029.

Note: North Zip modules and accessories, do not possess network connectivity, cannot receive software updates, and fall outside the scope of connected product security regulations.

Details of specific software versions, firmware releases, and historically resolved vulnerabilities can be found on our release notes page.

Coordinated vulnerability disclosure program

We collaborate openly with security researchers, system integrators, and customers to identify, mitigate, and patch vulnerabilities in line with global standards and EU CRA vulnerability handling rules. If you believe you have discovered a security vulnerability in a North product, please report it to our dedicated monitoring team.

Single point of contact: security@northbt.com
Language requirement: Please submit reports in English

What to include in your report

To help us investigate efficiently, please provide:

  • A technical description of the potential vulnerability or concern.
  • Details of the environment, tools, or proof-of-concept code used.
  • The specific product model, software, or firmware version affected.
  • (Optional) Your preferred contact information if you wish to receive status updates.

Our commitment & timelines

  • Acknowledgment: We will formally acknowledge receipt of your vulnerability report within 3 business days.
  • Status Updates: We will provide progress updates at least once every 14 days while our engineering team investigates and works on a resolution.
  • Remediation: Once verified, we will coordinate the release of a patch or mitigation advice and will credit your contribution (if desired) upon public disclosure.
Contact us

Get in touch. We would love to hear from you.

+44 (0)1273 69 44 22 info@northbt.com Our location and directions
News from North

Keep in touch with the latest news from North.

Subscribe to our mailing list
Popular links
About us Training Driver library Commander Hub
Trust centre
Privacy policy Security vulnerability reporting
© 2026 North Building Technologies Ltd.

News from North

Subscribe to our mailing list and keep in touch with the latest news from North.

Email me with:

By selecting subscribe, you agree that we can send occasional emails to you. Update your preferences, or unsubscribe, using the link in a News from North email. See our Privacy policy