Secure software, throughout the product’s lifetime

CalWin AS is actively working to meet the requirements of the EU Cyber Resilience Act (CRA), and has established procedures for vulnerability handling and security updates for CalWin 7 and CalWin 8.

Coordinated vulnerability handling

A dedicated policy for how security researchers can report findings to security@calwin.no, with acknowledgement within 3 working days and a defined process through to resolution.

Defined support period

CalWin 8 has a declared support period of at least five years from market launch. CalWin 7 is actively supported, with notice well in advance before support ends.

Secure operations as an add-on

The Premium operations package provides a dedicated database, continuous backups and geographic redundancy for businesses with stricter requirements.

What is the Cyber Resilience Act (CRA)?

The CRA is the EU’s regulation on cybersecurity in products with digital elements. It requires manufacturers to ensure secure development, vulnerability handling and updates throughout the product’s lifetime. As a supplier of business-critical software to the window and door industry, CalWin AS takes these requirements seriously, and the work is an integral part of how we develop and operate CalWin 7 and CalWin 8.

Read our full vulnerability disclosure policy →

How we work with security in practice

  • A dedicated contact point for security reports, with urgent handling of critical findings.
  • Daily backups on all operations levels, with continuous backups and geographic redundancy on Premium.
  • Regular follow-up and advice through our management agreements, with reporting tailored to your needs.
  • Notice well in advance before support for a product version ends.

Do you have questions about security or compliance?

Get in touch – we are happy to answer questions from customers and their auditors.

Contact us