Explore our Trust Center to find detailed information about IoT security best practices, industry certifications, and how we keep your data safe.
Visit our Trust CenterLearn about balena’s approach to IoT security in our whitepaper. Discover how we implement secure device management, data encryption, and compliance measures.
Download our WhitepaperThe Cyber Resilience Act (CRA) is the EU’s new regulation aiming to make digital products — both hardware and software — more secure by design and throughout their lifecycle. It applies to nearly every connected product on the EU market, from smart fridges to SaaS platforms.
But what exactly counts as a “product with digital elements”? What are “essential cybersecurity requirements”? And how does this affect manufacturers, importers, or devs working with open-source?
Deploy secure, resilient devices and meet regulations like the EU's CRA with balena's end-to-end security features.
Meet regulations like the EU's Cyber Resilience Act (CRA) and secure your fleet with balena's integrated security platform.
From secure boot to remote patching, use balena's foundational security to harden your devices against emerging threats.
Secure your entire device lifecycle—from development and supply chain to deployment and EOL—all on one platform.
Safeguarding security with reliable, verifiable updates, providing consistent application and kernel updates to keep fleets protected from potential attacks.
Offering secure authentication methods, including credential-based login, OpenID Connect (e.g. GitHub, Google), 2FA, TOTP, and SAML-based Single Sign-On for enterprises.
Name
Affiliation
Contribution
Disclosure Date
Resolution Date
Marco Jansen of Lorkeers
ThreatLabs
Marco reported a vulnerability in the 2FA recovery key management
April 22, 2024
June 14, 2024
Marco Jansen of Lorkeers
ThreatLabs
Marco reported a vulnerable gap in the 2FA setup
May 22, 2024
May 30, 2024
Santhoshkumar Chandramohan
—
Santhoshkumar reported a vulnerability in the email invite redirect parameter allowing malicious link injection
January 19, 2025
February 27, 2025