Edit Template

Cybersecurity Statement of Compliance

View contents
  1. 01 Product information
  2. 02 Purpose of the statement
  3. 03 Reporting security vulnerabilities
  4. 04 Recommended information when reporting a vulnerability
  5. 05 Passwords and access credentials
  6. 06 Security support period
  7. 07 Content of security updates
  8. 08 Publication and download of updates
  9. 09 Notification of new updates
  10. 10 Software integrity and authenticity
  11. 11 Cybersecurity maintenance
  12. 12 End of security support
  13. 13 Manufacturer’s declaration
  14. 14 Issue and signature
01

Product information

Product model or family[Radiators / Electric towel rails / Storage heaters / Electric underfloor heating / Domestic hot water cylinders / Split air conditioners / Portable air conditioning / Outdoor heating / Portable heating devices]
Product typeInternet-connected electronic device
Intended useDomestic
ManufacturerIndustrias Royal Termic, S.L.
Manufacturer’s addressVicente Antolinos Industrial Estate, C/E, Plot 43, 30140 Santomera (Murcia), Spain
Websitewww.rointe.co.uk
02

Purpose of the statement

This statement of compliance has been prepared by Industrias Royal Termic, S.L., the manufacturer of the product.

Industrias Royal Termic, S.L. declares that the product identified on this page has been designed, developed, manufactured and maintained in accordance with its internal cybersecurity processes and the legal requirements applicable to the product.

In particular, Industrias Royal Termic, S.L. declares that, in its opinion, the product complies with the security requirements applicable to it under Schedule 1 of the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023.

This statement applies to the model or product family indicated above and covers all software and firmware versions officially released by the manufacturer during the security support period.

03

Reporting security vulnerabilities

The manufacturer provides a dedicated channel for reporting potential security vulnerabilities that may affect the product.

Security email: [[email protected]]

Acknowledgement: within a maximum of five working days.

Status updates: at least every 14 calendar days until the matter is resolved or closed.

Reports received through this channel are recorded, analysed and prioritised according to the associated risk.

The manufacturer will acknowledge receipt of each report within a maximum of five working days. Thereafter, it will inform the reporting person of the status of the matter at least every 14 calendar days until it is resolved or closed.

Where a vulnerability is confirmed, the manufacturer will implement the corrective measures required under its vulnerability management procedure.

04

Recommended information when reporting a vulnerability

To facilitate the assessment, the report should include the following information wherever possible:

  • name of the affected product;
  • product reference;
  • serial number;
  • description of the vulnerability;
  • steps required to reproduce it;
  • any observed consequences;
  • contact details of the person submitting the report.

Passwords, private keys and unnecessary personal data must not be submitted.

05

Passwords and access credentials

The product is not supplied with a universal default password shared by all units.

Authentication is configured during the app pairing process using one of the following options:

  • creation of a password by the user during initial installation, which can subsequently be updated at the user’s request;
  • assignment of unique credentials to each device by the server;
  • use of an equivalent individual authentication mechanism.

Access credentials are managed and protected using appropriate security measures.

The user must change the credentials where required by the product or installation instructions and must protect them against unauthorised access.

06

Security support period

The manufacturer will provide security support for this product until the date stated below:

Minimum support period: five years, until 31 December 2031.

During this period, the manufacturer will monitor vulnerabilities and release security updates where they are necessary and technically feasible.

This is a minimum period and will not be shortened under any circumstances. The support end date may be extended. While the model or product family remains on sale, the manufacturer will review this date annually and extend it so that security support is maintained for at least five years from the date on which the final unit is placed on the market.

Any amendment will be published as soon as reasonably possible on this page or in the manufacturer’s support area.

07

Content of security updates

Security updates may include:

  • correction of identified vulnerabilities;
  • firmware security patches;
  • updates to third-party software components;
  • updates to cryptographic libraries;
  • renewal or replacement of digital certificates;
  • improvements to authentication mechanisms;
  • improvements to communications protection;
  • mitigation measures addressing new threats;
  • corrections relating to software integrity and authenticity.

Security updates do not necessarily have to include new functions or commercial product enhancements.

Security updates will be provided without additional charge during the declared support period, without prejudice to any applicable connectivity costs, technical intervention costs or third-party service charges.

08

Publication and download of updates

Depending on the characteristics of the product, updates will be distributed through one or more of the following channels:

  • secure over-the-air (OTA) updates;
  • the official mobile application;
  • official configuration software;
  • the customer portal;
  • the manufacturer’s support website;
  • an authorised technical service.
09

Notification of new updates

The availability of security updates may be communicated through:

  • the product interface;
  • the mobile application;
  • the customer portal;
  • the email address provided by the user;
  • the support website;
  • security notices or bulletins published by the manufacturer.

Information accompanying each update may include:

  • the update identifier;
  • publication date;
  • affected products;
  • a general description of the corrections;
  • installation instructions;
  • possible effects on operation;
  • recommended actions for the user.

For security reasons, the manufacturer may temporarily limit the level of detail published about a vulnerability until the update has been distributed.

10

Software integrity and authenticity

The product software and firmware are subject to controlled configuration, verification, validation and approval processes before release.

Where technically applicable:

  • update packages are digitally signed;
  • their integrity is verified before installation;
  • modified or unauthorised updates are rejected;
  • measures are implemented to prevent the installation of vulnerable or incompatible versions.
11

Cybersecurity maintenance

During the support period, the manufacturer maintains processes to:

  • monitor published vulnerabilities;
  • assess cybersecurity risks;
  • analyse reports received;
  • develop and validate corrective measures;
  • carry out security testing;
  • publish updates;
  • manage product-related incidents;
  • maintain records of released software versions.
12

End of security support

Once the security support end date has been reached:

  • the release of new security updates will no longer be guaranteed;
  • vulnerabilities identified subsequently may not be corrected;
  • continued use of the product may involve additional risks;
  • users are advised to consider replacing the product, disconnecting it or limiting certain connected functions.

The security support end date will remain published on this page or in the manufacturer’s support area.

13

Manufacturer’s declaration

Industrias Royal Termic, S.L. declares that it maintains the technical and organisational measures required to manage the cybersecurity of the product during the stated support period.

This statement refers exclusively to the models and references identified on this page and to the software and firmware versions officially released by the manufacturer.

14

Issue and signature

Place and date of issue: Santomera (Murcia), Spain, 3 August 2026.

Signature:

Name: Pedro Gónzalez Soto

Position: Managing Director

Privacy summary

This website uses cookies so that we can offer you the best possible user experience. Cookie information is stored in your browser and performs functions such as recognising you when you return to our site or helping our team understand which parts of the site you find most interesting and useful.