Manufacturer disclosures · Regulation (EU) 2024/2847
Our disclosures under the Cyber Resilience Act
This page is reachable without a sign-in and without the app. It contains the information the Cyber Resilience Act requires from us as a manufacturer — the support period for our products, the route by which you can report a vulnerability to us, and our assessment of which products fall under the regulation at all.
Manufacturer
Techlogia, Inhaber Jaciel Antonio Acea Ruiz
Sole proprietorship
Prinzenallee 38
13359 Berlin
Germany
These details are identical to the master data in our product file and go unchanged into a declaration of conformity under Annex V.
Products and support period
Under Art. 13(8) CRA the manufacturer determines a support period and publishes it. During that period vulnerabilities are handled and security updates are provided. We also list the products we assess as not covered by the CRA — including the reasoning, because “not listed” and “assessed and not affected” are two different things in an audit.
Techlogia App
In scopeMobile application for the Techlogia Lab learning platform, distributed via the Apple App Store.
- Support period
- –
- Classification
- Standard — no category under Annex III or IV applies
- Assessment
- In scope. Distribution via the App Store takes place in the course of a commercial activity — the fact that it is free of charge does not change this (Art. 3(2)). The backend at techlogia.de/api is remote data processing under Art. 3(3) and is assessed as part of this product, not as a product of its own.
Techlogia Lab
Out of scopeWeb learning platform for Linux and IT security, operated on our own infrastructure.
- Support period
- No support period under Art. 13(8) — product not in scope
- Assessment
- Out of scope. No product with digital elements is supplied for distribution or use on the Union market (Art. 3(2)); the software runs on our own infrastructure and is not shipped. The operator perspective follows the NIS 2 framework, not the CRA.
Reporting a vulnerability
If you find a security vulnerability in one of our products, please report it to the address below. We acknowledge receipt within 48 hours. The full process, the rules for responsible disclosure and the scope are set out in our coordinated vulnerability disclosure policy.
Machine-readable under RFC 9116: /.well-known/security.txt
Read the vulnerability disclosure policyWhat applies from 11 September 2026
From that day Article 14 CRA applies: manufacturers report actively exploited vulnerabilities and severe security incidents within 24 hours as an early warning, within 72 hours as a supplementary notification, and subsequently with a final report. Recipients are the CSIRT designated as coordinator — in Germany CERT-Bund at the BSI — and ENISA. Our internal process for this is defined, names a responsible person and a deputy, and has been rehearsed.
Bill of materials (SBOM)
For the products in scope we maintain a bill of materials of third-party components in CycloneDX format. It forms part of the technical documentation and is not published generally — nor does the CRA require that. Market surveillance authorities receive it on request; other legitimate requests should go to the security address above.
Why there is no CE marking here
CE marking under the Cyber Resilience Act is tied to the date the remaining provisions take effect: 11 December 2027. Until then we do not apply CE marking under this regulation to our products and issue no declaration of conformity under Annex V. We consider this the more honest route: affixing a mark whose assessment procedure is not yet complete would be the worst possible start for a company that offers an evidence tool. The groundwork is under way — scope assessment, product file, risk assessment, bill of materials and evidence package are in place.
Status of this page
These details are maintained as soon as anything about them changes. The leading source is our product file; this page reflects its status.
The tool behind it: CRA-Akte