Product security, in one paragraph
AirSpace Machinery Co., Ltd. publishes this policy so that distributors, end users,
security researchers and procurement auditors can report a suspected security
weakness in an AirSpace compressor package and know exactly what happens next.
We accept reports at a dedicated mailbox, acknowledge them, assess them against a
stated severity scale, fix what is confirmed, and tell the reporter what we did.
We follow the disclosure and handling models in ISO/IEC 29147 and ISO/IEC 30111,
and we align our position on EU Regulation 2024/2847 (the Cyber Resilience Act)
with the dates below.
Scope, stated plainly. An industrial air compressor is first and foremost a
machine. Its safety cases are mechanical and electrical — pressure vessels,
rotating guards, thermal protection, emergency stops — and those are governed by
the CE marking and the Machinery Regulation, not by this policy. This policy
covers the digital elements of the package: the machine controller, its
firmware, the operator interface, and any remote data-processing service supplied
with the unit.
1. What is covered
| In scope | Out of scope |
|---|---|
| Machine controller firmware and its update mechanism | Purely mechanical wear, pressure-vessel or guarding issues (report as a product safety matter, §6) |
| Operator interface / HMI logic and access control | Third-party plant SCADA, historian or network the compressor is connected to |
| Any gateway, module or app supplied by AirSpace for remote monitoring | Customer-supplied network equipment, firewalls and VPNs |
| Authentication and default credentials on AirSpace-supplied components | Generic web or email security of the reporting party |
| Documentation that claims a security property the product does not have | Denial-of-service by physical means, social engineering of our staff |
If a report touches both columns, we will still take it and route the mechanical
half internally.
2. Our security posture
AirSpace describes its control architecture as Zero Ransom Architecture. In
practice this means the compressor is designed to run and stay safe without
depending on an external connection:
- Local control is authoritative. Start, stop, load/unload, pressure setpoint
and all protection functions execute on the machine controller. Loss of a
network connection does not stop the compressor and does not defeat any
protective function. - No proprietary lock-in on the control layer. Setpoints, service parameters
and fault history are readable from the local panel, so a plant is not forced
into a single vendor’s remote platform to operate or service the machine. - Remote functions are additive, not load-bearing. AirSpace controllers are
network-capable. Where a remote monitoring or data connection is supplied or
enabled, it is a layer on top of local control — it reports, and it can be
switched off without changing the machine’s ability to run. Disabling the remote
function does not disable the compressor. - Firmware updates are authorised actions, and they can be delivered remotely.
A controller firmware update is issued by AirSpace and applied by AirSpace or by
an authorised service engineer. Where the plant has an authenticated remote
connection enabled, the update can be delivered over that connection; otherwise
it is applied on site. Nothing is pulled automatically from a public endpoint. A
plant that prefers no remote update path can have the remote function disabled
and updates applied on site.
We publish this because an audit questionnaire increasingly asks for a written
statement of the control architecture, not a brochure adjective.
3. How to report
Send the report to johnnywayne@chinacompressor.org with:
- The product family and, where available, the model and serial number.
- The controller or interface version, if you can read it from the panel.
- A description of the weakness and the conditions required to reach it.
- Steps to reproduce, or the reason reproduction was not attempted.
- Your name or handle, and whether you wish to be credited.
Please do not include live customer data, plant network diagrams you are not
authorised to share, or exploit code that can damage equipment.
4. What we commit to
| Stage | Target |
|---|---|
| Acknowledge receipt | Within 20 working days of receipt |
| Initial triage and severity assignment | Within 20 working days of receipt |
| Progress update to the reporter | Every 20 working days until the report is closed |
| Fix released, or a documented decision not to fix | Depends on severity; critical issues first |
| Public credit to the reporter | On request, after a fix is available |
We will not pursue legal action against someone who reports a potential weakness
in good faith, follows this policy, and does not disclose it publicly before we
have had a reasonable period to respond.
5. How we handle a report
Our internal sequence follows the two ISO/IEC models that procurement teams
recognise:
- Receive and acknowledge (ISO/IEC 29147 — vulnerability disclosure).
- Triage — confirm reproducibility, identify affected models and firmware
versions, assign severity. - Remediate (ISO/IEC 30111 — vulnerability handling) — fix in the current
firmware line, then assess whether units already in the field need a field
update, a service bulletin, or neither. - Notify — distributors and affected end users where the weakness is
confirmed and field-actionable; regulators where the law requires it. - Close and learn — record the root cause and feed it back into design review.
Severity is assessed on the realistic consequence for a compressor installation:
unauthorised change of a setpoint or a protection limit is treated as more severe
than information disclosure that does not affect machine state.
6. Product safety concerns that are not cybersecurity
A suspected defect in a pressure vessel, a guard, a relief device, a thermal or
electrical protection, or an instruction manual is a product safety matter.
Report those through the normal service channel at
Contact so they reach the
engineering team directly. Where a confirmed safety defect requires action on
units already delivered, we handle it as a field correction and notify affected
customers and distributors.
7. Our position on the EU Cyber Resilience Act
Regulation (EU) 2024/2847 — the Cyber Resilience Act (CRA) — entered into force
on 10 December 2024. Its obligations phase in:
| Date | What applies |
|---|---|
| 11 September 2026 | Reporting obligations begin: manufacturers must report actively exploited vulnerabilities and severe security incidents |
| 11 December 2027 | The main obligations apply to products made available on the EU market |
Our position on scope, stated without hedging. AirSpace compressor packages
contain digital elements — a controller running firmware and an operator interface
— and the controller is network-capable. We therefore treat our compressor
packages as products with digital elements within the meaning of the CRA, and we
prepare on that basis rather than arguing for an exemption we could not defend in
an audit.
For products in scope, the deliverables the CRA expects — a cybersecurity risk
assessment, vulnerability handling across the product lifecycle, and a software
bill of materials — are engineering artefacts. We treat them as such rather than
as marketing copy.
Sources: European Commission, Cyber Resilience Act (digital-strategy.ec.europa.eu);
regulation entered into force 10 December 2024, main obligations apply from
11 December 2027, reporting obligations from 11 September 2026.
8. Frequently asked questions
Does an industrial air compressor really need a cybersecurity policy?
It does if the package contains digital elements — a controller with firmware, an
operator interface, or a supplied remote-monitoring service — and it is sold into
a market where procurement audits ask for one. The EU Cyber Resilience Act treats
products with digital elements as in scope regardless of industry, and its
reporting obligations began on 11 September 2026.
What is Zero Ransom Architecture?
It is AirSpace’s name for a control design in which every function the machine
needs to run safely executes locally on the machine controller, so that losing a
network connection cannot stop production or defeat a protection function. The
controller is network-capable, but the network is an added layer rather than a
dependency: the compressor runs with the remote function disabled, and disabling
it does not disable the machine.
How do I report a vulnerability in an AirSpace compressor?
Email the security mailbox listed in §3 with the model, the controller version
where you can read it, a description of the weakness, and reproduction steps. You
should get an acknowledgement within 20 working days.
Will you credit me if I report something?
Yes, on request, once a fix is available. We ask that you give us a reasonable
period to respond before any public disclosure.
Is reporting a vulnerability going to get me sued?
No, not if you act in good faith, follow this policy, avoid damaging equipment or
accessing data you are not authorised to see, and give us time to respond before
publishing.
Are AirSpace compressors in scope for the EU Cyber Resilience Act?
Yes. Our compressor packages contain digital elements — a controller running
firmware and an operator interface — and the controller is network-capable, so we
treat them as products with digital elements within the meaning of Regulation (EU)
2024/2847 and prepare on that basis. This applies across our product families
rather than being assessed case by case. If you need the scope statement for a
specific model written into a questionnaire answer, send the model reference to
the address in §3.
Does this policy cover mechanical safety?
No. Mechanical, pressure and electrical safety concerns go to the service channel
in §6, so they reach the engineering team directly rather than a security queue.
How long do you support a product’s security updates?
We handle confirmed vulnerabilities for at least ten years from delivery. The
Cyber Resilience Act sets five years as the floor for most products with digital
elements, and its recitals note that equipment intended for use in industrial
settings is often in service considerably longer — so we publish ten rather than
five, and we treat it as a commitment rather than a target. Every security update
we issue remains available for ten years after it is released, or for the
remainder of the support period, whichever is longer, as Regulation (EU) 2024/2847
requires.
Where does this policy sit in your documentation set?
Alongside the Privacy Policy and
Terms and Conditions.
It is the security-specific counterpart: those cover data and commercial terms,
this covers the product’s digital elements.
9. Next step
If you are completing a supplier security questionnaire, send it with the
specific clause references to the contact address in §3 and we will answer
clause by clause rather than asking you to infer the answer from this page.
Distributors can request the current version of this policy for their own
customer files.
⚡ Is Your Factory Bleeding Cash?
Most fixed-speed compressors waste $3,600/year in "Unload Tax." Test your waste level in 30 seconds.
RUN THE ROI TEST →