The question

What can go wrong with a vendor and what happens then

Three things can go wrong with a connectivity vendor: Its service can be disrupted, it can stop maintaining the product you built on or it can cease to exist. This page takes them in that order and states, for each, what happens to a fleet built on Nabto and which provision covers it. It closes with who answers when you report a vulnerability, because a support period is only worth the response behind it.

If our cloud is disrupted

Connections pause. Devices do not change.

Nabto’s servers find devices and route connections; they hold nothing a device needs in order to run. If they are unreachable, new connections stop being made until service is restored and every device carries on with its keys, its pairings and its firmware exactly as they were. Why a disruption can never become an intrusion is explained on the trust page. Current service state is on the system status page.

Two provisions remove the dependency on our cloud altogether.

Run the server side yourself

Nabto WebRTC and Nabto Edge both run on your own infrastructure under a professional services agreement: A fixed-price deployment, an annual software subscription and no usage metering. Your fleet then depends on your operations, not ours. Terms are on the pricing page.

A continuity appliance, under Premium Maintenance

The Premium Maintenance addendum to our hosting and maintenance terms includes access to a Nabto appliance or an equivalent solution designed to keep the platform operating if Nabto’s cloud service is disrupted. It is an option agreed per contract and set up for your deployment.

If we stop maintaining a product

Years of notice, in writing, in advance

How long each Nabto product receives security updates is set out in the Nabto Security and Support Policy, the document our customer contracts point to. Its commitments are the same for every customer:

  • A support period is never shorter than five years from the date a product was first made available.
  • When Nabto decides to end support for a platform, the end date is published at least 24 months in advance and users with a registered security contact are notified directly.
  • An end date, once published, is never moved earlier. A change to the policy never shortens a period already published.
  • A released security update remains available for download for at least ten years after the product was first made available or for the rest of its support period, whichever is longer.
  • Nabto Edge, Nabto WebRTC and Nabto 4 all have no end date set.

The code inside your product is yours to build. The Nabto Edge device SDK source is published on GitHub and you compile it into a firmware image that you build and sign. A fix in the SDK never waits on a release pipeline you cannot see and nothing about a support period changes what you have already built.

If Nabto is gone

The platform is yours to run and the source can be too

Ceasing to exist is the case an assessor has to plan for with any vendor. Three provisions cover it. Each is available today, not on a roadmap.

Self-hosting

Under a self-hosted deployment the whole server side runs on your infrastructure with no usage metering. Day-to-day operation of your fleet then rests on your own operations team, with the software under an annual subscription.

Source code escrow

For the parts of the platform whose source is not already published, the Premium Maintenance addendum provides for a software escrow arrangement through an independent escrow provider, under a separate escrow agreement, agreed in writing. Release conditions are set in that escrow agreement.

Continuity terms in your agreement

Enterprise agreements can include change-of-control terms and continuity rights for the software you have deployed. Ask for them when you contract.

When you report a vulnerability

Named people, fixed response times

A support period is only as good as the response behind it, so the response is written down too.

Every report is acknowledged

A report to [email protected] or through GitHub is acknowledged within one week. A vulnerability that is being actively exploited is acknowledged within 24 hours, the window the Cyber Resilience Act gives a manufacturer for its own early warning. Details on the security page.

Support plans add named contacts

Support plans add response times from the Basic plan, a named technical contact from Professional and guaranteed response times and emergency phone access at Enterprise.

Advisories reach you directly

Every security update ships with an advisory on GitHub. Customers with a signed CRA addendum are also notified directly at their registered security contact.

For assessors

The documents

Everything above is stated in a document you can put in your vendor file. Two are public; the rest are sent on request.

Request the contract documents. The developer documentation is the normative reference for the support policy; this page is the plain-language statement of the same commitments.

Questions

Can we run Nabto without Nabto’s cloud?
Yes. Nabto WebRTC and Nabto Edge both run on your own infrastructure under a self-hosted deployment, set up under a professional services agreement with no usage metering. Under Premium Maintenance, a continuity appliance option keeps a Nabto-hosted deployment operating if our cloud service is disrupted.
Is the source code available?
The Nabto Edge device SDK source is published on GitHub and you build and sign the firmware image yourself. For components whose source is not published, source code escrow is available under the Premium Maintenance addendum.
Do you offer source code escrow?
Yes. It is arranged through an independent escrow provider under a separate escrow agreement, as provided for in the Premium Maintenance addendum.
How much notice do we get before a product’s support ends?
At least 24 months. The end date is published in the Security and Support Policy and sent directly to registered security contacts. A support period is never shorter than five years and a published end date is never moved earlier.
What happens if Nabto is acquired?
Your license, your support period and any escrow agreement are contracts with Nabto ApS and do not lapse because its ownership changes. Enterprise agreements can in addition include explicit change-of-control terms.
Who answers when we report a vulnerability?
Reports are acknowledged within one week or within 24 hours when the vulnerability is actively exploited. From the Professional support plan you have a named technical contact and Enterprise adds emergency phone access.
Does a disruption at Nabto put our devices at risk?
No. A device keeps its keys, its pairings and its firmware. A disruption can pause new connections but cannot open a device or change it. The trust page explains why.