The cart is empty

Software Bill of Materials (SBOM)

As part of our commitment to software transparency and compliance with the EU Cyber Resilience Act, ITVDesk maintains a detailed Software Bill of Materials (SBOM) for every released version.

About SBOM

The SBOM lists all open-source and third-party components used within the software, along with their versions and licenses. It allows partners and customers to verify the security posture of the product and track component-level vulnerabilities.

Public Summary

For transparency purposes, we provide a signed summary of the current release SBOM:

Full SBOM Access

The full, detailed SBOM (including all dependencies and license data) is maintained internally and available to regulatory authorities, integrators, and enterprise partners upon request.

To request the full SBOM for compliance verification, contact us at:
πŸ“§ This email address is being protected from spambots. You need JavaScript enabled to view it.

Last updated: October 2025


πŸ›‘οΈ EU CRA READY – Certified Software
Declaration of Conformity – October 2025

Security Contact

If you need to contact our security team directly, please use the following email address:

πŸ“§ This email address is being protected from spambots. You need JavaScript enabled to view it.

You can reach out for:

  • Reporting security vulnerabilities
  • Verifying software authenticity
  • EU CRA compliance inquiries

We aim to respond to all security-related communications within 72 hours.


ITVDesk Security Team

πŸ›‘οΈ EU CRA READY – Certified Software

Software Update & Patch Policy

ITVDesk provides secure and verified updates to ensure reliability, security, and compliance of the software.

  • βœ… Manual Updates Only: Updates are performed exclusively by the user by downloading the latest version from the official website.
  • βœ… Secure Installation: The user performs the replacement manually to ensure full control and installation safety.
  • βœ… Digitally Signed: All installers and update packages are signed with our EV Code Signing Certificate.
  • βœ… Integrity Verification: Each release includes SHA-256 checksum and signature files for verification.

All official updates are available only through the ITVDesk Downloads page and are distributed over HTTPS for authenticity and tamper protection.


Software Integrity & Protection

All ITVDesk binaries are digitally signed using an EV Code Signing Certificate to ensure authenticity and trust.

  • βœ” Integrity Verification: Application components are verified during execution to ensure they have not been modified.
  • βœ” Tamper Detection: Any unauthorized modification of binary files may result in integrity validation failure and restricted application functionality.
  • βœ” Trusted Distribution: Only officially signed and verified builds are supported and recommended for use.

Last updated: April 2026
Designed in accordance with EU Cyber Resilience Act (CRA) principles.

βœ” Secure Distribution: All downloads are served over HTTPS from official sources only - Downloads

EU Declaration of Conformity

Manufacturer:
IT vl. Mile Brkanović
54. Ulica 20
20271 Blato, Croatia
VAT: HR86858304503
https://www.itvdesk.eu
This email address is being protected from spambots. You need JavaScript enabled to view it.

Product name: ITVDesk – Virtual IP Camera & Streaming Software
Model / Edition: ITVDesk
Version: 8.6
Type: Software application

Conforms to the following EU legislation

  • Regulation (EU) 2024/XXXX β€” Cyber Resilience Act
  • Directive 2014/53/EU β€” Radio Equipment Directive (Article 3(3), applicable for connected software)
  • Regulation (EU) 2023/988 β€” General Product Safety Regulation

Harmonized standards and technical specifications applied

  • EN ISO/IEC 27001:2022 β€” Information security management
  • EN 303 645 v2.1.1 β€” Cyber security for consumer internet-connected products
  • EN 301 489-1 β€” EMC compatibility (where applicable)
  • CycloneDX SBOM specification v1.6 β€” Software component transparency and vulnerability tracking

Supporting documents

  • Technical documentation and risk assessment file (ITVDesk_TechFile.pdf)
  • Software Bill of Materials (itvdesk_sbom.json)
  • Security changelog and Vulnerability Disclosure Policy (https://www.itvdesk.eu)

Place and date of issue: Blato, Croatia β€” 11 October 2025

Signed for and on behalf of:
Mile Brkanović
CEO, IT vl. Mile Brkanović

Vulnerability Disclosure Policy (VDP)

ITVDesk values the contributions of the security community. If you find a security issue, please report it responsibly.

How to Report

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

  • Include a detailed description of the issue
  • Provide steps to reproduce (if possible)
  • Report privately and allow time for us to fix it

Response Commitment

  • Acknowledgment within 72 hours
  • Status update within 7 business days
  • Credit for responsible disclosure (optional)

Legal Safe Harbor

If you follow this policy in good faith, ITVDesk will not pursue legal action against you for your testing activities.

Last updated: October 2025

Security Changelog

This log lists important security-related changes and fixes in ITVDesk releases.

ITVDesk 10.8.0 - Security Update

Released: September 20, 2026 · Build: 7.7.11.2

This release adds security controls for hardened deployments and DISA STIG-related configuration requirements. Deployment-specific assessment and configuration are still required.

New Security Features

  • Added optional HTTPS-only and RTSPS-only operation.
    Administrators can disable plain HTTP per camera and plain RTSP for the streaming service. SRTP remains a separate option for encrypted audio/video.
  • Added Windows-protected storage for configuration, UI accounts, security settings, audit records and imported TLS private keys.
    Windows DPAPI adds protection tied to the Windows installation while supporting the existing application and SYSTEM Broker workflow.
  • Added shared certificate management for RTSPS and camera HTTPS services.
    Administrators can validate and save a certificate pair, apply it to all cameras, or select individual camera certificates under Advanced.
    Apply to All Cameras reloads the saved pair by restarting the relevant active services; clients may briefly disconnect.
  • Added an administrator-controlled certificate recovery policy.
    When the entire protected certificate store is missing, the optional fallback can use the bundled default certificate with a visible warning. Damaged or unreadable stores do not trigger fallback.
  • Added optional forwarding of Security Audit events to the Windows Application Event Log.
    Events use the ITVDesk Security source and can be collected through Windows Event Forwarding or existing monitoring tools. Collection and retention are configured by the administrator.
  • Added Change Password to UI Protect, including protection against reuse of the current and previous five passwords.
    Changes require the current password and TOTP code when enabled. Password history is retained if the same username is removed and added again.
  • Added an optional 15-character minimum-password policy for new or changed UI and supported network account passwords.
    Existing passwords remain valid until changed.
  • Added independent Local UI and Network Account Lockout controls.
    Both are disabled by default, with initial values of three failed attempts within 15 minutes and a 10-minute lock duration.
  • Added per-stream snapshot access control.
    Administrators can disable snapshot generation and retrieval, including access to previously cached images.
  • Added automatic Web Management sign-out after 10 minutes of inactivity.
    The panel is Administrator-only. Background image and status refreshes do not extend the session; sign-out is audited and does not stop separate ONVIF or VMS/NVR streams.

Security Improvements

  • Strengthened Local UI password protection with salted PBKDF2-HMAC-SHA256 hashing.
    New or changed UI passwords require at least eight characters, including uppercase and lowercase letters, a number and a special character. Existing accounts remain usable.
  • Improved network account setup by removing the predefined Add Camera password and validating new or changed camera passwords.
    The basic camera password policy requires at least eight characters with letters and numbers when the optional 15-character policy is disabled.
  • Added clearer ONVIF Administrator, Operator and User permissions and an Operator option in Login Management.
    Operator supports media configuration and PTZ; User supports viewing, events and playback/search. System, network and account administration require Administrator.
  • Protected direct HTTP/HTTPS snapshot access with Digest authentication when camera ONVIF authentication is enabled.
    Snapshot requests use the existing audit and optional network lockout policy, and responses instruct browsers and proxies not to cache images.
  • Expanded Security Audit with application and Broker startup/shutdown, UI authentication, supported UI configuration changes and Web profile/account saves.
    Administrative records identify the verified user, target, action and result without recording passwords or private keys.
  • Improved audit persistence with periodic and orderly-exit saving and coordinated application/Broker updates.
    With Windows Event Log forwarding enabled, local audit-save failures also generate a rate-limited error event.
  • Strengthened RTSP session-ID and SRTP key generation with a cryptographically secure random source.
    Active RTSP session IDs are checked for duplicates. Existing ID formats and SRTP key lengths remain unchanged.
  • Simplified HTTPS, RTSPS, SRTP and Certificate Management settings with clearer labels, status messages and aligned controls.
  • Added quick access to temporary Account Lockouts from the camera menu and automatic list refresh when opening the Account Lockout tab.
    Manually blocked IP addresses remain separate under Blocked Clients.
  • Updated the bundled default TLS certificate to RSA-2048 / SHA-256 and improved certificate validation messages.
  • Reduced internal Release log noise and improved encrypted configuration saving with atomic file replacement.

Security and Reliability Fixes

  • Fixed pending Security Audit records being lost after reopening the application and incorrect success reporting when clearing the audit fails.
  • Fixed normal Digest authentication challenges being counted as failed logins and already-blocked requests extending account lockout.
  • Corrected Burst Protection escalation and cleanup of expired counters.
  • Fixed RTSPS-only setup rejecting certificate pairs already saved in Windows-protected storage.
  • Fixed Web Management signing out prematurely after a temporary connection or status-check error.
  • Improved ONVIF XML depth validation to prevent parser stack overflow without changing the accepted nesting limit.
  • Fixed Windows license-history saving failures and Qt 6 compatibility for UI password-length validation.

Important Upgrade Notes

  • Windows configuration gains DPAPI protection on its next successful save. macOS and Linux storage behavior is unchanged.
    Keep a backup before upgrading: older builds cannot read protected files, and moving to another Windows installation requires planned recovery.
    Updates and in-place reinstalls retain access when configuration and the Windows installation are preserved. Windows file permissions remain necessary.
  • Import a deployment-specific certificate for production and configure client trust. Keep a secure backup of the original certificate and private key.
    Clients using the previous bundled certificate may require a trust update. Strict installations can disable default-certificate fallback.
  • VMS/NVR accounts that change media settings or use PTZ require Operator or Administrator; system and account changes require Administrator.
    Web Management supports browser Digest login over HTTP and HTTPS. HTTPS is recommended; Sign in may reuse credentials already cached by the browser.
  • UI password history applies to local UI accounts, not network accounts. Secure-only modes and Windows Event Log forwarding remain optional and disabled by default.

  • v8.6 β€“ October 2025 – Added CRA compliance, Watcher integrity verification, and signed update validation
    Added RTSP over HTTPS and improved certificate validation.
    Added RTSPS support.
    Added ITVDeskWatcher servise for protect ITVDesk in case of a crash or hang it safely restarts the app and restores all previously in case of a crash or hang it safely restarts the app and restores all previously  configured streams (desktop, camera, audio), keeping transmissions online with no manual intervention.
  • v8.5 β€“ September 2025 – SRTP (Secure Real-Time Transport Protocol) support added for IP camera streams.
  • v8.4 – July 2025 – Fixed potential buffer overflow in encoder video handling

Older versions change look link or upon request: This email address is being protected from spambots. You need JavaScript enabled to view it.


πŸ›‘οΈ EU CRA READY – Certified Software

# ITVDesk Vulnerability Disclosure Policy (VDP)

## 1. Purpose ITVDesk is committed to maintaining the highest security standards for our software products and services. We recognize the valuable role that independent security researchers play in helping us achieve this goal.

## 2. Scope
This policy applies to all ITVDesk software products and services, including:
- ITVDesk desktop applications (Windows, macOS, Linux)
- ITVDeskWatcher background service
- ITVDesk licensing and update systems
- itvdesk.eu domain and subdomains


## 3. Reporting a Vulnerability
If you discover a potential vulnerability, please notify us by email:


πŸ“§ **This email address is being protected from spambots. You need JavaScript enabled to view it.**

Please include:
- a detailed description of the issue
- steps to reproduce (if possible)
- affected version(s) or platform(s)


### Do’s
βœ… Provide a clear, technical description
βœ… Report privately and responsibly
βœ… Allow us reasonable time to fix the issue before disclosure


### Don’ts
🚫 No denial-of-service (DoS) testing
🚫 No data extraction or access to user data
🚫 No attacks against live customer systems


## 4. Our Commitment
- We will acknowledge your report within **72 hours**
- We will provide a status update within **7 business days**
- We may publicly credit responsible disclosures (with your consent)


## 5. Legal Safe Harbor
If you follow this policy in good faith, ITVDesk will not pursue legal action against you for your testing activities.


_Last updated: October 2025_