Compliance

Cybersecurity Compliance

Available in languages: English 中文 العربية Français Español русский 日本語

Document Version: 1.0
Last Updated: September 13, 2026

At Tigermeeting AB, we build meeting room management software designed for security, stability, and privacy. This document outlines our formal EU regulatory compliance, security instructions for our users, and our vulnerability disclosure process in accordance with the EU Cyber Resilience Act (CRA).

PART 1: EU Declaration of Conformity

1. Product/Software Identification:

  • Product Name: Tigermeeting Room Management Software
  • Software Components: Tigermeeting Android Application (APK), Tigermeeting Admin Application and Tigermeeting Cloud Services

2. Manufacturer Information:

  • Manufacturer: Tigermeeting AB
  • Registered Address: Edbovägen 47, 14263 Trångsund, Stockholm, Sweden
  • Website: https://tigermeeting.app

3. Responsibility Statement:

This declaration of conformity is issued under the sole responsibility of the manufacturer, Tigermeeting AB.

4. Object of the Declaration:

The object of the declaration described above (Tigermeeting software for digital signage, calendar integration, and meeting room management) is in conformity with the relevant European Union harmonization legislation, specifically:

  • Regulation (EU) 2024/2847 (Cyber Resilience Act - CRA)
  • Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR)

5. Conformity Assessment Procedure:

The conformity assessment procedure applied is the Internal Control procedure as detailed in the Cyber Resilience Act. A comprehensive Software Bill of Materials (SBOM) and Cybersecurity Risk Assessment are maintained internally by Tigermeeting AB and are available to market surveillance authorities upon lawful request.

Signed for and on behalf of Tigermeeting AB:

  • Place of issue: Stockholm, Sweden
  • Date of issue: September 13, 2026
  • Name, Function: Zoltan Arpadffy, CTO
  • Signature: [Signed on Original, available on request]

PART 2: Security Information & Instructions for Users

To ensure your meeting room displays and administrative dashboards remain secure, Tigermeeting AB requires network administrators and IT teams to adhere to the following operational guidelines:

1. Secure Network Architecture

  • Admin App: The central administration portal must be deployed behind a secure firewall or corporate VPN. Never expose the Admin application to the public internet without proper reverse proxy configuration, strict access controls, and HTTPS/TLS encryption.
  • Android Displays: We strongly recommend provisioning the Android tablets/screens running the Tigermeeting APK on an isolated IoT, guest, or dedicated digital signage VLAN. This prevents unauthorized lateral movement into your core corporate network.

2. Access Management & Calendar Integration

  • Default Credentials: Upon initial setup of the Admin users in the Admin app, administrators must immediately change all default / randomly generated passwords.
  • Service Accounts: When connecting Tigermeeting to your corporate calendar systems (e.g., Microsoft Exchange, Google Workspace), use dedicated service accounts with the principle of least privilege. Do not use personal administrator credentials for calendar API connections.

3. Software Updates

Tigermeeting actively monitors third-party dependencies in both our Android, Java, Angular and Node.js environments and regularly releases security patches.

  • Applying Updates: Administrators are notified of updates via the Release Note e-mails, social media posts - as well as in the network status icons in the Admin Application. Critical security updates should be deployed to all endpoint screens within 14 days of release.

4. Secure Decommissioning (Factory Reset)

When retiring a meeting room screen or migrating servers, administrators must utilize the platform's reset functionalities. For the Android APK, clear the app data or perform a device-level factory reset to ensure all local calendar caches, API tokens, and server connection strings are permanently destroyed.

PART 3: Product Support Lifecycle (End of Life)

In compliance with the EU Cyber Resilience Act, Tigermeeting AB guarantees to provide active vulnerability handling, security updates, and technical support for all major software versions for a minimum of five years from their respective release dates.

For the current latest version, this active support period is guaranteed until at least December 31, 2031.

Furthermore, as required by the CRA, any security update issued during this support period will remain accessible to users for at least 10 years from the date that specific update was released.

Beyond this date, the software version will reach End-of-Life (EoL). Tigermeeting AB will no longer guarantee the provision of security patches, and users will be required to upgrade to a newer supported version to maintain CRA compliance.

PART 4: Vulnerability Disclosure Policy

We welcome the contribution of security researchers, IT administrators, and users who help us improve the security of Tigermeeting.

How to Report a Security Flaw

If you discover a vulnerability in the Tigermeeting Android app, Admin app, or our web / cloud infrastructure, please report it immediately to our dedicated security team at: security@tigermeeting.app

Please include:

  • A technical description of the vulnerability and its potential impact.
  • Steps required to reproduce the issue (Proof of Concept).
  • The software version and hardware model you were testing on.

Our Response Timeline

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours.
  • Status Update: We will assess the vulnerability and provide an initial status update within 5 working days.
  • Remediation: We will develop and deploy a patch without undue delay.
  • Legal Reporting: Actively exploited vulnerabilities will be reported to the relevant national CSIRT and ENISA within 24 hours of confirmation, as required by EU law.

Safe Harbor

Tigermeeting AB will not pursue legal action against researchers who discover and report vulnerabilities in good faith, provided they do not exploit the flaw beyond what is necessary to prove its existence, do not access other users' data, and do not publicly disclose the vulnerability before we have issued a patch.

This is effective as of September 13, 2026.

Templates title