ACE Logo

ACE Security Statement

Last Updated: 08/01/2026

Security is a shared responsibility between Veltace, the organizations that deploy ACE, and the people who operate it. This statement describes our security approach at a high level without publishing implementation details that could weaken customer or service security. Here, Online Services means the Veltace-operated ACE website, customer portal, hosted license service, and support channels—not the self-hosted ACE automation Server.

Data Protection

ACE uses SSL/TLS to protect supported network communications in transit and AES encryption to protect sensitive data at rest. These safeguards are part of a broader security approach that is reviewed as the product, services, risks, and applicable requirements evolve.

Credential & Access Security

Credentials and sensitive service data are protected using appropriate storage and access controls. ACE provides permissions and administrative controls that customers can configure for their own users and environments.

Self-Hosted Architecture

The ACE automation Server runs on infrastructure selected and controlled by the Licensee. Operational data and local logs are not automatically sent to Veltace, and ACE does not provide Veltace with built-in remote access to the customer Server. Data leaves that environment only when the customer configures an external integration, uses a separate Online Service, or deliberately submits information for support.

Access Controls

Service Providers

Veltace uses established providers for functions such as hosting, analytics, and payments. Providers are selected and managed according to the service, risk, and applicable contractual or legal requirements. See the Privacy Policy for relevant data-processing information.

Secure Deployment

ACE security depends on the complete deployment. ACE includes rate-limiting controls intended to reduce abusive connection patterns, while Veltace applies rate limiting to appropriate Online Service endpoints. Rate limiting is one layer—not a substitute for secure network design. Customers and integrators should restrict exposure, use trusted systems, apply updates, protect credentials, configure least privilege, maintain recoverable backups, and test security and recovery procedures for the intended environment.

Minimal Data Collection

Veltace separates customer-hosted operational data from the limited information processed through the ACE website, customer portal, hosted license service, and support channels. See the Privacy Policy for the exact scope and choices.

Responsible Disclosure

If you believe you have found a security vulnerability in ACE or an ACE Online Service, report it privately to [email protected]. Include the affected version or service, impact, safe reproduction steps, and a way to contact you, but do not send unnecessary personal data, credentials, destructive payloads, complete licence or recovery keys, or customer data. We aim to acknowledge a usable report within seven calendar days; complex investigation may take longer. Please coordinate public disclosure with us and allow reasonable time for investigation and remediation. This policy does not promise a bug bounty or payment.

Secure Product Lifecycle

ACE is managed as a product with digital elements under a documented cybersecurity lifecycle. Security requirements and risks are reviewed across design, implementation, verification, release, maintenance, vulnerability handling, and end of support. Releases must be traceable to reviewed source and dependencies, and identified security risks must be treated or documented before release.

Before a release is represented as CRA-conforming, a machine-readable software bill of materials will be generated and retained for its released components. The SBOM and detailed technical evidence will not necessarily be public because they may contain security-sensitive information, but they will be retained and made available to authorities or conformity-assessment bodies where legally required.

Vulnerability Handling and Security Updates

Reports are acknowledged, triaged, investigated, remediated, and disclosed according to risk. Where a supported ACE release is affected, Veltace provides corrective or mitigating information and security updates without separate charge for the security correction during the support period, except where applicable law permits a different treatment.

Security updates are distributed through the documented ACE update channel. ACE is one continuously developed software product with a support period of at least five years, or longer where required by law. ACE uses a current-version remediation model: security corrections for superseded versions are normally delivered in the latest ACE version, made available to eligible users without charge through the update path. Veltace does not promise separate maintenance branches for every historical build. Issued security updates remain available for the period required by applicable law.

The local Server administrator starts installation with an explicit one-button action so the update can be scheduled around live automation. Veltace is responsible for making an authentic, tested update and clear risk, expected-downtime, and rollback information available. Administrators are responsible for monitoring notices, choosing the shortest safe maintenance window, applying the update without undue delay, verifying restart, and maintaining independent safeguards during the local outage. An urgent or actively exploited vulnerability may require immediate mitigation or isolation until a safe update window is available.

Cyber Resilience Act Reporting

Veltace maintains an internal escalation process for vulnerabilities that are known to be actively exploited and for severe incidents affecting ACE security. Where the EU Cyber Resilience Act requires notification, Veltace reports through the designated single reporting platform within the applicable statutory stages and informs affected users of corrective or mitigating measures when required. Customers, distributors, and integrators must promptly forward relevant evidence to [email protected] and must not delay urgent reporting.

CRA Conformity Status

This statement does not itself constitute an EU declaration of conformity or a certification. Before the CRA conformity obligations apply to a release, the manufacturer will complete the applicable product classification, technical documentation, conformity assessment, EU declaration of conformity, user information, and CE-marking steps. Manufacturer: Veltace s. r. o., registered office Karpatské námestie 7770/10A, 831 06 Bratislava, Slovak Republic.