eucsoft

Support windows

How long each product is supported, and whether the vendor has said so at all. Under CRA Art. 13(8) an upstream vendor's silence is not a defence — it becomes the manufacturer's problem.

3declare less than the 60-month CRA floor
1ship software and declare no window at all
5of 20 ship an installable product; the rest are services

Of the 5 products you install, the other 15 being services with no window to declare:

1 declare nothing · 20%3 declare under the CRA floor · 60%1 meet the floor · 20%
Declared support period per product, latest observation.
VendorProductSupport periodvs CRA floorStateSource
SentrySelf-hosted SentryNot declareddevelop.sentry.dev
AtlassianData Center releases24 months−36 moDeclaredconfluence.atlassian.com
GitHubGitHub Enterprise Server13 months−47 moDeclareddocs.github.com
MongoDBMongoDB Server 8.060 monthsmeetsDeclaredmongodb.com
ZoomZoom Workplace desktop and mobile app9 months−51 moDeclaredsupport.zoom.com
CloudflareCloudflare (SaaS)Service onlycloudflare.com
DatadogDatadog (SaaS)Service onlydatadoghq.com
FigmaFigma (SaaS)Service onlyfigma.com
HubSpotHubSpot (SaaS)Service onlyhubspot.com
IntercomIntercom (SaaS)Service onlyintercom.com
MailchimpMailchimp (SaaS)Service onlymailchimp.com
MiroMiro (SaaS)Service onlymiro.com
NotionNotion (SaaS)Service onlynotion.so
OpenAIOpenAI API (SaaS)Service onlyopenai.com
SlackSlack (SaaS)Service onlyslack.com
SnowflakeSnowflake (SaaS)Service onlysnowflake.com
StripeStripe API (SaaS)Service onlystripe.com
TwilioTwilio API (SaaS)Service onlytwilio.com
VercelVercel (SaaS)Service onlyvercel.com
ZendeskZendesk (SaaS)Service onlyzendesk.com

On a narrow screen this table shows the answer only. Plan, source and date are on each vendor's own page.

Why a blank matters. CRA Art. 13(8) sets a five-year support floor and requires updates to remain available for ten. It makes the support window the manufacturer's responsibility — so an upstream component whose vendor has never declared one does not excuse you, it becomes your exposure. "Not declared" is the finding, not the absence of one.
"Service only" is not a pass mark. Most vendors here are pure services with nothing for you to run, so no support window attaches to them and the column is blank because the question does not apply. That is different from a vendor that ships software and says nothing — and mixing the two would invent a failing. Whether the Article binds any particular product depends on how it is placed on the market, which is your assessment to make, not ours.

Security contacts

Where a vendor publishes /.well-known/security.txt (RFC 9116), that is the machine-readable route for reporting a vulnerability to them. The standard makes an Expires field mandatory; a file without one, or one long past its date, is a file nobody is maintaining.

VendorReporting routesecurity.txt
Sentrysecurity@sentry.iono Expires field (RFC 9116 requires one)
Atlassianatlassian.comexpires 2027-02-04
GitHubhackerone.comexpires 2026-10-18
MongoDBnone publishednone at the well-known path
Zoomzoom.comexpires 2029-12-31
Cloudflarehackerone.comno Expires field (RFC 9116 requires one)
Datadognone publishednone at the well-known path
Figmahackerone.comexpires 2026-10-21
HubSpotsecurity-notifications@hubspot.comexpires 2034-06-01
Intercombugcrowd.comexpires 2029-03-15
Mailchimpmailchimp.comno Expires field (RFC 9116 requires one)
Mirosecurity@miro.comexpires 2030-12-30
Notionnotion.soexpires 2030-01-01
OpenAIbugcrowd.comno Expires field (RFC 9116 requires one)
Slackhackerone.comno Expires field (RFC 9116 requires one)
Snowflakesecurity@snowflake.comexpires 2027-08-17
Stripehackerone.comexpires 2026-12-31
Twilionone publishednone at the well-known path
Vercelhackerone.comexpires 2027-05-27
Zendeskzendesk.comexpires 2027-04-16