RACO's
Secure by Design Pledge

We signed CISA's Secure by Design Pledge.
Here's what we promised.

Logo

The phone line didn't need a password. Your new system does.

For decades, a RACO autodialer sat on a copper phone line. It was simple, and it was hard to attack from a distance.

That world is going away. Gen2 and the RACO Monitoring Center (RMC) move your alarms onto cellular, satellite and the internet. You get better coverage, remote setup, and no phone bill. You also get something to defend.

Water and wastewater systems are real targets. In mid 2026 and prior, attackers got into internet-facing controllers at several U.S. water utilities. How? The factory default password had never been changed. 

Most of our customers run lean. Many have no full-time IT or security staff. A plant superintendent can't be expected to harden a cloud platform on nights and weekends. So we think the maker has to carry that load. That's the core idea of Secure by Design, and it's why we signed.


What the pledge is and isn't

A public promise with a deadline

The Secure by Design Pledge comes from the Cybersecurity and Infrastructure Security Agency (CISA). Companies that sign agree to work toward seven security goals over one year. Then they publish what they did.

A few things worth knowing:

  • It's voluntary. No law made us sign. We chose to.
  • It's public. CISA asks signers to show measurable progress, not just intent. Where we fall short, we'll say so.
  • It covers software. The pledge is written for software and cloud services, which includes RMC. CISA says hardware makers are welcome to show progress on devices too. We're applying the same goals to Verbatim Gen2. 


Goal 1: Multi-factor authentication (MFA)

What CISA asks: Measurably increase the use of MFA across our products.

Why it matters to RACO: A stolen password is still the easiest way in. RMC is where your team sets alarm points, edits call lists, and arms or disarms sites. If someone logs in as your operator, they could silence an alarm or change who gets the call. MFA means a password alone isn't enough.

Our users are often in a truck, in a wet well, or on a phone at 2 a.m. So MFA has to be easy, or people won't turn it on. We'd rather build it right than bolt on a hassle.

Where we stand: MFA is on our roadmap for end of Q4 2026 for RMC. It is implemented on AlarmAgent.com today.


Goal 2: No default passwords

What CISA asks: Reduce default passwords across our products. When setup is done, only the customer should hold the login.

Why it matters to RACO: This is the goal that hits closest to home for our industry. The 2023 water utility attacks came down to one thing: a password that shipped the same on every unit and never got changed.

Gen2 is built to avoid that trap. The unit opens no inbound ports, and you set it up through your own RMC account, not a shared factory login on the device. 

Where we stand: No RACO product ships since using a shared default password. 


Goal 3: Reduce entire classes of vulnerability

What CISA asks: Pick one or more common types of security flaw and cut them down across our products, at the root.

Why it matters to RACO: Most real-world attacks use the same few kinds of bugs over and over. Fixing them one at a time is a losing game. Removing the whole category is how you get ahead.

For us, that means the RMC web app and the Gen2 firmware. Our equipment stays in the field for a long time. Some original Verbatims have run for decades. A flaw we prevent in the code today is one you never have to patch at a remote lift station later.

Where we stand: TBD


Goal 4: Security patches

What CISA asks: Make it easier for customers to install security fixes, and take ownership of security after the sale.

Why it matters to RACO: Nobody wants to drive out to 40 sites to update firmware. If patching is hard, it doesn't happen, and unpatched gear is where attackers look first.

RMC is a cloud service, so we patch it ourselves. You don't have to do a thing. For Verbatim Gen2.

This goal also asks makers to be clear about how long a product will get security support. Our customers buy for the long haul, so we think that's only fair. 

Where we stand: All devices currently support OTA updates and do not require an upgrade. RACO does recommend an OS update every 3-5 years.


Goal 5: Vulnerability disclosure policy

What CISA asks: Publish a policy that lets good-faith security researchers test our products, gives them a clear way to report problems, and promises we won't take legal action against them.

Why it matters to RACO: We would much rather hear about a weakness from a researcher than from an attacker. A clear policy tells the people who find bugs that we want to hear from them, and that they're safe to tell us.

Where we stand: Our policy will be live at racoman.com/security/disclosure, with a security.txt file for researchers by July 31, 2026.


Goal 6: Honest CVE reporting

What CISA asks: File CVEs (the public record for security flaws) on time for all critical and high-impact issues, with complete and accurate details.

Why it matters to RACO: When there's a flaw that needs your action, you should hear about it fast and in plain terms. The CVE system is the standard way to do that. It's also how your IT team, your integrator, and your state regulators track risk.

CISA makes a point we agree with: a vendor with zero published flaws isn't always the safest one. Sometimes it's just the quietest. We'd rather be open.

Where we stand: Our CVE Policy is currently under development and we plan to issue it by July 31, 2026.


Goal 7: Evidence of intrusions

What CISA asks: Give customers the logs they need to spot and look into a security incident.

Why it matters to RACO: If something looks wrong, you need to know who did what, and when. RMC already keeps an alarm log with every alarm and every acknowledgement. Standard RMC service includes one year of data retention. CISA's own example is six months at no extra charge. 

This goal asks for more than alarm history, though. It asks for records of sign-ins and setting changes, too. That way, if a call list gets edited or a site gets disarmed, you can see exactly who did it.

Where we stand: Audit events RMC logs today (sign-ins, config changes, arm/disarm) and are retained for 1 year for free. Additional years of retention are available for an extra fee.


The three principles behind the pledge

How we think about security

CISA, the NSA, the FBI and cyber agencies from 12 other countries built Secure by Design on three principles. Here's what each one means for us.

1. Take ownership of customer security. Security shouldn't be an add-on you pay extra for, or a setting you have to find. It should work out of the box. If our product is hard to secure, that's our problem to fix, not yours.

2. Be open and accountable. We'll publish what we've done, what we haven't, and why. That includes this page, our progress report, and our CVEs.

3. Lead from the top. Security is a business decision at RACO, not only an engineering task. Our CEO owns this pledge.


What this means for you

Built for the people who run the system

For operators and superintendents You shouldn't have to be a security expert to keep your alarms safe. We aim for safe defaults, so the right choice is also the easy one.

For IT and security teams Gen2 uses outbound-only messaging with TLS encryption from end to end. It opens no inbound ports and needs no firewall changes for standard installs. Our cybersecurity statement has the details. 

For engineers and procurement CISA urges buyers to ask vendors hard questions about security. We agree. Use this page, our cybersecurity statement, and our progress report in your specs and vendor reviews.


Security is shared

Our part, and yours

We take on as much of the work as we can. But no product can secure a system by itself. Keep strong, unique passwords. Remove access when staff leave. Keep your local safeguards and response plans in place.

RACO monitoring is a tool for awareness, built with redundant paths. It doesn't replace your own procedures, and it isn't a life-safety system.

FAQ

Questions about the pledge

Did RACO have to sign this?

No. The pledge is voluntary. We signed because our customers run critical infrastructure with small teams, and we think the maker should carry more of the security load.

 

Does signing mean RACO products are certified secure?

No. The pledge isn't a certification, and CISA doesn't audit or endorse products. It's a public promise to make measurable progress on seven goals and report the results.

The pledge is about software. Does it apply to Gen2 hardware?

The pledge is written for software and cloud services, which covers RMC. CISA invites hardware makers to show progress too, and we're applying the same goals to Verbatim Gen2. 

What about my older Verbatim units?

Legacy RTUs and autodialers are not connected to the internet and are not a part of this pledge.

How will I know if you kept your word?

 We'll publish a progress report by December 31, 2026. We'll post it on this page.

How do I report a security problem?

 security@racoman.com. Please don't use the general support line for security reports, so your report gets to the right team fast.

Where can I get your cybersecurity statement?

Ask your RACO sales contact.