About · Security & compliance
Secure and private. Our default.
You are handing us your customers' names, addresses and account numbers. We treat that as the most important thing on the platform, and we let outside auditors check.
To report a security concern, see the responsible disclosure policy.
Independently audited
SOC 2 Type II
Security, Availability and Confidentiality. A Type II report shows the controls operated over a period, not on the day of the audit. Continuously monitored between audits.
- Privacy
- CCPA, as amended
- Accessibility
- WCAG 2.2 AA · VPAT on request
- Control monitoring
- Continuous, automated
- Penetration test
- Independent, at least annually
- Data collected
- Customer PII only. No card data. No PHI.
Personal data
Encryption at rest is the checkbox. We also encrypt the columns.
Most vendors enable encryption at rest in their cloud console and stop. So do we. Then we go a step further: every field of personally identifiable information in our databases is encrypted at the column level with PostgreSQL pgcrypto PGP encryption.
The consequence is what matters. Someone with access to a database copy would see ciphertext where the names, addresses and account numbers are, not the data. This makes some of our own teams' work slower. We accept that, because the alternative is your customers' data protected by a single setting.
We collect only the fields a program needs, use them only for eligibility and program operation, never sell them, and delete them at end of life or on your direction. Handling aligns with the CCPA as amended and with your data-governance requirements.
Financial data
We never store card or bank details. Not encrypted, not tokenized — not at all.
Card payments are handled end to end by Stripe, and financing applications by our lending partners, on their PCI DSS-certified systems. Payment fields are Stripe elements embedded in the marketplace: what a customer types goes straight from their browser to Stripe, and never reaches an Enervee server, database or log. Our PCI footprint is the minimal SAQ A, and your program inherits it. Our Trust Center lists it plainly under data collected: customer PII, yes; credit card information, no.
Security program
Layered, specific, and tested by people we don't employ.
-
Data
Encrypted in transit and at rest, with PII encrypted again at the column level.
- TLS 1.2 or higher in transit; AES-256 at rest across databases, object storage and volumes
- Keys in AWS KMS and HashiCorp Vault on hardware security modules, aligned to NIST SP 800-57
- No card or bank-account data stored; payments and financing handled entirely by Stripe and lending partners
- Classified, retained and disposed of under a documented data-management policy
-
Application
Tested by outside specialists on the running system, and by static analysis on every change.
- Third-party penetration tests of the deployed application and environment, at least annually
- Static application security testing (SAST) in the GitLab pipeline
- Code review and staged QA gates before every release
-
Infrastructure
Hosted on AWS with the platform’s native security services switched on.
- GuardDuty threat detection, Inspector vulnerability scanning, KMS
- Kubernetes on managed node groups and Fargate: no hand-managed servers in production
- Private subnets and endpoints, perimeter firewalls, managed DDoS protection
-
Identity & access
Least privilege, enforced and reviewed.
- Role-based access; administrative access requires multi-factor authentication
- Secrets in a dedicated key-management service, never in code
- Quarterly access reviews; prompt revocation on role change or departure; activity on sensitive data logged
-
Monitoring & response
Detection feeds an on-call team, and the plan for a bad day is rehearsed.
- Continuous threat detection, configuration monitoring and centralised logging
- Documented incident-response plan (detect, contain, eradicate, recover, review), tested at least annually
- Notification of affected customers, partners and regulators within the contracted window
-
People & vendors
Controls that apply to the humans and suppliers, not only the systems.
- Background checks, confidentiality agreements and security training for all personnel
- Production access limited to authorised staff
- Seven named subprocessors (AWS, Stripe, Google Workspace, HubSpot, Aircall, Snowflake, Vanta), each under security due diligence; the list is public on the Trust Center
- Cybersecurity insurance maintained; board briefed on cyber and privacy risk at least annually
Availability & continuity
Up when your customers need it, and recoverable when something fails.
Demand on a utility marketplace is not flat. A rebate email, a heat wave or a wildfire warning can multiply traffic in an hour. Capacity scales automatically, data is replicated across availability zones, and the recovery plan is rehearsed, not filed.
- Scaling
- Capacity for visits, eligibility checks and orders expands automatically during surges and releases as demand subsides.
- Redundancy
- Redundant load balancing, automated failover and data replicated across multiple AWS availability zones; component failures recover without invoking disaster recovery.
- Backups
- Daily encrypted backups and snapshots; cluster backup and recovery.
- Plan upkeep
- Business continuity and disaster recovery plan updated annually, key personnel trained annually, recovery procedures tested on a regular cycle.
Accessibility
Accessible by default. WCAG 2.2 AA.
A utility program serves everyone in the territory, so the marketplace cannot assume a mouse, a large screen or full vision. For many customers a phone is the only screen they will use.
Perceivable and operable
Full keyboard operation, visible focus, AA contrast, information carried by text and shape as well as colour, text resizing and responsive reflow, text alternatives for non-text content.
Understandable and robust
Semantic headings and landmarks, associated form labels, clear error identification, and name, role and state exposed to assistive technology.
How it is verified
Automated accessibility checks in the build; manual keyboard-only and screen-reader testing; acceptance criteria in design and QA; defects remediated on a risk-prioritised basis.
Documentation
Voluntary Product Accessibility Template (VPAT) and Accessibility Conformance Report against WCAG 2.2 AA and Revised Section 508, on request.
For your security review
What we can put in front of your security team.
-
Under NDA
SOC 2 Type II report
Security, Availability and Confidentiality trust services categories. Current period.
-
Under NDA
Penetration test summary
Most recent independent network and application test, with remediation status.
-
On request
VPAT / ACR
Accessibility conformance against WCAG 2.2 AA and Revised Section 508.
-
On request
Policy index & questionnaire answers
Information security, access control, cryptography, incident response, BC/DR, vendor and HR security. Completed SIG, CAIQ or your own format.
Security review
Send us your questionnaire.
We answer vendor security assessments as part of every utility engagement. Share the questionnaire or the frameworks you map to, and we'll return the SOC 2 report under NDA with it. We reply within a business day.