Book a demo

[ Trust ]

Security and Data Handling

Energy data describes how a site actually runs. Before you hand it over, you are entitled to know where it will sit, who will see it, and when it gets deleted.

Last reviewed: August 2026

What we process, and what we do not

The platform handles three classes of data:

  • Technical measurement data — electrical quantities (kW, kWh, current, voltage, power quality), pressure, temperature, flow and equipment running states.
  • Site and asset definitions — site name and location, device list, contracted capacity, tariff details.
  • User account details — name, work email address, role.

Nothing outside these three classes is processed. Production or ERP data is handled only if you ask for it, and only within a scope agreed in writing.

In UK GDPR terms you remain the controller of this data. We act as processor and do only what your instructions and our contract allow.

The technical record

At a glance

Hosting
EU
Finland · ISO/IEC 27001 certified data centre
Dashboard and API
TLS
Encrypted end to end · certificates renew automatically
Field link
MQTT 8883
TLS protected · separate credentials per site
Password storage
bcrypt
Irreversible hash, never stored in plain text
Authorisation
2 layers
Role based and site based
Backups
daily
Automatic · retained 30 days

Where your data sits, in UK terms

Servers are in Finland, inside the European Economic Area. This matters for UK procurement: the UK recognises the EEA as providing an adequate level of protection, so personal data moving from the UK to our infrastructure needs no additional transfer safeguards.

One point we would rather state than have you discover: our support and engineering team works from Türkiye. Under UK GDPR, remote access from outside the UK counts as a transfer, and Türkiye does not hold a UK adequacy decision. Where personal data is in scope, an International Data Transfer Agreement can be put in place, with a transfer risk assessment alongside it.

If you would rather no data left your own network at all, that option exists too. See the on-premise section below.

Your data belongs to you

This is the most important line on the page.

  • On request, data is exported in a machine-readable format or permanently deleted.
  • Customer data is never shared with third parties, never used commercially, and never used in another customer’s analysis.
  • When a contract ends, data is handed over within the agreed period and removed from the system.

Energy data reveals a site’s production rhythm, shift pattern and capacity utilisation. That is precisely why we do not pool it, benchmark it against other customers, or use it to train models.

Access, network and application

Who can see what

Authorisation works in two layers: role based (administrator or user) and site based. A user sees data only for the sites they are authorised for, and administrative endpoints carry an additional role check. Sessions use signed tokens and expire.

Network and servers

The database and internal services are closed to the internet; only dashboard access is exposed. The firewall restricts by source, so field devices reach defined endpoints only. Administrative access to servers is key based and limited to a small number of people.

Application process

Source code is held in a private repository with restricted access. Internal security reviews run periodically. The most recent full review completed in July 2026, closing findings on authorisation checks, input validation, error message content and network access restrictions. A backup is taken before every release and a rollback point is kept.

Artificial intelligence: what goes where

There are two distinct AI components and they behave differently.

Automated findings and savings recommendations are rule based and run entirely on our own infrastructure. No data leaves the platform for this.

The natural-language assistant uses a cloud language model service. Only summarised figures relevant to the question asked are sent. The raw measurement archive and user details are not.

This component can be switched off entirely for your organisation. Everything else — monitoring, alarms, reporting and the recommendation engine — continues to work.

What we have not done yet

Most security pages list only what has been done. Stating what has not been done is what makes the rest credible. Current gaps:

  • Independent penetration testing. Not yet carried out. On request we agree a schedule with you and share the summary findings.
  • Second-location backup copies. Daily backups run; a second geographic copy is still in progress.
  • ISO/IEC 27001 certification. The data centre is certified. Certification of our own information security management system is a separate process and is not complete.

Keeping data inside your own network

The platform can run on your own server, or on a dedicated appliance we supply. In that model measurement and production data never leaves your network: no ports are opened to the internet and all connections are outbound only. We decide the deployment model together.

Contractual commitments

Available on request:

  • Non-disclosure agreement
  • Data Processing Agreement under UK GDPR, with an International Data Transfer Agreement where a restricted transfer applies
  • Completion of your supplier security assessment questionnaire
  • Breach notification: we notify you without undue delay, so that you can meet your own 72-hour obligation to the ICO

If your procurement process needs a fuller security document, we can send the briefing note this page is based on.

Let us measure what is happening on your site.

In a one-hour call we look at your existing setup and set out exactly which measurement points are needed and what you would be able to see.

Book a demo