ENERGY1POWER

Security at ENERGY1POWER

Energy platforms fail in two ways: they get breached, or they dispatch incorrectly. We engineer against both.

ISMS

We run an information security management system aligned to ISO/IEC 27001:2022 and are on a published track to certification. SOC 2 Type I is targeted for Phase 5.

Zero-trust operations

The operator console sits behind Cloudflare Access with MFA. Live bids need two-person control, and releasing the kill switch needs two approvers.

Supply chain

Every change is scanned with Trivy, gitleaks, and dependency audits. Uploaded documents are malware-scanned before any parser touches them.

Append-only records

Bids, awards, dispatch, measurements, and settlements are immutable events. Corrections are made as reversing events.

Report a vulnerability

Email security@energy1power.com. We acknowledge reports within two business days. Please do not test against live market or dispatch endpoints.