Encryption in transit and at rest
The platform architecture is designed to support encrypted transport and protected storage. Protocols, key ownership and storage controls are reviewed for the agreed deployment.
Role-based access
Access is designed around job responsibilities. Network, commercial, maintenance and administrative users should receive only the permissions needed for their work.
Organization-level isolation
Each organization’s data and workspace access are designed to remain logically separated. The deployment assessment covers isolation boundaries and administrative access.
Audit trails
Important access, investigation and configuration events are designed to be traceable, supporting review of who changed what and when.
Access monitoring
Administrative and integration access should be monitored against the agreed operational policy, with escalation paths defined during onboarding.
Human approval controls
Recommendations do not grant permission to change a bill, operate equipment or initiate a repair. Authorized people remain responsible for consequential decisions.
Configurable retention
Retention and deletion requirements are agreed by data category, operational need and deployment. The configuration should reflect customer and contractual requirements.
Secure enterprise integration
Connections use agreed service identities and permissions. Read-only access is preferred when the workflow does not require writes to a source system.
Data-quality monitoring
Missing readings, inconsistent identifiers and stale records should remain visible so operators can judge the reliability of a result.
Customer-controlled permissions
Your organization determines approved users, data access and enabled capabilities. Access changes follow an accountable administrative process.
