Security

Energy maintains an information-security program with documented policies and procedures designed to manage access, secure development, information protection, incident response, third-party risk, business continuity, and operational security.

Production infrastructure

  • Core services run in Google Cloud in the United States.
  • Energy uses application-level checks, cloud access controls, service authentication, and operational monitoring.

Security governance

Energy assigns security responsibilities and maintains documented policies for information assets, access, cryptographic safeguards, third parties, and incidents.

Identity and access

  • Account access is authenticated.
  • Connected-account ownership is checked before integration requests are proxied.
  • Per-user and per-service controls apply to connected-service requests.
  • Supported desktop credentials and session tokens use encrypted local storage.

Data and service protections

  • Encrypted-only connections to the account database.
  • Backup and point-in-time-recovery capabilities for the account database.
  • Database audit logging for relevant write, DDL, and role-management activity.
  • Authentication and server-authenticated encryption for selected coordination services.
  • Restricted access, audit logging, and alerts for relevant completed-turn vault access.

Secure engineering

Energy’s secure-development policy establishes security expectations throughout the development lifecycle. Engineering practices include version control, review and testing workflows, separated service components, deployment controls, and dependency, credential, and configuration safeguards.

Monitoring and incident response

Health checks and incident alerting monitor the application and core dependencies. Energy maintains documented incident-response procedures designed to support assessment, containment, investigation, remediation, and communication for relevant security incidents. Customer notification is subject to law and contract.

Security testing

Energy uses engineering reviews, operational monitoring, and security-focused tooling appropriate to the service.

Frequently asked questions

Is Energy SOC 2 certified?

SOC 2 is an independent attestation issued by a CPA firm, not a certification. Energy is building and maintaining a security program designed to support rigorous customer due diligence and is preparing for a future SOC 2 examination. Once a report is issued, qualified customers will be able to request it through the document-request process.

Where is my data stored and processed?

Core production services run in Google Cloud in the United States. See Privacy & Data Use for how Energy handles account information, customer content, and connected-service data.

Is my data encrypted?

Energy uses encryption and access safeguards for defined systems and data flows: connections to the account database are encrypted-only, supported desktop credentials and session tokens use encrypted local storage, and selected coordination services use server-authenticated encryption. Exact safeguards depend on the service and data flow, so Energy does not make a blanket encryption claim.

Does Energy train AI models on my content?

No. Energy does not train AI models on your content, and your data is not sold or used for advertising. Energy processes customer content to carry out the work you direct and to provide, secure, and support the service — see Privacy & Data Use.

Which providers process my data?

Energy publishes its core service providers and AI model providers on the Subprocessors page, including each provider’s service role and the data categories it may process. AI providers only process customer content for user-directed work, depending on the selected model and configuration.

Who at Energy can access customer data?

Access is governed by documented access-control policies with per-user and per-service controls. Sensitive stores use restricted access with audit logging and alerting, and database audit logging covers relevant write, DDL, and role-management activity.

What happens when there is a security incident?

Energy maintains documented incident-response procedures covering assessment, containment, investigation, remediation, and communication. Customer notification follows applicable law and the applicable agreement. See Reliability for how services are monitored.

Can I request deletion of my data?

Yes. Energy processes deletion and access requests under its documented privacy procedures; scope and timing may depend on the data involved, legal requirements, backups, and the applicable agreement. Contact privacy@getenergy.com to make a request.

How do I report a security vulnerability?

Email security@getenergy.com with reproduction steps and impact. The vulnerability disclosure page describes what to include and the good-faith guidelines Energy asks reporters to follow.

How do I complete a security review of Energy?

Start with this Trust Center, then request detailed materials — security overviews, architecture summaries, and policy summaries — through the document-request process. Energy responds to qualified customer due-diligence requests, including security questionnaires, through that process.

This page is provided for general information and does not amend the applicable agreement. Energy’s practices may vary by product, service, configuration, and region.

Privacy Notice · Terms of Service