Trust Center & Security Principles
Engineered for the rigorous demands of critical infrastructure.
When you partner with Battery Cyber to defend your energy storage or critical power assets, you entrust us with the visibility into your most sensitive operational networks. We operate under uncompromising engineering safety principles, strict customer data boundaries, and verifiable security governance.
Operating Commitments
Core Operational Principles
Our operational safety model is founded on three immutable engineering commitments:
1. Operational Safety First
We never execute active port scans, synthetic packet flooding, or unauthorized intrusive commands on active operational networks. All telemetry collection on industrial control loops utilizes optically isolated physical taps or passive SPAN mirrors. Power availability and physical safety always supersede data collection.
2. Customer Data Boundaries
Your industrial telemetry, asset parameters, network topology schematics, and configuration files belong strictly to you. Battery Cyber never sells customer data, never trains public models on proprietary site telemetry, and provides complete on-premises air-gapped deployment options for classified or sensitive installations.
3. Verifiable Integrity
We practice radical transparency. Every remote session proxied by our platform is recorded at the visual and protocol level. Every code release is cryptographically signed, built via audited pipelines, and tested against rigorous static and dynamic analysis.
Technical Governance
Data Handling, Encryption & Access Controls
How telemetry and customer assets are protected across transit, rest, and analysis.
Encryption in Transit & at Rest
All data transmitted between site sensors and management control planes is encrypted using TLS 1.3 with mutually authenticated certificates (mTLS). In air-gapped deployments, telemetry remains confined entirely to customer-owned physical media. Stored customer metadata is encrypted at rest using AES-256 with customer-managed cryptographic keys (CMEK) supported upon request.
TLS 1.3 • mTLS • AES-256-GCM • CMEK supportLeast-Privilege & Zero-Standing Access
Internal access to customer environments is governed by strict role-based access control (RBAC), multi-factor authentication (FIDO2 WebAuthn hardware keys required), and ephemeral privilege grants. No Battery Cyber engineer has permanent standing access to customer production telemetry or edge appliances.
Hardware MFA • Ephemeral grants • Immutable audit trailsSecure Software Development Lifecycle (SSDLC)
Our software and sensor firmware are developed under strict security controls: branch protection rules, mandatory peer review by senior engineers, automated static analysis (SAST), software composition analysis (SCA) for open-source dependencies, and continuous container vulnerability scanning.
SLSA-aligned pipelines • CycloneDX SBOMs • Signed commitsDeployment Isolation Options
We support three distinct deployment tiers: Dedicated Cloud (isolated tenant containers deployed across global Cloudflare edge infrastructure), Hybrid (local edge collectors with outbound-only mTLS metadata sync), and 100% Air-Gapped On-Premises (for military bases, municipal utilities, and sovereign critical sites with zero internet connectivity).
Dedicated Cloud • Hybrid DMZ • 100% Air-GappedIndustry Benchmarks
Standards & Framework Alignment
Battery Cyber engineers its platform, services, and assessment methodologies to align precisely with international industrial cybersecurity and critical infrastructure frameworks:
| Standard / Framework | Issuing Body | Primary Domain | Battery Cyber Alignment & Application |
|---|---|---|---|
| IEC 62443 | ISA / IEC | Industrial Automation and Control Systems (IACS) Security | Engineered to IEC 62443-3-3 (System Security Requirements) and IEC 62443-4-2 (Component Security). We help operators establish Zones, Conduits, and Security Levels (SL 1–4). |
| NIST SP 800-82 | NIST | Guide to Operational Technology (OT) Security | Core reference for passive network monitoring, ICS network segmentation, and safety-critical control-loop protections. |
| NERC CIP | NERC / FERC | Critical Infrastructure Protection Standards (Bulk Electric System) | Supports BESS owners in meeting requirements for CIP-005 (Electronic Security Perimeters), CIP-007 (System Security Management), and CIP-010 (Configuration Change Management). |
| NIS2 Directive | European Union | Cybersecurity Requirements for Essential & Important Entities | Assists European energy storage and data center operators in establishing supply chain risk management, incident notification, and vulnerability handling workflows. |
| DOE C2M2 | U.S. Dept of Energy | Cybersecurity Capability Maturity Model | Structured assessment framework evaluating cybersecurity maturity across asset management, threat monitoring, and response capabilities. |
| UL 2900 | Underwriters Laboratories | Software Cybersecurity for Network-Connectable Products | Guidance for evaluating battery inverter and BMS vendor firmware against known vulnerabilities, malware, and software weaknesses. |
*Note on Certification Credibility: Battery Cyber aligns its architectures, assessments, and controls with the standards listed above. We assist asset owners in preparing for, documenting, and maintaining compliance audits. We make no false or unverified claims of third-party certifications.
Responsible Disclosure
Vulnerability Reporting & Security Contact
Battery Cyber takes the security of our website, platform, and client ecosystems with utmost seriousness. If you believe you have discovered a security vulnerability in any Battery Cyber system, we encourage responsible, coordinated disclosure.
Our Disclosure Policy:
- We will acknowledge receipt of your report within 24 business hours.
- We ask that you provide a detailed technical description and reproducible steps.
- We ask that you do not access, modify, or destroy customer or operational data.
- We ask that you do not execute denial-of-service (DoS) attacks or disrupt electrical power operations.
- We will work cooperatively with you to understand, remediate, and validate the issue before public disclosure.