Trust Center & Security Principles

Engineered for the rigorous demands of critical infrastructure.

When you partner with Battery Cyber to defend your energy storage or critical power assets, you entrust us with the visibility into your most sensitive operational networks. We operate under uncompromising engineering safety principles, strict customer data boundaries, and verifiable security governance.

Report a Vulnerability Standards Alignment

Operating Commitments

Core Operational Principles

Our operational safety model is founded on three immutable engineering commitments:

1. Operational Safety First

We never execute active port scans, synthetic packet flooding, or unauthorized intrusive commands on active operational networks. All telemetry collection on industrial control loops utilizes optically isolated physical taps or passive SPAN mirrors. Power availability and physical safety always supersede data collection.

2. Customer Data Boundaries

Your industrial telemetry, asset parameters, network topology schematics, and configuration files belong strictly to you. Battery Cyber never sells customer data, never trains public models on proprietary site telemetry, and provides complete on-premises air-gapped deployment options for classified or sensitive installations.

3. Verifiable Integrity

We practice radical transparency. Every remote session proxied by our platform is recorded at the visual and protocol level. Every code release is cryptographically signed, built via audited pipelines, and tested against rigorous static and dynamic analysis.

Technical Governance

Data Handling, Encryption & Access Controls

How telemetry and customer assets are protected across transit, rest, and analysis.

Encryption in Transit & at Rest

All data transmitted between site sensors and management control planes is encrypted using TLS 1.3 with mutually authenticated certificates (mTLS). In air-gapped deployments, telemetry remains confined entirely to customer-owned physical media. Stored customer metadata is encrypted at rest using AES-256 with customer-managed cryptographic keys (CMEK) supported upon request.

TLS 1.3 • mTLS • AES-256-GCM • CMEK support

Least-Privilege & Zero-Standing Access

Internal access to customer environments is governed by strict role-based access control (RBAC), multi-factor authentication (FIDO2 WebAuthn hardware keys required), and ephemeral privilege grants. No Battery Cyber engineer has permanent standing access to customer production telemetry or edge appliances.

Hardware MFA • Ephemeral grants • Immutable audit trails

Secure Software Development Lifecycle (SSDLC)

Our software and sensor firmware are developed under strict security controls: branch protection rules, mandatory peer review by senior engineers, automated static analysis (SAST), software composition analysis (SCA) for open-source dependencies, and continuous container vulnerability scanning.

SLSA-aligned pipelines • CycloneDX SBOMs • Signed commits

Deployment Isolation Options

We support three distinct deployment tiers: Dedicated Cloud (isolated tenant containers deployed across global Cloudflare edge infrastructure), Hybrid (local edge collectors with outbound-only mTLS metadata sync), and 100% Air-Gapped On-Premises (for military bases, municipal utilities, and sovereign critical sites with zero internet connectivity).

Dedicated Cloud • Hybrid DMZ • 100% Air-Gapped

Industry Benchmarks

Standards & Framework Alignment

Battery Cyber engineers its platform, services, and assessment methodologies to align precisely with international industrial cybersecurity and critical infrastructure frameworks:

Standard / Framework Issuing Body Primary Domain Battery Cyber Alignment & Application
IEC 62443 ISA / IEC Industrial Automation and Control Systems (IACS) Security Engineered to IEC 62443-3-3 (System Security Requirements) and IEC 62443-4-2 (Component Security). We help operators establish Zones, Conduits, and Security Levels (SL 1–4).
NIST SP 800-82 NIST Guide to Operational Technology (OT) Security Core reference for passive network monitoring, ICS network segmentation, and safety-critical control-loop protections.
NERC CIP NERC / FERC Critical Infrastructure Protection Standards (Bulk Electric System) Supports BESS owners in meeting requirements for CIP-005 (Electronic Security Perimeters), CIP-007 (System Security Management), and CIP-010 (Configuration Change Management).
NIS2 Directive European Union Cybersecurity Requirements for Essential & Important Entities Assists European energy storage and data center operators in establishing supply chain risk management, incident notification, and vulnerability handling workflows.
DOE C2M2 U.S. Dept of Energy Cybersecurity Capability Maturity Model Structured assessment framework evaluating cybersecurity maturity across asset management, threat monitoring, and response capabilities.
UL 2900 Underwriters Laboratories Software Cybersecurity for Network-Connectable Products Guidance for evaluating battery inverter and BMS vendor firmware against known vulnerabilities, malware, and software weaknesses.

*Note on Certification Credibility: Battery Cyber aligns its architectures, assessments, and controls with the standards listed above. We assist asset owners in preparing for, documenting, and maintaining compliance audits. We make no false or unverified claims of third-party certifications.

Responsible Disclosure

Vulnerability Reporting & Security Contact

Battery Cyber takes the security of our website, platform, and client ecosystems with utmost seriousness. If you believe you have discovered a security vulnerability in any Battery Cyber system, we encourage responsible, coordinated disclosure.

Security Contact: security@batterycyber.com
RFC 9116 security.txt: /.well-known/security.txt
Response Target: Initial acknowledgment within 24 business hours

Our Disclosure Policy:

  • We will acknowledge receipt of your report within 24 business hours.
  • We ask that you provide a detailed technical description and reproducible steps.
  • We ask that you do not access, modify, or destroy customer or operational data.
  • We ask that you do not execute denial-of-service (DoS) attacks or disrupt electrical power operations.
  • We will work cooperatively with you to understand, remediate, and validate the issue before public disclosure.