Identity and access
Role-aligned permissions, account lifecycle controls and protected sessions limit access to authorised work.

Hotels & HospitalityGuest comfort and estate performance
Office BuildingsOccupancy-led performance
Retail & MallsTrading-hours intelligence
UniversitiesCampus-wide energy decisions
Wellness CentresWater, humidity and comfort
Residential CommunitiesHomes and shared infrastructure
Airports & TerminalsContinuous terminal operations
Data CentresCooling, power and resilience
Utilities & District EnergyGeneration, storage and demand
Ports & LogisticsCargo-linked energy operations
ManufacturingProduction-linked intelligence
Food & Cold ChainTemperature-assured optimisationENERGE TWIN is designed to connect operational evidence without weakening the boundaries, approvals and accountability already protecting an estate. Controls are selected for the deployment context and shared responsibilities are documented.
Role-aligned permissions, account lifecycle controls and protected sessions limit access to authorised work.
Approved interfaces, classified evidence and managed secrets protect connected information flows.
Monitoring, response and recovery practices support continuity while preserving human control.
CEBS Worldwide is responsible for controls within the ENERGE TWIN service boundary. Customers remain responsible for their users, devices, source systems, networks, local operating procedures and the authority granted to integrations.
The exact boundary, hosting arrangement and assurance evidence are confirmed during technical and commercial due diligence.
Account creation, authentication, session handling, password controls and access removal are managed according to the deployment design. Customers should notify the authorised administrator promptly when a user's role or employment changes.
Customer and property contexts are logically separated through application permissions and data scopes. Test, development and production activities should be controlled to reduce unintended access or change.
Credentials, tokens, certificates and integration secrets must be stored and transmitted through approved mechanisms. Encryption controls for data in transit and at rest are selected according to the hosting service, data classification and contractual scope.
Changes should be reviewed, tested and released through controlled processes. Security requirements are considered in design, dependency management, configuration and deployment activities.
Material production changes should be traceable to an authorised change and have an appropriate validation or rollback approach.
Relevant authentication, administrative, integration and service events may be logged to support operations, security review and incident investigation. Log access and retention are governed by purpose, risk and applicable agreements.
Known vulnerabilities are assessed according to relevance, exploitability and potential impact. Remediation priority considers the affected component, available mitigations and operational risk.
Third-party libraries and service dependencies are reviewed as part of normal product maintenance.
Suspected incidents are triaged, contained, investigated, documented and recovered through an agreed response process. Evidence is preserved where appropriate, lessons are tracked, and communications follow contractual and applicable legal requirements.
The process supports risk-based notification duties, including the UK and EU 72-hour supervisory-authority framework, Singapore PDPA notification where significant harm or scale thresholds are met, and applicable US federal or state breach requirements.
Backup, recovery and continuity controls are chosen for the deployed service and its criticality. Recovery objectives and service commitments are only binding where confirmed in a signed agreement.
ENERGE TWIN supports monitoring, explanation, simulation and governed decision-making. It does not imply autonomous authority over physical equipment. Any control integration must be explicitly designed, authorised, tested and operated under the customer's safety procedures.
Modelled recommendations must be reviewed by appropriately qualified people before implementation.
Hosting providers and supporting suppliers are assessed according to the service they provide and the information they handle. Applicable data location, subprocessor and assurance information is confirmed for the relevant engagement.
New processing, integrations and material changes are assessed for purpose, data minimisation, access, retention, transfer and security risk. A documented data protection or privacy impact assessment is completed where applicable law or the level of risk requires one.
Security controls support obligations under the UK GDPR, EU GDPR, applicable US privacy and breach laws, and Singapore PDPA. The applicable control set depends on the deployment and does not imply certification unless expressly documented.
Security questionnaires, architecture discussions and available assurance material can be provided during a qualified engagement, subject to confidentiality and relevance.
This page describes security principles. It does not claim a certification, guarantee uninterrupted service or replace the controls and commitments stated in a customer agreement.
Strong outcomes depend on ENERGE TWIN controls, secure customer systems, accurate role management and safe operating procedures working together.
Speak with our team about the website, platform or your assurance requirements.
Contact the ENERGE TWIN team