Trust and assurance

Security standards.

ENERGE TWIN is designed to connect operational evidence without weakening the boundaries, approvals and accountability already protecting an estate. Controls are selected for the deployment context and shared responsibilities are documented.

01

Identity and access

Role-aligned permissions, account lifecycle controls and protected sessions limit access to authorised work.

02

Data and integrations

Approved interfaces, classified evidence and managed secrets protect connected information flows.

03

Operational resilience

Monitoring, response and recovery practices support continuity while preserving human control.

01
Control model

Security and shared responsibility

CEBS Worldwide is responsible for controls within the ENERGE TWIN service boundary. Customers remain responsible for their users, devices, source systems, networks, local operating procedures and the authority granted to integrations.

The exact boundary, hosting arrangement and assurance evidence are confirmed during technical and commercial due diligence.

02
Authorisation

Least privilege and role design

  • Grant access according to job responsibility and operational need
  • Separate administrative, analytical and ordinary user permissions
  • Limit property and organisation visibility to authorised scopes
  • Review elevated access and remove permissions that are no longer required
03
Account security

Account lifecycle and session protection

Account creation, authentication, session handling, password controls and access removal are managed according to the deployment design. Customers should notify the authorised administrator promptly when a user's role or employment changes.

04
Tenant boundaries

Environment and customer separation

Customer and property contexts are logically separated through application permissions and data scopes. Test, development and production activities should be controlled to reduce unintended access or change.

05
Connectivity

API and integration controls

  • Use approved and documented interfaces
  • Apply least-privilege service permissions
  • Validate source, destination and data purpose
  • Protect against unauthorised requests and malformed input
  • Review connected systems when configuration changes
06
Information protection

Encryption and secrets

Credentials, tokens, certificates and integration secrets must be stored and transmitted through approved mechanisms. Encryption controls for data in transit and at rest are selected according to the hosting service, data classification and contractual scope.

07
Product engineering

Secure development and change control

Changes should be reviewed, tested and released through controlled processes. Security requirements are considered in design, dependency management, configuration and deployment activities.

Material production changes should be traceable to an authorised change and have an appropriate validation or rollback approach.

08
Detection

Logging and monitoring

Relevant authentication, administrative, integration and service events may be logged to support operations, security review and incident investigation. Log access and retention are governed by purpose, risk and applicable agreements.

09
Exposure management

Vulnerability management

Known vulnerabilities are assessed according to relevance, exploitability and potential impact. Remediation priority considers the affected component, available mitigations and operational risk.

Third-party libraries and service dependencies are reviewed as part of normal product maintenance.

10
Response

Security incident management

Suspected incidents are triaged, contained, investigated, documented and recovered through an agreed response process. Evidence is preserved where appropriate, lessons are tracked, and communications follow contractual and applicable legal requirements.

The process supports risk-based notification duties, including the UK and EU 72-hour supervisory-authority framework, Singapore PDPA notification where significant harm or scale thresholds are met, and applicable US federal or state breach requirements.

11
Continuity

Recovery and service resilience

Backup, recovery and continuity controls are chosen for the deployed service and its criticality. Recovery objectives and service commitments are only binding where confirmed in a signed agreement.

12
Operational boundaries

Safety and human control

ENERGE TWIN supports monitoring, explanation, simulation and governed decision-making. It does not imply autonomous authority over physical equipment. Any control integration must be explicitly designed, authorised, tested and operated under the customer's safety procedures.

Modelled recommendations must be reviewed by appropriately qualified people before implementation.

13
Supply chain

Hosting and supplier assurance

Hosting providers and supporting suppliers are assessed according to the service they provide and the information they handle. Applicable data location, subprocessor and assurance information is confirmed for the relevant engagement.

14
Privacy engineering

Data protection by design

New processing, integrations and material changes are assessed for purpose, data minimisation, access, retention, transfer and security risk. A documented data protection or privacy impact assessment is completed where applicable law or the level of risk requires one.

Security controls support obligations under the UK GDPR, EU GDPR, applicable US privacy and breach laws, and Singapore PDPA. The applicable control set depends on the deployment and does not imply certification unless expressly documented.

15
Governance

Assurance, training and records

  • Assign accountable owners for security and personal-data handling
  • Provide role-appropriate security and privacy training
  • Maintain records of processing, incidents, access and material changes where required
  • Review control effectiveness and remediate identified gaps
  • Support lawful regulator, customer and data-subject enquiries
16
Evidence

Customer assurance and limitations

Security questionnaires, architecture discussions and available assurance material can be provided during a qualified engagement, subject to confidentiality and relevance.

This page describes security principles. It does not claim a certification, guarantee uninterrupted service or replace the controls and commitments stated in a customer agreement.

Security is a shared operational discipline

Strong outcomes depend on ENERGE TWIN controls, secure customer systems, accurate role management and safe operating procedures working together.

ENERGE TWIN by CEBS Worldwide

Need more information?

Speak with our team about the website, platform or your assurance requirements.

Contact the ENERGE TWIN team