Principles
- Read-only by default. The platform reads data from installations and changes no settings, setpoints or dispatch without an explicit, separate instruction.
- No access by default. Permissions are granted per organisation and per resource. Anything not explicitly allowed is denied.
- One policy for screen and server. The same permission policy decides what you see in the interface and which data the server returns. Live connections go through the same check.
Hosting and data location
The platform, database and files run at OVHcloud in the EU, in a data centre in Poland. Customer data is stored in the EU. Only for AI features and email is the necessary information sent to providers outside the EU.
Our privacy policy lists the other parties that process data.
Encryption
- All traffic to the website, platform and API is encrypted over HTTPS (TLS). The website also enforces this with HSTS.
- Backups are kept on separate storage in the EU.
- Credentials for manufacturer portals stay on the server and are never sent to the browser. Additional encryption for them is planned.
Accounts and access
- Passwords are never stored readably, only as a hash using a modern, slow hashing algorithm.
- Each organisation is logically separated. The server checks every request against organisation and role.
- Customer administrators decide who gets access and with which role.
- Two-factor authentication is planned.
- Only the platform's administrators have access to production data.
Manufacturer integrations
Where a manufacturer offers it, we connect through the official API using OAuth and the owner's consent, as with SMA. We only request the permissions monitoring needs. An owner can withdraw consent at any time in the manufacturer's portal.
Backups and continuity
We make daily backups and keep them for 30 days on separate storage in the EU. We test restores every quarter.
We show missing measurements as missing, never as zero, so a broken integration is noticed straight away.
AI processing
AI features only receive the data needed for the question, within the user's permissions. Customer data is not used to train third-party models. AI features cannot control installations.
Incidents and data breaches
We log security-relevant events and investigate anomalies. If an incident affects customer data, we inform the customers concerned without undue delay and within 24 hours of confirming it. That lets them meet their own reporting duties, including under NIS2 and the Dutch Cyberbeveiligingswet. Where required, we report data breaches to the Dutch Data Protection Authority within 72 hours.
Certification
We do not currently hold ISO 27001 or SOC 2 certification. We align our processes with ISO 27001. Energy-sector customers can request our security questionnaire and data processing agreement.
Report a vulnerability
Found a vulnerability? Report it confidentially to security@alphamonitoring.app. We follow the Dutch NCSC's Coordinated Vulnerability Disclosure guideline.
How it works:
- Describe the issue and how to reproduce it. Include your contact details.
- We acknowledge your report within 3 working days and keep you updated on the fix.
- Don't disclose the vulnerability publicly before we have fixed it, and no later than 60 days after your report unless we agree otherwise.
- Don't exploit the vulnerability further than needed to demonstrate it. Don't view, change or delete other people's data. Don't run denial-of-service, social engineering or physical attacks, and don't test against customer installations.
- If you follow these rules, we won't report you to the police and, if you like, we'll credit you with the fix.
These rules cover alphamonitoring.app and its subdomains. Our security contact details are also in /.well-known/security.txt.