Trust & security

Security-first architecture for charging operations

Encryption in transit, role-based access, and AWS-native isolation — with a formal compliance program in progress for enterprise buyers.

US security operations center with a national network map and EV charging depot outside the windows

Posture & controls

Compliance signals, architecture, and access controls

Honest certification status plus AWS-native controls your security team can review — open OCPP, gated provisioning, Cognito SSO, and operator RBAC with per-app database schemas.

SOC 2 Type II

In program · Target Q4 2026

Control framework aligned to AICPA Trust Services Criteria; formal attestation on roadmap (SEC-1)

ISO 27001

Aligned

Security management practices mapped to ISO controls — formal cert may be required for some RFPs; security briefing available

GDPR / CCPA

Ready

Data residency, access controls, and audit-friendly RDS schemas

AWS-native

Production

EKS, IoT OCPP, Cognito SSO, VPC-isolated RDS

AWS-native stack

EKS workloads, IoT OCPP gateway, Cognito SSO, and VPC-isolated RDS with a dedicated schema per application — not a shared multi-tenant grab bag.

Compliance program

SOC 2 Type II in program (target Q4 2026), ISO 27001-aligned practices, and GDPR/CCPA-ready data controls for operator and driver records.

Open standards

OCPP 1.6J in production on AWS IoT Core, OCPP 2.x on the roadmap — open protocol handoff without lock-in to a closed CSMS stack.

Defense in depth

VPN-gated onboarding, ALB-classified edge, TLS 1.2+, and RBAC across admin, operator, and viewer roles with audit-friendly change history.

  • Encryption in transit TLS on every public and private edge — console, onboarding, and OCPP gateway paths.
  • Identity & SSO Cognito-backed authentication with role mapping for platform and customer operators.
  • Network isolation Private RDS, IRSA-scoped service access, and VPC-only paths for sensitive admin surfaces.
  • Operational RBAC Least-privilege roles for fleet ops — who can commission, who can view sessions, who can change access.