Data security that meets utility-grade requirements.
Ampgrove handles operational interval data from electric utility SCADA and EMS systems. We take the security requirements of this data seriously and have designed our platform architecture accordingly, including an on-prem deployment option for environments where OT data cannot leave the premises.
How Ampgrove protects your operational data.
Encryption in Transit
All data exchanged between your SCADA/EMS systems and Ampgrove's ingestion layer is encrypted using TLS 1.3. Connections use mutual TLS authentication where your IT environment supports it. No interval data transmits over unencrypted connections.
Encryption at Rest
All stored interval data, model artifacts, and configuration data are encrypted at rest using AES-256. Encryption keys are managed via a dedicated key management service and rotated on a defined schedule. Storage-level encryption applies to all data tiers.
Per-Tenant Data Isolation
Your utility's operational data is isolated at the infrastructure level from other customers. We do not aggregate or cross-reference interval data across utility tenants. Models are trained exclusively on your own historical data. No operational data from Utility A is accessible to Utility B's instance.
Access Controls
Operator seats authenticate via password + time-based OTP. API tokens are scoped per operator seat and can be revoked individually. Administrative access to production infrastructure is restricted to named Ampgrove employees and logged to an immutable audit trail.
OT/IT Separation Considerations
For utilities requiring strict OT network segmentation, the Ampgrove on-prem agent (Scale tier) runs inside your environment. The agent reads interval data via read-only SCADA/EMS connections, processes it locally, and serves the operator console without transmitting raw interval data outside your network perimeter.
Compliance Roadmap
Ampgrove has implemented SOC 2 Type I controls as of 2026. SOC 2 Type II certification is in progress. We do not currently hold NERC CIP certification. We can provide our security documentation, control inventory, and penetration test summary to qualified utility procurement teams on request under NDA.
What data we store, how long, and who can access it.
| Data Type | Retention | Access | Deletion |
|---|---|---|---|
| SCADA interval data (load readings) | Duration of contract + 30 days | Customer operators; Ampgrove platform processes (read-only) | On contract end or on written request |
| Trained model artifacts | Duration of contract + 30 days | Ampgrove inference layer only; not customer-accessible | With interval data on contract end |
| Forecast output data | 90 days rolling | Customer operators; API token holders | On written request |
| Dispatch recommendation history | 24 months | Customer operators; read-only via console | On written request, subject to contract minimum |
| Alert history and notifications | 24 months | Customer operators | On written request |
| Operator authentication logs | 12 months | Customer administrators; Ampgrove security team | Per regulatory retention minimum |
| Support and communication records | 3 years | Ampgrove customer success team | On written request |
Request our security documentation.
We provide a security summary, control inventory, and penetration test results to qualified utility procurement teams under NDA. Contact us with your procurement requirements and we'll respond within one business day.