Security & Operational Trust

Security and accountability built into operations.

Authentication, role-based access, protected credentials and audit records help operators maintain control across sites, portfolios and market workflows.

Operational controls

Identity, authority and evidence across every workflow.

Authentication

Identity and trusted devices

JWT authentication, password hashing, two-factor authentication and trusted-device flows.

Authorisation

Role and scope checks

Role and scope checks for site, installer, portfolio and market operations.

Credentials

Protected market access

Protected storage for external participant and market credentials.

Audit

Configuration and command records

Request auditing, configuration history and VPP command records.

Deployment options

Security requirements decide where responsibilities sit.

Cloud, hybrid and site-resident responsibilities should be selected against the programme’s control, connectivity, recovery and residency constraints, not as a generic infrastructure preference.

01
Define the information and command boundaries
02
Assign authority and recovery ownership
03
Identify the evidence required for approval
Request a security briefing