Security & human authority

Plant evidence.
Human decisions.

EnergieUs connects operating information to the people responsible for the plant. This page explains the current service, its data handling and the controls to review before deployment.

Last reviewed · Current service overview

Operating boundary

Decision support, not autonomous control.

The current application has no DCS, PLC, SIS, ESD or SCADA command or write-back path. It reads uploaded or received operating observations. Simulator controls affect the model only.

Ask Plant can create or update workspace records and drafts within the user's permitted scope. This does not authorise field work or plant changes. Operational and engineering decisions remain with authorised personnel under the site's procedures.

Current controls

Access and information handling

Individual access by invitation

Public self-registration is disabled. An authorised administrator reviews requests and issues a plant-specific invitation. Users sign in with individual accounts; passwords are hashed and browser sessions use secure, HttpOnly cookies in production.

Explicit plant membership

Access depends on assigned plant membership or ownership, not a matching company name. Plant records are kept in separate site stores. Backend role and ownership checks protect administrative actions and controlled document uploads.

Document access follows plant membership. Separate per-document confidentiality groups are not currently offered.

Transport and hosting

The service is hosted on Render and served over HTTPS. Production responses enable browser security headers. Render documents encryption at rest for persistent disks and their snapshots.

These are hosting-provider controls, not a claim of EnergieUs certification or customer-managed encryption keys. Render disk protection · TLS documentation

Traceability and administration

Source locators connect results to retained evidence. Selected administrative and workspace actions are recorded in a site audit history. Authorised administrators manage invitations, plant configuration and supported data controls.

The current audit history is bounded and is not a complete, immutable security audit service.

Privacy & AI processing

What leaves the workspace

Question and relevant plant evidenceExternal AI processingResponse or draft in EnergieUs

AI features use the OpenAI API. Requests may include your question, conversation context, document excerpts, tag information and operating values. Visual analysis may send drawing pages, screenshots or image crops. When external research is used, search queries may also leave the service. Upload only information your organisation authorises for this processing.

OpenAI states that API inputs and outputs are not used for model training by default, unless the API account explicitly opts in. Provider retention depends on the endpoint and account settings; abuse-monitoring logs may normally be retained for up to 30 days, with exceptions. We do not promise zero retention or a particular processing region. Read OpenAI's data controls.

EnergieUs retains uploaded files, extracted evidence, operating records and saved workspace outputs to support subsequent work. Retention is not currently governed by a universal automatic deletion schedule. Removing a visible record does not establish deletion from every derived index, provider system or backup.

For an export, deletion request or deployment-specific data review, contact admin@energieus.com with your organisation and request type. We will verify your authority and agree the scope; do not email credentials or plant archives. This overview does not replace agreed contractual terms.

Before enterprise rollout

Confirm the requirements for your site.

MFA and SSO are roadmap requirements, not current features. Formal retention schedules, recovery targets and restore evidence, provider data settings, and any additional access or audit requirements need an agreed deployment review.

Live historian connectivity also requires site-specific validation of service authentication and the network boundary. A configured connector is not proof of a commissioned OT connection. The current service is not presented as a validated multi-instance enterprise deployment.

We make no claim of EnergieUs SOC 2, ISO 27001, IEC 62443 or IRAP certification or assessment.

Discuss your deployment requirements