Security your auditor can check.
How Amplyra GridSteward protects utility data: what is in place today, how your team can verify it, and what we have not done yet. Last reviewed October 4, 2026.
Four controls that do the heavy lifting.
Permissions on the server
27 roles, from dispatcher to administrator. Every action is checked on the server, not just hidden in the screens.
Locked-down data
Row-level security is switched on for every table in the database, and file storage is private.
A chained audit trail
Every significant action is logged with who, which role and when, each entry linked to the last by a cryptographic hash.
People decide
GridSteward advises. Qualified people make every safety decision, and the software does not operate equipment.
The detail your cyber team will ask for.
| Where it runs | GridSteward runs on Lovable Cloud, which is built on Supabase (PostgreSQL). Data is stored in the United States. Our hosting providers hold their own independent certifications: Supabase reports SOC 2 Type 2, and Lovable reports SOC 2 Type II and ISO 27001. These are the vendors' certifications, not ours. |
|---|---|
| Encryption | All traffic to GridSteward uses HTTPS (TLS). Data at rest is encrypted by our database provider (AES-256). Session cookies are marked Secure and HttpOnly. |
| Who can see what | Access is by invitation only. Invitations can expire, be revoked and be limited in number, and invitation tokens are stored only as hashes. Each user holds a role, and the server checks that role's permissions on every request. Allowed and denied requests are both recorded. |
| Database | Row-level security is on for every table. Tables that hold sensitive records refuse direct browser access outright, and file storage buckets are private. |
| Sign-in | Email and password sign-in. Single sign-on with your identity provider (SAML, Microsoft Entra ID or Google Workspace) is built in and switched on as part of each utility's integration plan. |
| Audit trail | Significant actions are written to an append-only audit log: who, in which role, under which permission, what action, on which record, and when. Each entry is linked to the one before it by a cryptographic hash, and the application blocks edits and deletions of the log. |
| AI features | The assistant runs on our servers, not in your browser. Requests ask the AI provider not to store the data, and our platform vendor's data processing agreement excludes customer personal data from model training. AI output is advice for a person to review. |
What we have not done yet.
We would rather your security review hears it from us first.
- No SOC 2 report of our own yet. The Energy Circle Firm has not completed its own SOC 2 audit. Our hosting vendors' reports cover the infrastructure, not our company.
- No independent penetration test yet. We have not commissioned a third-party penetration test of GridSteward.
- Tamper-evident, not tamper-proof. The audit chain lives inside the application database. It shows when entries are altered, but it is not separate write-once storage.
What we will do for your team.
Answer your questionnaire
Send us the security questionnaire your utility uses and we will complete it, question by question.
Walk through the controls
Our engineers show your IT and cybersecurity staff the roles, audit trail and data controls in a live session.
Share our subprocessors
We will give you the current list of hosting, database and AI providers that handle data for GridSteward.
Talk to an engineer, not a form.
Write to engineering@theenergycirclefirm.com and an engineer will reply.