Contents
Security is foundational to everything EnerCloud builds. We design, deploy and operate AI systems for enterprises and public institutions to the standard their regulators already hold them to.
Our controls are aligned with ISO/IEC 27001, the ACSC Essential Eight (targeting Maturity Level 3), the Information Security Manual (ISM) and IRAP assessment practices.
1. Our approach
We take a defence in depth, secure by design approach. Security is embedded from architecture through to run time operations, not retrofitted. Every engagement includes an assurance layer covering governance, observability and regulator aligned controls.
2. Governance & compliance
- Information Security Management System aligned to ISO/IEC 27001.
- Controls mapped to the ACSC Essential Eight and ISM.
- Support for IRAP-assessed workloads and SOCI Act obligations for critical infrastructure clients.
- Regular internal audits, risk assessments and independent penetration testing.
3. Data sovereignty
By default, customer data is stored and processed onshore in Australia (for example, AWS ap-southeast-2). Data residency, tenancy and segregation requirements are agreed per engagement and enforced technically.
4. Infrastructure security
- Cloud environments provisioned as code (Infrastructure as Code) with peer review and change control.
- Network segmentation, private connectivity and zero trust principles.
- Hardened baselines, timely patching and automated configuration compliance.
5. Access control
- Single sign on, multi factor authentication and role based access control.
- Least privilege access, just in time elevation and periodic access reviews.
- Full audit logging of privileged and administrative activity.
6. Data protection
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with customer managed keys available where required. We apply data minimisation, classification and secure retention and destruction practices.
7. AI assurance
For AI and agentic systems we add controls specific to models and data: evaluation harnesses, red teaming, guardrails and policy enforcement, prompt and output logging, drift monitoring, and full decision traceability to support audit, FOI and regulator review.
8. Monitoring & incident response
We operate continuous monitoring and alerting across environments and maintain a documented incident response plan. Where a data breach is likely to result in serious harm, we notify affected parties and the OAIC in line with the Notifiable Data Breaches scheme.
9. People & suppliers
Personnel undergo background checks appropriate to their role, receive ongoing security awareness training, and are bound by confidentiality obligations. Suppliers are assessed for security posture before engagement and monitored throughout.
10. Report a vulnerability
We welcome responsible disclosure. If you believe you have found a security vulnerability, please contact security@enercloud.io. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.