Cybersecurity

Cybersecurity

Cybersecurity

Encrypted end to end.

Yours to keep, or to take with you.

Enterprise energy data is operational data, and Smarkia treats it that way. Every signal is encrypted end to end, our information-security operations are certified to ISO/IEC 27001, and nothing about the platform locks you in. You own your data, you own your export, and you can take control back in one click.

The trust boundaryEncrypted
SystemsYour BMS, meters, controlsOwned
TLS 1.2+Encrypted, both waysSecure
SmarkiaISO 27001, your exportCertified
Encrypted end to endTLS 1.2+

What's at stake

Energy data is

operational data.

Meters, setpoints, and schedules describe how your business actually runs, and nobody should own it but you.

What's at stake

Energy data is

operational data.

Meters, setpoints, and schedules describe how your business actually runs, and nobody should own it but you.

Untrusted transport

Signals moving in the clear, or only half-encrypted between systems, leave operational data on the wire for anyone paying attention.

Untrusted transport

Signals moving in the clear, or only half-encrypted between systems, leave operational data on the wire for anyone paying attention.

Untrusted transport

Signals moving in the clear, or only half-encrypted between systems, leave operational data on the wire for anyone paying attention.

Vendor-owned data

Platforms that hold your data hostage and charge to export it are one contract dispute away from walking off with your baseline.

Vendor-owned data

Platforms that hold your data hostage and charge to export it are one contract dispute away from walking off with your baseline.

Vendor-owned data

Platforms that hold your data hostage and charge to export it are one contract dispute away from walking off with your baseline.

Security by assertion

A reassuring sentence on a website is not a control. Real security is built into the platform and provable, not asserted.

Security by assertion

A reassuring sentence on a website is not a control. Real security is built into the platform and provable, not asserted.

Security by assertion

A reassuring sentence on a website is not a control. Real security is built into the platform and provable, not asserted.

How it works

Secure by design,

provable by audit

The security posture isn’t a line in a brochure. It’s how the platform is built and run.

How it works

Secure by design,

provable by audit

The security posture isn’t a line in a brochure. It’s how the platform is built and run.

Encrypt

Every signal travels over TLS 1.2+, both directions, and is stored AES-256 encrypted at rest. No half-secured links, no cleartext fallbacks.

Background
Control

Access follows least privilege, role-based, with MFA on every remote connection. Start in read-only mode, and hand full control back to your team in one click, any time.

Background
Prove

Every access is logged and a 24/7 security team is watching, with a documented incident-response plan you can review. Security you can verify, not just take on trust.

Background

How we secure it

The controls your

security team will ask about.

A short overview of how the platform is secured, hosted, and operated. The full security overview is a click away.

How we secure it

The controls your

security team will ask about.

A short overview of how the platform is secured, hosted, and operated. The full security overview is a click away.

Background

Site BMS

Integration

Permissions

Read

Write

Site BMS

Integration

Permissions

Read

Write

Encryption and access

TLS 1.2+ in transit, AES-256 at rest, least-privilege role-based access, and multi-factor authentication on every remote connection.

  • TLS 1.2+

  • AES-256

  • MFA

  • RBAC

  • OAuth2

Baseline set

IPMVP · 12-month

Cloud and resilience

Hosted on Microsoft Azure across multiple availability zones, over Microsoft's private backbone, with high-availability SLAs and Tier IV grade facilities.

Baseline set

IPMVP · 12-month

Cloud and resilience

Hosted on Microsoft Azure across multiple availability zones, over Microsoft's private backbone, with high-availability SLAs and Tier IV grade facilities.

Baseline set

IPMVP · 12-month

Cloud and resilience

Hosted on Microsoft Azure across multiple availability zones, over Microsoft's private backbone, with high-availability SLAs and Tier IV grade facilities.

Man typing on a keyboard beside a desktop monitor

Security operations

A 24/7 security operations team under an ISO/IEC 27001 certified management system, with documented incident response, monthly critical patching, and continuous vulnerability scanning.

Man typing on a keyboard beside a desktop monitor

Security operations

A 24/7 security operations team under an ISO/IEC 27001 certified management system, with documented incident response, monthly critical patching, and continuous vulnerability scanning.

Man typing on a keyboard beside a desktop monitor

Security operations

A 24/7 security operations team under an ISO/IEC 27001 certified management system, with documented incident response, monthly critical patching, and continuous vulnerability scanning.

Security overview

Want the detail? The full security overview: architecture, encryption, hosting, and operations, ready to share with your security team.

Background

Security overview

Want the detail? The full security overview: architecture, encryption, hosting, and operations, ready to share with your security team.

Background

Why Smarkia

Why security teams sign off.

Why Smarkia

Why security teams sign off.

FAQs

Do you have any questions?

Here are the answers.

FAQs

Do you have any questions?

Here are the answers.

FAQs

Do you have any questions?

Here are the answers.

How does Smarkia secure our energy data?

Smarkia encrypts every signal end to end and runs a dedicated information-security operation around it. Energy data is operational data, and Smarkia protects it with the same rigor as any critical business system.

Who owns the data in Smarkia?

You do. Meters, setpoints, and schedules describe how your business runs, and with Smarkia that data stays yours to keep or to take with you if you leave. Smarkia does not lock your operational data in.

Can we export our data out of Smarkia?

Yes. Your data is portable by design, so you can take it with you at any time. Smarkia is built so ownership and access always stay with the customer.

What security practices does Smarkia follow?

Smarkia applies end-to-end encryption, continuous security monitoring, and least-privilege access to every site it connects. Security is handled by a dedicated operations function rather than left as an afterthought.

Does connecting Smarkia expose our building controls to risk?

No. Smarkia communicates over encrypted channels and is designed to read and send setpoints without opening your control systems to outside access. Protecting the systems it optimizes is part of the design.

Where is our data stored and who can access it?

Access is restricted to the people and services that need it, governed by least-privilege controls, and every action is auditable. Your operational data is never shared or sold.

What happens to our data if we stop using Smarkia?

It remains yours. You can export everything and take it with you, because Smarkia is built so the data always belongs to the customer, not the platform.

Explore

Go deeper into

the platform.

Connectivity, cybersecurity, compliance, and AI. Everything Smarkia does runs from the same place, on top of the systems you already have.

Explore

Go deeper into

the platform.

Connectivity, cybersecurity, compliance, and AI. Everything Smarkia does runs from the same place, on top of the systems you already have.

Explore

Go deeper into

the platform.

Connectivity, cybersecurity, compliance, and AI. Everything Smarkia does runs from the same place, on top of the systems you already have.

Send us your security checklist. We'll answer it line by line.

Send us your security checklist. We'll answer it line by line.

Send us your security checklist. We'll answer it line by line.