A Deep Commitment to Protecting Your Data
Clean Power Research's comprehensive information security system complies with leading industry standardsIntroduction
At Clean Power Research®, protecting customer information and maintaining the security of our services is fundamental to everything we do. We are committed to meeting the security, compliance and risk management expectations of our customers and partners. We maintain a comprehensive Information Security Management System (ISMS) supported by strong security governance, risk management and operational security controls designed to protect our systems, services and customer data.
Clean Power Research’s information security program is independently validated through ISO/IEC 27001:2022 certification and annual SOC 2 Type II examinations. These independent assessments provide assurance that information security controls are integrated into our organizational processes, information systems and governance practices, and that they are regularly evaluated to ensure they operate as intended. Learn more about ISO/IEC 27001 certification and SOC 2 Type II attestation by clicking the links below:
Each year, an independent third-party audits Clean Power Research’s ISMS for compliance with ISO/IEC 27001:2022 and SOC 2 Type II. To request a copy of the latest audit results, please contact us.
ISO/IEC 27001:2022 Certification
Clean Power Research cloud software services comply with the ISO/IEC 27001:2022 standard as confirmed by certification from an independent auditor.
The ISO/IEC 27001 standard provides guidance for establishing, implementing, maintaining and continually improving an ISMS that manages and protects sensitive information, and reduces the risk of data breaches, cyber attacks and other security incidents.
The ISO/IEC 27001 standard, developed by the International Organization for Standardization (ISO), is internationally recognized as the leading standard for information security management.
To request a copy of the Clean Power Research ISO/IEC 27001:2022 certification, please contact us.
SOC 2 Type II Attestation
Clean Power Research cloud software services comply with Service Organization Controls (SOC) 2 Type II standards for operational security, availability and confidentiality, as confirmed by an annual attestation from an independent auditor.
Developed by the American Institute of Certified Public Accountants (AICPA), the SOC 2 framework serves as a standard for controls that maintain the confidentiality and privacy of information stored and processed in the cloud. This aligns with the International Standard on Assurance Engagements (ISAE), the reporting standard for international service organizations.
A SOC 2 Type II attestation describes the security system and assesses the fairness of the service provider’s description of its controls. It also evaluates whether the service provider’s controls are designed appropriately and were operating effectively over a specified time period.
To request a copy of the latest SOC 2 or SOC 3 (a SOC 2 summary) report, please contact us.
Report a Security Vulnerability
At Clean Power Research, the security of the services we provide to our customers is our utmost priority. If you believe you have found a security vulnerability in one of our products, we strongly encourage you to report it directly to us as soon as possible. We will investigate all legitimate reports and work on a fix in a timely manner, based on the potential impact and severity of the issue.
We ask everyone reporting a security vulnerability to follow a responsible disclosure by giving us reasonable time to investigate and remediate the issue before sharing any of that information with others.
While we encourage reporting any security vulnerabilities found to Clean Power Research, it is expressly prohibited to take any action against our products that intentionally violates applicable laws or regulations. This includes probing our systems to discover security vulnerabilities, and any actions that may negatively impact Clean Power Research, our products or users of our products.
To report a security vulnerability to Clean Power Research, please email us at security@cleanpower.com with your contact information and details about the vulnerability so that we can validate and reproduce the issue.
Frequently Asked Questions
Which Clean Power Research software services are covered by information security audits?
Clean Power Research’s ISO/IEC 27001:2022 certification and SOC 2 Type II attestations cover the products and services in the PowerClerk®, SolarAnywhere®, WattPlan® and FleetView® families.
Who performs the independent, third-party audits of Clean Power Research’s information system?
The entity performing security audits for Clean Power Research is Baker Tilly (formerly Moss Adams LLP).
How long is the ISO/IEC 27001:2022 certification valid for?
How often are the Clean Power Research SOC Type II Reports issued?
Are there any requirements to receive Clean Power Research security documentation?
The ISO/IEC 27001:2022 certificate and the SOC 3 report (which is a summary of the SOC 2 report) are available upon request validation.
SOC 2 Reports are provided based on legitimate business need. However, to receive a SOC 2 report, your organization will need to enter into a specific, one-way non-disclosure agreement (NDA) with Clean Power Research.
What is the difference between a SOC 2 and SOC 3 report?
Request Security Information
To receive more information about Clean Power Research Security Information assessments, please fill out the form below.