Security is at the forefront of how we operate, develop and maintain our product. We are committed to proactively secure our product within strict compliance norms.
Leveraging the resilience of cloud-based solutions, Piclo thrives on the flexibility and robustness of Amazon Web Services (AWS) infrastructure and trusted online collaboration tools.
Your data is safe with us. We utilise the highest industry standard encryption ciphers in transit and at rest.
Our environment is tested by both internal teams and our external CREST-certified security partners to ensure that any vulnerabilities are quickly remediated.
ISO27001 is an international standard setting out best practice and guidance for information security management systems. ISO27001 certification signifies our commitment to risk management, cyber-resilience and operational excellence.
The ISO9001 standard lays out quality management principles which ensure our product and services is consistently of high quality, with a strong focus on customer needs and continual improvement.
All Piclo data is safely stored in AWS data centres which apply the highest standards of security and compliance. Dependent on the region in which Piclo operates, this data will be localised for data centres in that area.
You may contact the team at security@piclo.energy
No, Piclo does not currently offer a disclosure programme. Piclo instead conducts continuous security testing with our external security provider for assurance of our product.
Piclo is registered with the UK Information Commissioner’s Office, and complies with all requirements of the UK and EU GDPR and associated regulations in the regions that we operate.
Piclo offers a secure cloud-based secure marketplace which provides a platform for energy system operators and providers to manage flexible energy supply. The security of this environment is a key aspect of all its activity, and it is therefore vital that Piclo ensures that any information security risks to its ongoing business are assessed, addressed, and mitigated. Everyone at Piclo is committed to preserving the confidentiality, integrity and availability of all the physical and electronic information assets throughout our organisation. To support this, Piclo has achieved UKAS-accredited ISO 27001 certification and is committed to the ongoing maintenance of the certification through the support of our ISMS and associated policies. Regular audits by accredited third-parties maintain the validity and effectiveness of our ISMS.
Security is the primary focus of our platform. All data traffic is secured using HTTPS/TLS 1.2+; data at rest is encrypted to AES256+ standard. The Piclo environment is held within AWS regionalised data centres, these offer the highest levels of security and availability for our platform and customer data. Our environment undergoes continuous security testing from our specialist security partners, and any findings are resolved at the earliest opportunity by our development team. We have a dedicated security team and utilise threat intelligence from recognised agencies to help us identify any potential risks, in order to take timely mitigating action.
New members of staff undertake mandatory information security training as part of their onboarding, and all staff are required to undertake regular update sessions to ensure their knowledge and understanding remains current. We utilise role-based access control to ensure that data is appropriately managed. We have a separate Privacy Notice explaining the specific arrangements in place regarding the processing of personal data.