Security, compliance, and resilience for critical energy and utility workflows

PowerClerk® brings together independently validated controls, secure cloud architecture, resilient operations, and responsible governance to protect sensitive data, support compliance expectations, and keep critical energy workflows operating with confidence.

Security engineer checking setup
AICPA SOC
ISO/IEC 27001:2022 Certification

Security and compliance

PowerClerk combines independently validated controls, recognized security attestations and certifications, and mature security and governance practices to protect sensitive information and support organizational security and compliance requirements.

  • SOC 2 Type II – An independent audit that demonstrates the effectiveness of Clean Power Research’s controls supporting the security, availability, and confidentiality of PowerClerk throughout the examination period.
    Request SOC 2 Type II Report
  • ISO/IEC 27001 – An internationally recognized certification that validates Clean Power Research’s information security management system (ISMS) and its ongoing commitment to information security and risk management.
    Request ISO/IEC 27001 Certification
  • Consumer data privacy – Compliance with the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), General Data Protection Regulation (GDPR), and other applicable privacy requirements to support the protection of personal information.
  • Independent security assessments – Periodic third-party audits and assessments validate the effectiveness of security controls and support continuous improvement.

​Data protection

Technical and administrative safeguards protect customer data throughout its lifecycle while supporting privacy, integrity, and availability requirements.

  • Encryption at rest and in transit – Data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256. Secure data exchange options, including APIs and SFTP, support protected data transfer between connected systems. 
  • Protection for sensitive data – Layered administrative technical controls, including governed access, additional encryption, and other safeguards, protect sensitive customer data.
  • Data ownership – All customer data remains their exclusive property. Customer data is not shared with third parties for unrelated commercial purposes.
Security badge with arrow circling
Noun AI Security icon

AI security and governance

PowerClerk supports secure, governed use of AI-enabled capabilities through privacy controls, human oversight, and built-in safeguards.

  • Privacy and data-use controls – Customer data is not used to train or fine-tune generative AI models or shared with model providers.
  • Opt-in AI features – Maintain control over AI deployment by choosing where it is used and who can access AI-enabled capabilities.
  • Human oversight – Human-in-the-loop processes help maintain accountability and control in AI-enabled workflows.
  • AI safeguards – Built-in protections help reduce risks such as harmful content, prompt injection, and unreliable outputs.

Explore AI capabilities in PowerClerk

​Identity and access management

PowerClerk applies strong authentication and authorization controls that ensure users can access only the information necessary for their role and responsibilities.

  • Role-based access controls (RBAC) – Flexible permissions allow organizations to govern access to information and functionality across internal and external stakeholders while applying the principle of least privilege.
  • Multi-factor authentication (MFA) – Additional authentication factors help protect accounts and reduce the risk of unauthorized access. 
  • Single sign-on (SSO) – Customer organizations can centrally manage access and roles and provide users with a seamless login experience using SAML and OIDC.
Person working on setting up software on computer
Cloud computing

Secure, scalable software infrastructure

PowerClerk is a cloud-based SaaS platform hosted on Amazon Web Services (AWS) and architected to support the security, availability, and scalability needs of critical workflows.

  • Cloud-native, multi-tenant SaaS platform hosted on AWS – PowerClerk is hosted across multiple AWS Availability Zones, which utilize distinct data centers, and is designed according to established cloud architecture and security best practices.
  • Continuous security monitoring and threat protection – Continuous monitoring, endpoint detection and response (EDR), and intrusion detection and prevention systems (IDS/IPS) help detect, investigate, and respond to suspicious activity.
  • Vulnerability scanning and independent penetration testing – Monthly vulnerability scans and annual third-party penetration testing help identify potential vulnerabilities and security risks, supporting the ongoing security of the platform.

​Reliability and business continuity

Resilient infrastructure, tested recovery procedures, and ongoing operational planning support the continuity of critical business operations.

  • Highly available architecture – Cloud architecture following the principles of the AWS Well-Architected Framework is designed for high availability and consistently achieves 99.9% or greater monthly uptime.
  • Multiple availability zones – Workloads and standby services are distributed across multiple AWS Availability Zones, leveraging separate physical data centers to support resiliency and availability, and protect against localized disruptions.
  • Daily backups and restoration testing – Daily backups support data recovery, while periodic restoration testing helps verify backup integrity and recoverability. 
  • Geographically redundant backups – Offsite backups are stored in a different geographic region, providing an additional layer of protection against service outages and regional disruptions. 
  • Disaster recovery and business continuity planning – Disaster recovery and business continuity plans are reviewed and tested at least annually to maintain operational readiness. 
  • Security incident response – A documented incident response plan aligned with NIST incident response principles is periodically reviewed and tested and includes procedures for detection, containment, eradication, recovery, and post-incident analysis. 
Globe with coverage arrows circling
Handshake of trust

A company-wide culture of security

At Clean Power Research, protecting customer information and maintaining the security of our services is fundamental to everything we do. We are committed to meeting the security, compliance and risk management expectations of our customers and partners. Security is integrated into how all Clean Power Research employees design, develop, operate, and support PowerClerk.

  • Strong employee access controls – Employees use multi-factor authentication, including physical and virtual security tokens to access physical sites, company networks, cloud infrastructure and privileged accounts.
  • Regular training and awareness testing – Employees complete annual security training with additional role-specific technical topics for software development and operations teams. Simulated phishing exercises reinforce awareness throughout the year.
  • Change management – A documented change management process follows industry best practices and includes request tracking, design reviews, peer code reviews, testing, and formal approval of production changes.
  • Software testing – Each release undergoes extensive automated and manual testing before approval for production deployment.
  • Risk management – A formalized enterprise risk management program identifies, evaluates, monitors, and mitigates risks across the organization, information systems, and third-party vendors and partners.
  • Vulnerability monitoring – Software dependencies and supporting infrastructure are monitored for vulnerabilities. Security patches are applied according to an established maintenance cadence, with accelerated remediation of applicable high severity issues.