Data security

Cybersecurity is our priority

At CalibSun, data security is embedded in the cloud infrastructure, the CI/CD pipeline, the access control model, and the governance structure.

Solar forecasting services process sensitive operational data from photovoltaic plants ( on-site measurements, production telemetry, and irradiance records from pyranometers and sky imagers). For IPPs, utilities, and large industrial energy companies, entrusting this data to a third-party provider requires clear, verifiable cybersecurity guarantees and comprehensive security measures. Protecting sensitive data, preventing unauthorized access, and maintaining the integrity and availability of forecasting services are not optional considerations, they are core operational requirements.

Every layer of the service is designed to protect your data, reduce risk, and ensure that our client assets remain controlled and operationally available. CalibSun guarantees its process with SOC 2 Type 2 report. Using a token-based authentication via AWS Cognito and automated CVE scanning for threat detection backed by incident response planning, our IT team ensures a formalised offboarding protocol.

What Data Does CalibSun Handle?

CalibSun collects and processes real-time sensitive operational data from photovoltaic plants through multiple secure ingestion channels: a dedicated API, client-side API connections, and SFTP transfers. Identifying the types of data involved is a key part of CalibSun’s data classification and access management approach:

  • Actual production data from solar plants
  • On-site meteorological measurements from pyranometers and weather stations
  • Sky imager imagery captured by equipment provided by trusted hardware providers.

These data flows feed into CalibSun’s solar irradiance and production forecasting engine, which generates outputs delivered to clients via API or Grafana-based dashboards — both hosted on AWS cloud infrastructure managed by CalibSun.

Certification and Compliance Framework

SOC 2 Type 2: The Reference Standard for CalibSun's Security Posture

We are dedicated to providing a clear certification strategy is a practical and legal matter for any organization while managing our client’s sensitive data. CalibSun operates primarily outside Europe, serving clients across Asia, USA, China, and India. In this context, SOC 2 Type 2 is the most relevant international standard, covering the security, availability, and confidentiality of systems and data, and directly addressing customer trust, data privacy, and the prevention of unauthorized access.

The SOC 2 Type 2 certification program is currently underway. CalibSun conducted its first formal security audit in 2025 as part of the SOC 2 Type 2 preparation process.

Third-Party Access Management

CalibSun does not grant infrastructure access to external third parties. In exceptional cases, the principle of least privilege applies: access is scoped strictly to the required task and granted for the minimum necessary duration, directly limiting the attack surface associated with third-party access to sensitive systems.

Infrastructure Security

CalibSun’s approach combines enterprise-grade AWS cloud infrastructure, strict client environment isolation, and token-based authentication to ensure that sensitive data remains protected at every stage — from ingestion to delivery.

AWS: Enterprise-Grade Cloud Infrastructure

CalibSun’s forecasting service, API and Dashboards is hosted on Amazon Web Services (AWS). AWS provides the foundational security layer for CalibSun’s cloud infrastructure, including physical security, network security controls, and certified data centre operations. AWS was chosen by CalibSun as it’s meeting the most demanding enterprise and government standards for storage, availability, and data integrity. 

CalibSun is able to deploy its solution on any AWS region worldwide, or via edge computing for isolated or off-grid sites, depending on client requirements. This flexibility directly supports data residency, data sovereignty, and legal compliance obligations, addressed in detail on the dedicated [Data Sovereignty page].

Client Environment Isolation and Network Security

Each client’s environment is operated with strict isolation from other client environments. CalibSun’s network security model ensures that sensitive data processed for one client is not accessible in any other client context, preventing unauthorized access, data corruption, and cross-client data breaches. This isolation is maintained without requiring clients to understand the underlying technical implementation, the guarantee is operational and contractual.

Access Control, Authentication, and Identity Management

Preventing unauthorized access to sensitive data starts with robust identity and access management. Access to CalibSun’s API is secured through token-based authentication via AWS Cognito (a multi-factor authentication-ready identity solution that protects against unauthorized access and common credential-based attacks).

For client-side data transmission, CalibSun uses pre-signed URLs, which provide temporary, permission-controlled access windows for each secure data transfer, limiting exposure, preventing unauthorized reuse, and reducing the risk of data loss through misconfigured access controls.

Secure Data Transfer, Encryption, and Data Privacy

All data exchanged between clients and CalibSun’s infrastructure is protected in transit through industry-standard security measures:

  • HTTPS for API exchanges, combined with token-based authentication and pre-signed URLs,  ensuring data encryption in transit and protecting against interception attacks
  • SFTP for clients requiring a file-based secure transfer protocol, providing encrypted and authenticated file exchange


These measures protect sensitive data from unauthorized access, social engineering vectors targeting transfer endpoints, and network-level threats. Secrets and credentials management is handled at the infrastructure level and is not detailed publicly.

Resilience, Recovery, and Data Continuity

CalibSun’s resilience model ensures data integrity, service continuity, and rapid recovery, designed to meet the availability and backup requirements of critical energy infrastructure.

Backup & Recovery

AWS RDS automated backup allows us to backup our database anytime with minimal data lost to ensure a reliable recovery.

Service Availability

AWS multi-AZ architecture, continuous operation, no single point of failure.

Data Continuity

SOC 2-aligned retention policies, integrity and availability guaranteed by design.

Security Commitments at a Glance

CalibSun’s security strategy,  covering infrastructure security, secure data transfer, vulnerability management, resilience, and compliance best practices , and what clients can concretely expect in practice.

Area

CalibSun's Approach

Certification

SOC 2 Type 2 in progress (via Vanta)

Security audit

First formal audit completed in 2026

API authentication

Token-based via AWS Cognito + pre-signed URLs

Secure data transfer

HTTPS and SFTP — encryption in transit

Cloud infrastructure

AWS multi-AZ, region-specific deployment

CVE and vulnerability detection

Continuous automated scanning via Vanta

Secure development

Test environments+ mandatory peer review

Access rights management

Granular per-client control

Data retention and backup

SOC 2-aligned, AWS RDS automated backup

Contact

For any cybersecurity enquiry, compliance documentation request, security assessment, or to discuss specific security requirements contact us !

Markets