Security & Trust
Enterprise-Grade Security,
Built In from Day One
All EPG Solutions software is hosted and secured on Base44's enterprise-grade platform, inheriting industry-leading certifications and controls designed for regulated industries.
Third-Party Audited Certifications
EPG Solutions is built on Base44, which holds formal independent certifications covering security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Type II
Independent audit framework evaluating the design and sustained effectiveness of security and operational controls over a 6–12 month observation period. Covers all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Request Report Under NDA →ISO 27001
International standard for managing information security and privacy controls across people, processes, and technology. Confirms a repeatable, audited process to protect data — directly aligning with NERC CIP vendor assessment requirements.
View Certificate →GDPR
Full adherence to EU General Data Protection Regulation standards including data residency controls, consent management, Standard Contractual Clauses (SCCs), and EU data protection requirements. A formal Data Processing Agreement (DPA) is available upon request.
View DPA Overview →PCI DSS (Payments)
Payment processing is handled exclusively by PCI DSS–certified providers. Sensitive payment data is encrypted in transit and never stored within the EPG Solutions or Base44 environment. Fraud and abuse controls are applied at the platform level.
View Base44 Trust Center →Bug Bounty Program
An active bug bounty program invites independent security researchers worldwide to responsibly disclose vulnerabilities. All confirmed findings are prioritized for rapid remediation according to severity. This embodies a commitment to proactive, transparent security.
Contact Bug Bounty Team →OWASP Penetration Testing
Both internal and third-party penetration tests are performed based on OWASP methodologies, simulating real-world attack scenarios to identify vulnerabilities and validate defense effectiveness. All findings are reviewed, prioritized, and remediated continuously.
View Security Details →Hosting & Security: Powered by Base44
All EPG Solutions software is built, hosted, and secured on the Base44 platform. Every application sits behind the same enterprise-grade controls Base44 maintains for its largest customers.
SSO & MFA Authentication
Enterprise SSO with multiple customer-managed identity provider (IDP) support. MFA is enforced. Google SSO and traditional email+password with anti-bot controls are also supported.
Row-Level Security (RBAC)
Granular CRUD (Create, Read, Update, Delete) permissions per user and per record at the database level. Multi-seat license tiers (1, 5, and 10 seats) are enforced with isolated access controls.
Built-In Security Scans
Automated code analysis detects hardcoded secrets and exposed API keys, validates row-level security rules, and identifies backend functions lacking proper server-side authentication — before reaching production.
Continuous Monitoring
24/7 system monitoring via DataDog with detailed audit logging of all events. Real-time alerting enables rapid incident detection and response across the entire platform infrastructure.
IP Allowlisting
Network-level access controls allow administrators to restrict workspace and application access to pre-approved IP addresses — a critical control for utility organizations requiring network perimeter security.
Secure SDLC (SSDLC)
Security is integrated at every stage of software development through threat modeling, secure design reviews, code reviews, and penetration testing. Risks are identified early and systematically resolved.
App Governance & Visibility
Workspace administrators control application visibility (Private, Workspace-only, or Public). Enterprise Governance settings define defaults for new app publishing and restrict member permissions as needed.
Third-Party Risk Management
A comprehensive TPRM program ensures all vendors comply with security and compliance standards. Vendor adherence is periodically validated to confirm ongoing alignment — directly satisfying NERC CIP-013 sub-supply chain requirements.
GitHub Integration (Extensible)
Two-way GitHub integration allows export of application code for teams with established security pipelines, enabling external security tooling and specialized compliance scanners to be run alongside built-in protections.
How Your Data Is Handled
EPG Solutions maintains a minimal data footprint. We collect only what is necessary to deliver the platform, and it is never sold or shared outside the defined subprocessor list.
Encryption at Rest & in Transit
AES-256 encryption for stored data; TLS 1.3 for all data in transit. Provided and managed by Base44 infrastructure.
No Data Selling
EPG Solutions never sells, rents, or shares client or subscriber data with third parties outside of defined platform subprocessors.
Encrypted Backups
Daily encrypted backups with 30-day retention managed by Base44, ensuring business continuity and disaster recovery capability.
Data Residency (US)
All Base44 servers are located in the United States. EU/UK data residency options are available on Elite and Enterprise plans for applicable data created after April 16, 2026.
Incident Response
Confirmed security incidents trigger a structured notification process. Security questions and breach inquiries can be directed to compliance@epgsolutions.services.
Other Business Systems (Scoped)
EPG Solutions uses standard third-party tools (HubSpot, Shopify, Calendly, etc.) for marketing, payments, and scheduling only. No subscriber or training data is shared with these systems.
Base44 Third-Party Subprocessors
The following third-party providers are used by Base44 to securely process and store data on behalf of EPG Solutions. All are bound by strict data processing agreements.
Full subprocessor directory: base44.com/dpa/exhibitc
Top 10 Questions from Utility IT & Security Teams
These are the most common questions raised during vendor security assessments by utility company IT and compliance departments.
- Base44 SOC 2 Type II report (under NDA)
- ISO 27001 certificate
- Completed vendor security questionnaire
- Data Processing Agreement (DPA)
- Completed vendor security questionnaire (VSQ)
- Base44 SOC 2 Type II report (under NDA)
- ISO 27001 certificate (Base44)
- Data Processing Agreement (DPA)
- GDPR compliance overview
- Subprocessor list with DPA coverage
Ready to Start a Vendor Security Review?
Our team can provide SOC 2 reports, completed vendor questionnaires, and custom security assessments to support your organization's procurement and compliance process.