Security & Trust

Security & Trust Center

Enterprise-Grade Security,
Built In from Day One

All EPG Solutions software is hosted and secured on Base44's enterprise-grade platform, inheriting industry-leading certifications and controls designed for regulated industries.

SOC 2 Type II Certified ISO 27001 Certified GDPR Compliant PCI DSS (Payments) OWASP Pen Testing

Third-Party Audited Certifications

EPG Solutions is built on Base44, which holds formal independent certifications covering security, availability, processing integrity, confidentiality, and privacy.

✓ Compliant

SOC 2 Type II

Independent audit framework evaluating the design and sustained effectiveness of security and operational controls over a 6–12 month observation period. Covers all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Request Report Under NDA →
✓ Certified

ISO 27001

International standard for managing information security and privacy controls across people, processes, and technology. Confirms a repeatable, audited process to protect data — directly aligning with NERC CIP vendor assessment requirements.

View Certificate →
✓ Compliant

GDPR

Full adherence to EU General Data Protection Regulation standards including data residency controls, consent management, Standard Contractual Clauses (SCCs), and EU data protection requirements. A formal Data Processing Agreement (DPA) is available upon request.

View DPA Overview →
✓ Certified

PCI DSS (Payments)

Payment processing is handled exclusively by PCI DSS–certified providers. Sensitive payment data is encrypted in transit and never stored within the EPG Solutions or Base44 environment. Fraud and abuse controls are applied at the platform level.

View Base44 Trust Center →
✓ Active

Bug Bounty Program

An active bug bounty program invites independent security researchers worldwide to responsibly disclose vulnerabilities. All confirmed findings are prioritized for rapid remediation according to severity. This embodies a commitment to proactive, transparent security.

Contact Bug Bounty Team →
✓ Active

OWASP Penetration Testing

Both internal and third-party penetration tests are performed based on OWASP methodologies, simulating real-world attack scenarios to identify vulnerabilities and validate defense effectiveness. All findings are reviewed, prioritized, and remediated continuously.

View Security Details →

Hosting & Security: Powered by Base44

All EPG Solutions software is built, hosted, and secured on the Base44 platform. Every application sits behind the same enterprise-grade controls Base44 maintains for its largest customers.

SSO & MFA Authentication

Enterprise SSO with multiple customer-managed identity provider (IDP) support. MFA is enforced. Google SSO and traditional email+password with anti-bot controls are also supported.

Row-Level Security (RBAC)

Granular CRUD (Create, Read, Update, Delete) permissions per user and per record at the database level. Multi-seat license tiers (1, 5, and 10 seats) are enforced with isolated access controls.

Built-In Security Scans

Automated code analysis detects hardcoded secrets and exposed API keys, validates row-level security rules, and identifies backend functions lacking proper server-side authentication — before reaching production.

Continuous Monitoring

24/7 system monitoring via DataDog with detailed audit logging of all events. Real-time alerting enables rapid incident detection and response across the entire platform infrastructure.

IP Allowlisting

Network-level access controls allow administrators to restrict workspace and application access to pre-approved IP addresses — a critical control for utility organizations requiring network perimeter security.

Secure SDLC (SSDLC)

Security is integrated at every stage of software development through threat modeling, secure design reviews, code reviews, and penetration testing. Risks are identified early and systematically resolved.

App Governance & Visibility

Workspace administrators control application visibility (Private, Workspace-only, or Public). Enterprise Governance settings define defaults for new app publishing and restrict member permissions as needed.

Third-Party Risk Management

A comprehensive TPRM program ensures all vendors comply with security and compliance standards. Vendor adherence is periodically validated to confirm ongoing alignment — directly satisfying NERC CIP-013 sub-supply chain requirements.

GitHub Integration (Extensible)

Two-way GitHub integration allows export of application code for teams with established security pipelines, enabling external security tooling and specialized compliance scanners to be run alongside built-in protections.

How Your Data Is Handled

EPG Solutions maintains a minimal data footprint. We collect only what is necessary to deliver the platform, and it is never sold or shared outside the defined subprocessor list.

Encryption at Rest & in Transit

AES-256 encryption for stored data; TLS 1.3 for all data in transit. Provided and managed by Base44 infrastructure.

No Data Selling

EPG Solutions never sells, rents, or shares client or subscriber data with third parties outside of defined platform subprocessors.

Encrypted Backups

Daily encrypted backups with 30-day retention managed by Base44, ensuring business continuity and disaster recovery capability.

Data Residency (US)

All Base44 servers are located in the United States. EU/UK data residency options are available on Elite and Enterprise plans for applicable data created after April 16, 2026.

Incident Response

Confirmed security incidents trigger a structured notification process. Security questions and breach inquiries can be directed to compliance@epgsolutions.services.

Other Business Systems (Scoped)

EPG Solutions uses standard third-party tools (HubSpot, Shopify, Calendly, etc.) for marketing, payments, and scheduling only. No subscriber or training data is shared with these systems.

Base44 Third-Party Subprocessors

The following third-party providers are used by Base44 to securely process and store data on behalf of EPG Solutions. All are bound by strict data processing agreements.

MongoDBData storage & hosting🇺🇸 United States
SendGridEmail transmission🇺🇸 United States
RenderServer services🇺🇸 United States
Google Cloud (GCP)Analytics services🇺🇸 United States
OpenAILLM API calls🇺🇸 United States
AnthropicLLM API calls🇺🇸 United States
DataDogGeneral logging & monitoring🇺🇸 United States
Wix.com Ltd.Platform services🇮🇱 Israel

Full subprocessor directory: base44.com/dpa/exhibitc

Top 10 Questions from Utility IT & Security Teams

These are the most common questions raised during vendor security assessments by utility company IT and compliance departments.

Yes. EPG Solutions is built on Base44, which is SOC 2 Type II certified. The full report is available under NDA. To request a copy, email compliance@epgsolutions.services and a security specialist will initiate the NDA process. The report covers all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
EPG Solutions is classified as a low-to-medium risk third-party software vendor. Our platform does not connect to, control, or interface with any operational technology (OT), SCADA systems, or bulk electric system (BES) cyber systems. For CIP-013 vendor documentation, we can provide:
  • Base44 SOC 2 Type II report (under NDA)
  • ISO 27001 certificate
  • Completed vendor security questionnaire
  • Data Processing Agreement (DPA)
All data is stored on Base44 servers located in the United States (MongoDB, hosted via Render). Data is encrypted at rest using AES-256 and in transit using TLS 1.3. Access is controlled via role-based permissions (RBAC) at the row level — users can only see data they are authorized to access. EPG Solutions staff access is limited to account administration only. No data is shared with EPG's marketing or scheduling tools (HubSpot, Shopify, Calendly).
Yes. Base44 supports enterprise SSO with multiple customer-managed identity providers (IDPs), enabling your organization to enforce access through your existing identity management system. MFA is supported and can be required at the workspace level. Google SSO is also available for standard users. Anti-bot controls and email verification are applied to all email+password logins.
Base44 conducts both internal and third-party penetration testing using OWASP methodologies to simulate real-world attack scenarios. Built-in security scans continuously analyze application code for hardcoded secrets, exposed API keys, row-level security violations, and authentication gaps. All findings are reviewed, prioritized by severity, and tracked through remediation as part of a continuous security improvement process. An active bug bounty program with independent researchers provides additional coverage.
Security incidents are monitored continuously via DataDog logging. In the event of a confirmed breach or data incident affecting EPG Solutions customers, we will notify affected organizations in accordance with applicable law and our Data Processing Agreement. For security incident inquiries or to report a concern, contact compliance@epgsolutions.services. For platform-level incidents, Base44's status page is available at status.base44.com.
Yes. Base44's IP allowlisting feature allows workspace administrators to restrict access to applications based on approved client IP addresses. This provides network-level perimeter control and is available on Enterprise plans. Organizations requiring this control should contact compliance@epgsolutions.services to discuss plan options that include this capability.
Yes. All Base44 subprocessors are bound by strict data processing agreements (DPAs) governing data transfers to the US and, where applicable, use of Standard Contractual Clauses (SCCs) or the Data Privacy Framework (DPF). Current subprocessors include MongoDB (storage), SendGrid (email), Render (server), Google Cloud (analytics), OpenAI and Anthropic (AI), DataDog (monitoring), and Wix.com (platform). The full directory is at base44.com/dpa/exhibitc.
Account owners retain full ownership of their data and applications at all times per Base44's Terms of Service. Prior to cancellation, subscribers may export all application data from the platform dashboard. Upon account deletion, application data is permanently removed from the platform. To request a copy of personal data held by Base44, email compliance@base44.com from the associated account email. For EPG-specific data retention questions, contact compliance@epgsolutions.services.
Yes. EPG Solutions can provide the following upon request:
  • Completed vendor security questionnaire (VSQ)
  • Base44 SOC 2 Type II report (under NDA)
  • ISO 27001 certificate (Base44)
  • Data Processing Agreement (DPA)
  • GDPR compliance overview
  • Subprocessor list with DPA coverage
To initiate a vendor security review, email compliance@epgsolutions.services with your organization's questionnaire or review requirements.

Ready to Start a Vendor Security Review?

Our team can provide SOC 2 reports, completed vendor questionnaires, and custom security assessments to support your organization's procurement and compliance process.