Connected operations.
Security built in.
Certified information security
Connected assets should make operations smarter without creating unnecessary risk. Undagrid combines scalable IoT technology with certified security governance and secure operational practices—helping organisations gain valuable operational visibility while maintaining control over their data, identities and integrations. Security is built into how we design, develop and operate our IoT solutions.
Undagrid operates within EnOcean GmbH’s Information Security Management System, certified according to ISO/IEC 27001:2022. The certification explicitly includes Undagrid B.V. and covers the development and operation of cloud-based IoT solutions, including cloud infrastructure, customer data, applications, databases, development environments and operational processes:
Security throughout the service lifecycle
Secure by design
Security requirements are considered from architecture and development through deployment and operation.
Our development practices include peer review, automated security testing, dependency and secret scanning, controlled releases and separation between development, test and production environments.
Identity and access protection
Access is governed through verified identities, role-based permissions and the principle of least privilege.
Depending on the solution configuration, Undagrid supports single sign-on, multi-factor authentication, Microsoft Entra ID integration and tenant-specific access controls. Administrative and support access is restricted to authorised personnel and logged.
Customer and tenant separation
Undagrid applies tenant-scoped authentication, authorisation and data-access controls to support the logical separation of customer environments. Within a customer environment, permissions can be organised around locations, operational areas and organisational responsibilities.
Data protection
Undagrid solutions are designed primarily around assets, equipment and operational events—not the monitoring of individuals. Our data-protection approach includes data minimisation, purpose limitation, controlled access, configurable retention, secure export and deletion, and transparent cloud-service governance. Managed-cloud solutions can be deployed using only European processing regions, depending on the selected architecture and contracted services.
Monitoring and resilience
Centralised logging and monitoring support the detection, investigation and resolution of operational and security events. Our security framework includes incident management, business continuity, backup and restoration processes. Customer-specific availability and recovery requirements are defined as part of the applicable service design and agreement.
Vulnerability management
Potential vulnerabilities are identified through automated scanning, security advisories, internal testing and reports from customers and security researchers.
Findings are assessed according to their applicability, exposure and potential impact. Identified risks are tracked through remediation or documented mitigation, which may include software updates, dependency updates, configuration changes or additional monitoring.
EnOcean’s and Undagrid’s Cyber Resilience Act Approach
The Cyber Resilience Act, Regulation (EU) 2024/2847, establishes cybersecurity requirements for hardware and software products with digital elements placed on the EU market.
EnOcean and Undagrid are implementing the CRA in line with its phased application.
For the requirements applying from September 2026, EnOcean and Undagrid have established and are maintaining processes for:
- receiving and assessing product-security vulnerability reports;
- communicating with reporters and, where appropriate, affected users;
- handling product vulnerabilities through a risk-based process;
- reporting actively exploited vulnerabilities and severe product-security incidents to the competent authorities where required; and
- maintaining supporting vulnerability-management, incident-management and documentation processes.
Coordinated vulnerability disclosure
In this regard, we welcome responsible reports from customers, partners and security researchers. If you believe you have identified a vulnerability affecting an Undagrid or EnOcean product, application, API or service, please contact: cra@enocean.com
Please include:
- The affected product or service
- A description of the potential vulnerability
- Steps to reproduce the issue
- Its possible security or privacy impact
- Supporting evidence, where available
Please avoid including sensitive information in your initial message. We will arrange an appropriate method for exchanging such information if necessary. We ask researchers to avoid disrupting services, accessing unnecessary data or publicly disclosing a vulnerability before we have had a reasonable opportunity to investigate and address it.
For full details on reporting, communication, confidentiality, coordinated disclosure, customer notifications and SBOM-related information, please read our:
Vulnerability Reporting and Coordinated Vulnerability Disclosure Policy
Data transparency
Undagrid provides product-specific transparency information supporting customers’ rights under the EU Data Act. These disclosures explain the nature and format of data generated by applicable connected products and related services, relevant storage and retention arrangements, and the available methods for accessing, retrieving and erasing data:
Read Transparency Disclosures for Undagrid Offerings under EU Data Act