PeakLoad Security Overview
This page sets out how PeakLoad protects the information entrusted to us. It is intended for security teams evaluating PeakLoad and answers the questions we are most often asked. Our underlying policies are available on request under NDA — see Documentation below.
PeakLoad is operated by Busbar Financial Media LLC. We publish energy transition news and data to subscribing organisations. The personal data we hold is limited to business contact information and platform usage data. We hold no special category data, no payment card data and no financial account data.
Last updated: 15 Aug 2026
Certifications
PeakLoad does not hold ISO 27001 or SOC 2 Type 2 certification. We would rather state this plainly than imply otherwise.
Our policy suite is structured against the ISO 27001 Annex A control headings and is reviewed annually, but it is not independently certified. Independent assurance in our supply chain is drawn from our infrastructure providers: Amazon Web Services, Cloudflare, Google and Microsoft each hold ISO 27001 and SOC 2 Type 2, and we obtain, review and record their assurance reports as part of our supplier review cycle.
We are a small organisation and have taken a proportionality decision on certification given the limited categories of personal data we process. Where a prospective client requires certification as a condition of contracting, we would rather discuss that early than late.
Authentication and Access
Customer accounts
Passwords are never stored in a form we can read. They are held as salted one-way hashes, which means neither PeakLoad staff nor an attacker with database access can recover them. Password resets issue a time-limited link rather than disclosing an existing credential.
Multi-factor authentication for customer accounts is on our roadmap and is not currently available. Where an organisation requires enforced MFA today, we can discuss IP restriction of access as an interim control.
PeakLoad staff
- Access is granted only through company-issued credentials. Personal accounts may not be used to access company systems.
- Multi-factor authentication is mandatory on every staff account, without exception.
- Role-based access control is applied on the principle of least privilege. Administrative privileges are restricted to senior technical staff.
- Administrative access to production systems is additionally gated by Cloudflare Zero Trust, with identity-based policy enforcement.
- Credentials are revoked across all systems on the day a member of staff leaves, against a documented offboarding checklist.
- Access rights are reviewed at least annually and on any change of role.
Data Protection
Encryption
All data is encrypted at rest using AES-256, across every production data store. Traffic to PeakLoad services is encrypted in transit using TLS 1.2 or above.
Where data is held
Our platform is hosted on Amazon Web Services in the us-east-1 region (Northern Virginia, USA). Client personal data and correspondence remain in managed cloud systems and are not copied to staff devices. Staff work on company-provided laptops with full-disk encryption enforced, anti-malware active, automatic updates enabled and automatic screen locking.
Tenant separation
Each client organisation's data is logically separated, and authorisation is enforced at the application layer so that a user can only retrieve records belonging to their own organisation.
Data Retention
How long we retain personal data depends on the role in which we hold it.
Data we hold on behalf of our clients
For the records of individuals at your organisation who hold a PeakLoad licence, we act as a processor and you are the controller. We retain that data only for as long as you instruct. Where your agreement with us specifies retention and deletion terms, those terms govern.
Where an agreement is silent, our standard position is that we delete your data. On termination we retain it for 30 days, during which you may request an export in a standard machine-readable format; this window also protects against accidental or reversed termination. At the end of that period the data is deleted from production systems, and purged from encrypted backups in line with our standard backup retention cycle. If you would prefer immediate deletion without an export window, we will do that on request. This includes user-level activity data, which is deleted on the same basis. Accounting and billing records are retained for the period required by law.
Data we hold for our own purposes
For prospect, marketing, billing and staff data we act as controller. Retention is determined by the purpose the data was collected for rather than by a single period: customer account and contract records are retained for six years after termination in line with the contractual limitation period; marketing contacts are retained while our legitimate interest subsists and reviewed at least every two years; accounting records are retained for the statutory period. Where you have asked us not to contact you, we retain your email address indefinitely for the sole purpose of honouring that request.
We also maintain aggregate, anonymised statistics on platform usage to inform product development. This data cannot be linked back to individuals or to a particular client organisation and is not personal data.
Our full retention position is set out in our Data Protection Policy.
International Transfers
PeakLoad is US-established and our platform and suppliers are located in the United States. Personal data originating in the United Kingdom or the European Economic Area is therefore transferred to a third country.
We rely on the EU Standard Contractual Clauses, Module 2 (Controller to Processor), together with the UK International Data Transfer Addendum. We do not rely on the EU–US Data Privacy Framework. The transfer mechanism relied upon for each supplier is recorded in our Sub-processor and Outsourcing Register.
Sub-processors
We maintain a Sub-processor and Outsourcing Register recording, for each supplier, the legal entity and LEI, registered office, processing activity, categories of personal data, storage and processing locations, transfer mechanism and risk tier. Our current sub-processors are:
- Amazon Web Services, Inc. — cloud infrastructure and primary data store (USA)
- Cloudflare, Inc. — edge protection, web application firewall, and Zero Trust access control for administrative interfaces (global edge; logs in USA)
- Google LLC — Google Workspace: business correspondence, documents and internal messaging (USA)
- Microsoft Corporation — Microsoft 365 and OneDrive: managed storage for customer and sales records (USA)
- Twilio Inc. (SendGrid) — transactional email delivery (USA)
- Intuit Inc. — invoicing and billing administration (USA)
No supplier is engaged to process client data without approval and entry in the Register. Suppliers are tiered by criticality and reviewed at least annually for the most critical. Where a client agreement requires prior notice of a new sub-processor, or confers a right to object, we notify in accordance with that agreement before processing begins.
Infrastructure and Platform Security
- Production infrastructure is hosted in AWS, with network access controls restricting access to production systems. The database tier is not publicly addressable.
- Cloudflare provides edge protection for public hostnames, including a web application firewall and always-on DDoS mitigation.
- Production data is backed up, and restore testing is performed at least every six months with results recorded.
- Vulnerability scanning and penetration testing are conducted as required, with findings tracked to resolution.
- Only approved cloud services may be used, as recorded in our Register.
Incident Response
We operate a documented Information Security Incident Management Procedure covering identification, categorisation, containment, remediation, recovery, notification and post-incident review. Our commitments to affected clients are:
- Within 48 hours of identifying an incident that affects your data or service, we notify you, setting out what happened, what is affected, the potential impact, the action we have taken, and what happens next.
- Within 72 hours, we provide a detailed follow-up report covering full scope, root cause analysis and preventive measures.
- Where we act as processor and a personal data breach affects data we hold for you, we notify you so that you can meet your own regulatory obligations, and we assist you in doing so.
- Where we act as controller, we notify the Information Commissioner's Office within 72 hours where the breach is likely to result in a risk to individuals.
Clients not affected by an incident are not notified of it. An incident at one of our suppliers is handled as though it had occurred within PeakLoad, and our notification clock runs from the point we become aware.
PeakLoad has experienced no personal data breach since commencement of operations.
People
- All staff complete annual security and data protection training covering device security, data handling, credential practice, phishing and social engineering, incident reporting and their obligations on leaving. Completion is recorded.
- Staff handling client personal data complete an additional module covering our obligations as a processor, handling of client correspondence, and recognition of data subject requests.
- Personal email and personal messaging applications may not be used for company business.
- No third-party service may be used to process client data without approval, including free-tier and trial services.
Your Rights and Requests
Where we act as processor, a request from one of your users to access, correct or delete their data is referred to you as controller, and we assist you in responding. Where we act as controller, we respond directly within one calendar month.
We can assist with data extraction, deprovisioning and deletion requests at any point during or after our engagement.
Documentation
The following are available to clients and prospective clients on request:
- Cybersecurity Policy
- Data Protection Policy
- Information Security Incident Management Procedure
- Third-Party and Supplier Risk Management Policy
- Sub-processor and Outsourcing Register
We are also able to complete supplier security questionnaires and to enter into a Data Processing Agreement incorporating the Standard Contractual Clauses.
Contact
Security and data protection enquiries, including reports of suspected vulnerabilities, should be sent to our Data Protection Officer via our support channel [email protected].