AmpNexus

Trust Centre

Assurance you can evaluate

Review the controls and independent assurance we can state publicly, then bring detailed security, privacy and operational questions into due diligence.

Current assurance

Clear about what is certified and what is in progress

AmpNexus is Cyber Essentials certified and is working towards ISO/IEC 27001 certification. Platform controls add scoped access, tenant isolation, audit history and controlled fleet change around that assurance programme.

Cyber Essentials certified

Independent UK Government-backed assurance covering core technical controls including access, configuration and patching.

Scoped access

Use OAuth2 client credentials and granular scopes so integrations receive only the access required for their role.

Tenant isolation and RBAC

Separate customer data and actions through multi-tenant controls and role-based permissions across the platform.

Audit history

Record sensitive actions such as remote commands, access changes and rollout approvals with actor and time context.

Controlled change

Move fleet changes through cohorts, approvals, maintenance windows, failure thresholds and rollback controls.

Service transparency

Publish current availability, incident history and planned maintenance through the AmpNexus status service.

Public trust resources

These pages provide the current public position. Tender-specific evidence and questionnaires can be handled through the evaluation process.

  • Platform security controls and certification status
  • Privacy notice and data-processing context
  • Accessibility statement and feedback route
  • Live service status, incident history and maintenance windows
  • Responsible vulnerability disclosure route
  • Platform support and operational contact routes
  • Documented authentication and permission model
  • Security-questionnaire and architecture-review support

Built for due diligence

Procurement and tender teams

Start from a consistent public assurance position, then scope the evidence required for your evaluation.

Security and privacy reviewers

Review identity, tenancy, audit, change and disclosure controls with the teams responsible for them.

Operational stakeholders

Understand how service status, access control and governed change support day-to-day charging operations.

Evaluation path

Move from public assurance to scoped evidence

Different estates and procurement routes ask different questions. The evaluation starts with public controls and then focuses on the requirements that affect your service.

  1. 01

    Review

    Use the security, privacy, accessibility and status pages for the public position.

  2. 02

    Scope

    Identify the architecture, data, access and operational requirements relevant to the service.

  3. 03

    Assess

    Work through questionnaires and technical review with the responsible AmpNexus teams.

  4. 04

    Record

    Capture agreed controls, responsibilities and evidence in the procurement process.

Bring us your due-diligence questions

We can work through security questionnaires and platform-control reviews against the scope of your charging service.