Trust Centre
Assurance you can evaluate
Review the controls and independent assurance we can state publicly, then bring detailed security, privacy and operational questions into due diligence.
Current assurance
Clear about what is certified and what is in progress
AmpNexus is Cyber Essentials certified and is working towards ISO/IEC 27001 certification. Platform controls add scoped access, tenant isolation, audit history and controlled fleet change around that assurance programme.
Cyber Essentials certified
Independent UK Government-backed assurance covering core technical controls including access, configuration and patching.
Scoped access
Use OAuth2 client credentials and granular scopes so integrations receive only the access required for their role.
Tenant isolation and RBAC
Separate customer data and actions through multi-tenant controls and role-based permissions across the platform.
Audit history
Record sensitive actions such as remote commands, access changes and rollout approvals with actor and time context.
Controlled change
Move fleet changes through cohorts, approvals, maintenance windows, failure thresholds and rollback controls.
Service transparency
Publish current availability, incident history and planned maintenance through the AmpNexus status service.
Public trust resources
These pages provide the current public position. Tender-specific evidence and questionnaires can be handled through the evaluation process.
- Platform security controls and certification status
- Privacy notice and data-processing context
- Accessibility statement and feedback route
- Live service status, incident history and maintenance windows
- Responsible vulnerability disclosure route
- Platform support and operational contact routes
- Documented authentication and permission model
- Security-questionnaire and architecture-review support
Built for due diligence
Procurement and tender teams
Start from a consistent public assurance position, then scope the evidence required for your evaluation.
Security and privacy reviewers
Review identity, tenancy, audit, change and disclosure controls with the teams responsible for them.
Operational stakeholders
Understand how service status, access control and governed change support day-to-day charging operations.
Evaluation path
Move from public assurance to scoped evidence
Different estates and procurement routes ask different questions. The evaluation starts with public controls and then focuses on the requirements that affect your service.
- 01
Review
Use the security, privacy, accessibility and status pages for the public position.
- 02
Scope
Identify the architecture, data, access and operational requirements relevant to the service.
- 03
Assess
Work through questionnaires and technical review with the responsible AmpNexus teams.
- 04
Record
Capture agreed controls, responsibilities and evidence in the procurement process.
Bring us your due-diligence questions
We can work through security questionnaires and platform-control reviews against the scope of your charging service.