Security and privacy

Built to be ring-fenced.

A regulated monopoly adopts nothing it cannot audit. Gridmark is designed to make that audit easy, and to make every claim below checkable.

SEPARATELY TENANTED

One tenancy per network. No application data is shared across networks. Applicant-side records belong to the applicant and are presented to one network at a time.

ROLE-BASED ACCESS

Assessor, reviewer, decision-maker and observer roles, defined by the network, with information barriers between regulated and contestable services in line with the AER's Ring-fencing Guideline.

IMMUTABLE AUDIT LOG

Every evaluation, every change to a threshold, every decision: who, what, when, against which rule version. Written once, never edited.

CONSENT RECORDS

Customer authority for interval data is scoped to named NMIs and dates, timestamped, revocable, and retained for the period the National Energy Retail Rules require. A scanned signature is replaced by a verifiable record.

NO STANDARDS TEXT STORED

Rules cite Australian Standards; they never reproduce them. You see the check, the clause reference and your own evidence.

DATA HELD IN AUSTRALIA

Hosted in Australian regions, encrypted at rest and in transit. [CONFIRM PROVIDER AND REGION]

DETERMINISTIC CHECKS

A rule evaluates to the same result from the same inputs, every time, with the inputs and evidence references recorded. AI assists with extraction, retrieval and drafting. It does not make engineering judgements.

INDEPENDENT ASSURANCE

Independent security and privacy assurance before any live use with a network, and independent evaluation of every measured result. [NAME PARTNERS WHEN CONTRACTED]

Customer data, step by step

Sizing a connection needs the site's interval data. Today the path is manual: the NMI off a bill, a letter of authority in whatever form the retailer or network specifies, an email, a spreadsheet for multiple sites, and a regulated wait. Gridmark automates everything around the regulated wait, and nothing inside it.

StepWhat Gridmark does
1Identifies the customer and NMI: legal account holder, address, retailer, meter channels.
2Captures explicit, purpose-limited authority covering source, date range, recipient, use, retention and withdrawal, with the signatory's capacity recorded.
3Routes the request to the current retailer or network through its supported channel, as a customer authorised representative under the Rules.
4Tracks the request against the procedural target and records every clarification.
5Ingests the response in NEM12 or NEM13 and validates identity, interval length, daylight-saving transitions, quality flags, units and direction.
6Encrypts, logs access, applies the agreed retention period, and honours withdrawal.

The Consumer Data Right pathway, with its accredited-data-recipient obligations, is the planned route where it applies. [ACCREDITATION STATUS]

Contacts

01Privacy. Questions about personal or customer data, authority records or withdrawal: privacy@gridmark.com.au
02Security. To report a vulnerability or a security concern: security@gridmark.com.au. We acknowledge within two business days.
03Support. Everything else about using Gridmark: support@gridmark.com.au