Security
Last Updated: April 5, 2026
Rate360 is committed to protecting the confidentiality, integrity, and availability of the systems and data entrusted to us. This page summarizes our security program and practices. For specific security questions, please contact us at contact@rate360.io.
Security Principles
Our security program is designed around core principles that include least privilege, defense in depth, secure-by-default configuration, monitoring, resilience, and continuous improvement. We recognize that utility operational and financial data is sensitive and apply a risk-based approach to protecting it.
Administrative Safeguards
We maintain administrative security measures designed to support governance, accountability, and risk management, including:
- documented policies and standards;
- role-based access management;
- workforce awareness and security training;
- vendor and third-party risk review practices;
- change management and secure operational procedures;
- incident response planning and escalation processes.
Technical Safeguards
We use technical safeguards designed to reduce risk and protect systems and data, including where appropriate:
- encryption of data in transit (TLS) and at rest;
- authentication and session management controls;
- access control enforcement and privilege separation;
- logging, monitoring, and anomaly detection;
- vulnerability management and patch processes;
- network segmentation and firewall controls;
- secure software development practices.
Infrastructure and Hosting
Rate360 is built on reputable cloud infrastructure providers that maintain their own robust security certifications and compliance programs. We leverage managed services designed with security, availability, and regulatory compliance in mind to provide a stable and secure foundation for the platform.
Data Handling and Sensitivity
We recognize that utility data — including operational, financial, rate, and customer information — can be sensitive. We apply data minimization principles and limit access to customer data to personnel who need it to operate and support the Services. Customer data is not used for purposes beyond those described in our Privacy Policy and Terms of Service.
Incident Response
We maintain an incident response process to detect, contain, and remediate security events. In the event of a security incident that affects customer data, we will notify affected customers in accordance with applicable legal requirements and our contractual obligations.
If you believe you have discovered a security vulnerability in the Rate360 platform, please report it responsibly to contact@rate360.io. We appreciate responsible disclosure and will work to address valid findings promptly.
Questions About Security?
For security-related questions, vulnerability disclosures, or to request more detailed information about our security program, please contact us:
Rate360contact@rate360.io
www.rate360.io