Illustrative reference signals only. Not live settlement or regulated dispatch.
REFERENCE INDEX€8.1425
REFERENCE LATENCY42ms
REFERENCE INDEX€8.1425
REFERENCE LATENCY42ms
Security

Security Overview

CitizenSolar is presented as a trust-aware release candidate with bounded claims, explicit limitations, a coordinated disclosure path, and a staged roadmap toward stronger telemetry and controller assurance.

Trust Surface

Security, standards, privacy, and disclosure should read as one bounded trust posture

Use the trust surface to explain what is present in the release, what is roadmap, and where technical review should begin.

Abstract trust posture visual for security, standards, and privacy context.
release-readySecurity

Security language remains bounded to the current release and documented roadmap.

PQ framing is roadmap-oriented and explicitly separated from implemented release scope.

Audience

Partners • Technical reviewers • Municipalities

Core Focus

Current Release Posture

Best Next Route

Supplier Candidate Intake

What To Review First

Current Release PostureThreat-Aware Design PrinciplesPQ Migration RoadmapDisclosure Path

Quick Route Actions

Open the next commercial surface, move into buyer guidance, or start a scoped inquiry without leaving the current page.

Jump To Section

Trust Posture

Current Release Posture

The current public release is a static frontend package with route hardening, crawler-safe metadata, release manifests, checksums, and access controls suitable for cPanel/Apache deployment. It is not presented as a completed secure operations backend or audited settlement infrastructure.

  • • Static deploy bundle with release manifests and checksums
  • • Apache access restrictions for sensitive files and internal directories
  • • Route-specific metadata and noindex treatment for internal or demonstrative surfaces
  • • Release-safe documentation, disclosure, and privacy materials

Threat-Aware Design Principles

The trust model centers on bounded claims, explicit maturity labels, controlled public scope, and an architecture direction toward stronger device identity, telemetry integrity, firmware signing, and audit attestations over time.

  • • Bound claims to what is present in the current release
  • • Separate commercial, demonstrative, and research surfaces
  • • Design for stronger controller identity and telemetry trust paths
  • • Keep disclosure and operational limitations visible to reviewers and partners

PQ Migration Roadmap

CitizenSolar is designed with a roadmap toward hybrid classical plus post-quantum assurance for long-lived critical infrastructure trust paths. The current release documents the direction; it does not claim a fully implemented PQ platform.

  • • Device identity and key lifecycle hardening
  • • Signed telemetry and event receipt roadmap
  • • Firmware signing and upgrade attestations
  • • Audit and ledger notarization research path
  • • High-assurance operator and admin pathway design

Disclosure Path

Security issues should be reported privately first with reproducible details, affected routes or assets, and impact notes. No public bug bounty is claimed in this release.

  • • Use the documented disclosure route before public posting
  • • Include affected route, asset, or deployment context
  • • Share steps to reproduce and observed impact
  • • Treat the current contact route as a temporary release-stage disclosure path

Standards And Security Direction

The public security surface stays aligned with interoperability and staged trust evolution rather than blanket claims.

  • • Designed for secure controller identity and trusted telemetry evolution.
  • • Built with a roadmap toward hybrid classical plus post-quantum assurance.
  • • Structured for auditability and operator-grade traceability without claiming blanket certification.
  • • Designed for interoperability across inverters, BMS, meters, EVSE, EMS, and SCADA-adjacent surfaces.