Security Overview
CitizenSolar is presented as a trust-aware release candidate with bounded claims, explicit limitations, a coordinated disclosure path, and a staged roadmap toward stronger telemetry and controller assurance.
Trust Surface
Security, standards, privacy, and disclosure should read as one bounded trust posture
Use the trust surface to explain what is present in the release, what is roadmap, and where technical review should begin.
Security language remains bounded to the current release and documented roadmap.
PQ framing is roadmap-oriented and explicitly separated from implemented release scope.
Audience
Core Focus
Best Next Route
What To Review First
Quick Route Actions
Open the next commercial surface, move into buyer guidance, or start a scoped inquiry without leaving the current page.
Jump To Section
Trust Posture
Current Release Posture
The current public release is a static frontend package with route hardening, crawler-safe metadata, release manifests, checksums, and access controls suitable for cPanel/Apache deployment. It is not presented as a completed secure operations backend or audited settlement infrastructure.
- • Static deploy bundle with release manifests and checksums
- • Apache access restrictions for sensitive files and internal directories
- • Route-specific metadata and noindex treatment for internal or demonstrative surfaces
- • Release-safe documentation, disclosure, and privacy materials
Threat-Aware Design Principles
The trust model centers on bounded claims, explicit maturity labels, controlled public scope, and an architecture direction toward stronger device identity, telemetry integrity, firmware signing, and audit attestations over time.
- • Bound claims to what is present in the current release
- • Separate commercial, demonstrative, and research surfaces
- • Design for stronger controller identity and telemetry trust paths
- • Keep disclosure and operational limitations visible to reviewers and partners
PQ Migration Roadmap
CitizenSolar is designed with a roadmap toward hybrid classical plus post-quantum assurance for long-lived critical infrastructure trust paths. The current release documents the direction; it does not claim a fully implemented PQ platform.
- • Device identity and key lifecycle hardening
- • Signed telemetry and event receipt roadmap
- • Firmware signing and upgrade attestations
- • Audit and ledger notarization research path
- • High-assurance operator and admin pathway design
Disclosure Path
Security issues should be reported privately first with reproducible details, affected routes or assets, and impact notes. No public bug bounty is claimed in this release.
- • Use the documented disclosure route before public posting
- • Include affected route, asset, or deployment context
- • Share steps to reproduce and observed impact
- • Treat the current contact route as a temporary release-stage disclosure path
Standards And Security Direction
The public security surface stays aligned with interoperability and staged trust evolution rather than blanket claims.
- • Designed for secure controller identity and trusted telemetry evolution.
- • Built with a roadmap toward hybrid classical plus post-quantum assurance.
- • Structured for auditability and operator-grade traceability without claiming blanket certification.
- • Designed for interoperability across inverters, BMS, meters, EVSE, EMS, and SCADA-adjacent surfaces.
Related Routes
Supplier Candidate Intake
IntakeHave supplier evidence to submit for review? Start the Supplier Candidate Intake to map provider fit, sovereign/control-chain posture, finance evidence, orchestration readiness, and Community Energy Bank readiness.
Supplier Candidate Registry
RegistryBefore a supplier can be considered for an Energy System Pack, CitizenSolar screens provider fit, sovereign/control-chain posture, finance evidence, orchestration readiness, and Community Energy Bank readiness where applicable.
Deterministic Agent Controls
SecurityG1-G10 deterministic safeguards, action-tier limits, and operator approval boundaries.
Orchestration Partners
PartnersPartner route for trust-aware storage-first collaboration, safeguards review, and outreach.
Standards Alignment
StandardsInteroperability posture and interface classes.
Privacy
PrivacyCurrent release data-handling scope and contact model.
Contact
ContactOpen technical or disclosure-related inquiry.
Recommended Next Action