Security
Website Security
This page describes the security controls for utilconnect.com. Customer production deployments of the UtilConnect platform operate under separate, deployment-specific security controls tailored to each utility's operational and regulatory requirements.
Scope: The security measures described here apply to the marketing and informational website at utilconnect.com. They do not describe the security architecture of the UtilConnect utility operations platform, which is documented separately for each customer deployment.
Transport Security
All traffic to utilconnect.com is served exclusively over HTTPS with TLS 1.2 or higher. HTTP requests are permanently redirected to HTTPS. The site is configured with Strict-Transport-Security (HSTS) with a one-year max-age and includeSubDomains, preventing protocol downgrade attacks.
Security Headers
Every response from utilconnect.com includes a set of defensive HTTP headers: X-Content-Type-Options (nosniff), X-Frame-Options (SAMEORIGIN) to prevent clickjacking, Referrer-Policy (strict-origin-when-cross-origin), and Permissions-Policy restricting camera, microphone, and geolocation access.
Infrastructure
The website is hosted on Hostinger's infrastructure behind Apache with Phusion Passenger for Node.js process management. The application runs in standalone Next.js mode. Environment credentials (SMTP, API tokens) are stored as server-side environment variables and are never embedded in client-side code or the public build.
Analytics and Tracking
This website uses Google Analytics 4 for traffic analysis. Analytics are only loaded after explicit user consent via our cookie consent banner. Consent Mode v2 is implemented — no analytics network requests are made before consent is granted. Users can withdraw consent at any time using the cookie preferences button.
Content Security
The Sanity CMS Studio is accessible only to authenticated team members via OAuth. The public dataset allows read-only access to published content. Write operations require a scoped API token with editor-level permissions. SVG uploads are blocked at the CDN level to prevent script injection via image assets.
Form Submissions
Contact, demo request, and expert inquiry form submissions are processed server-side via API routes. Form data is transmitted over HTTPS and sent directly to internal email addresses via SMTP. No form data is stored in a database or passed to third-party marketing platforms.
Reporting a Security Issue
If you discover a security vulnerability on utilconnect.com or in the UtilConnect platform, please report it responsibly. We will acknowledge your report within 48 hours and aim to resolve confirmed issues promptly.
security@utilconnect.comPlease do not disclose security issues publicly until we have had the opportunity to assess and address them. We do not currently operate a bug bounty programme.
Ready to connect your
utility operations?
See how UtilConnect modernises Customer 360, meter data, billing, revenue assurance, and operational workflows — in one platform.