Security & Data
The questions every facility team asks before a launch begins: how Enerzyz is isolated from your back office and guest data, who controls what, and what's independently verified.
The Enerzyz gateway (Edge Mini) connects only to your building's BMS network, via a dedicated IP address behind your existing firewall.
It has no connection to your PMS, guest network, or any guest information: the two systems never touch.
The device operates on its own dedicated VLAN, isolated from your property management network.
Read-only by default
Every deployment starts in monitoring/awareness mode, surfacing recommendations for your engineers to act on manually. Nothing is written back to your BMS unless you explicitly move to active optimisation.
Your boundaries, your approval
If you choose to enable control actions, they run only within operating boundaries and thresholds that you set. You decide which actions auto-activate versus require individual sign-off.
Full visibility, full reversibility
Every recommendation and action is visible on your dashboard, logged, traceable and auditable. Any parameter can be overridden or reversed immediately.
Outbound-only: the Edge device initiates all communications to the Enerzyz cloud; no inbound ports are ever opened on your network.
TLS 1.2+ encryption on every connection, including the 4G cellular fallback used if the wired connection drops.
No software is installed on any BMS workstation.
ISO/IEC 27001
Certified: the globally recognised information security management standard.
GDPR · PDPA · PIPL
Compliant across the jurisdictions Enerzyz operates in.
Annual penetration testing
Third-party penetration testing of the platform and Enerzyz gateway firmware, conducted annually. Reports available under NDA for qualified enterprise prospects.
Data processing agreement
All data handling runs under DPA ENZ-LEGAL-DPA-001 v3.3, with named sub-processors (AWS, Google Cloud, Enerzyz affiliates) bound by consistent data processing agreements.
Where your data is hosted
Enerzyz operates a multi-cloud backend: AWS Asia Pacific (Singapore), AWS US East (Northern Virginia) and Google Cloud Singapore. Unless a specific customer residency configuration is agreed, customer data may be processed in both Singapore and the United States, and hosting regions may be selected according to customer data-residency requirements where supported. Facility Assessment documents you upload through Bookallil Advisory (utility bills, site photographs) are held separately in Bookallil Advisory's AWS Asia Pacific (Mumbai) environment; Enerzyz platform data does not reside there.
Is this monitoring-only, or can the platform write commands back to our BMS?
Both modes exist, and the choice is entirely yours. Every deployment starts in read-only mode while a baseline is established, and only moves to active optimisation once your team has reviewed and approved the parameters.
If a recommendation is wrong and causes an operational impact, who is responsible?
Your engineering team defines the thresholds within which the system can act, and can require individual approval for any action rather than automatic activation. Nothing executes outside those agreed boundaries, and any action can be reversed immediately.
Does Enerzyz see our guest or back-office data?
No. The gateway connects only to the BMS network and never touches the property management system, guest network, or guest information: those systems are never in scope.
We always use essential cookies to keep this site secure and working. With your consent we also use privacy-friendly analytics (Google Analytics) to understand how the site is used. Choosing Reject keeps the site fully functional. See our Privacy Policy.