WeaveGrid Renews SOC 2 Compliance Across All Five Trust Service Criteria

WeaveGrid continues to uphold its commitment to SOC 2 Type II compliance at the highest standard the framework offers, because grid edge orchestration demands complete accountability. Here’s what that means for our partners.
Utilities and device manufacturers evaluating software partners for grid edge orchestration know that security is a foundational prerequisite. As distributed energy resources like EVs, batteries, and smart thermostats multiply across the low-voltage grid, the software orchestrating them operates at a sensitive intersection of critical infrastructure: behind-the-meter customer devices, utility operational data, and real-time grid control signals. The platform trusted with that responsibility must prove its operational integrity formally and repeatedly.
Through an independent third-party audit, this compliance confirms that WeaveGrid’s systems and controls meet the most stringent requirements across all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
All Five Criteria Matter for Grid Edge Orchestration
SOC 2 is a compliance framework established by the American Institute of Certified Public Accountants (AICPA) to evaluate how organizations manage and protect customer data across five criteria:
- Security: Controls protect against unauthorized access, use, or disclosure.
- Availability: Systems remain operational as committed, supporting the reliability demands of utility programs, at scale.
- Processing Integrity: System processing is complete, valid, accurate, and authorized, which is essential for the integrity of continuous load flexibility dispatch and M&V.
- Confidentiality: Confidential information is protected throughout its lifecycle, including sensitive operational and customer data.
- Privacy: Personal information is safely collected, used, retained, disclosed, and deleted in conformity with privacy commitments.
WeaveGrid Sets a Higher Standard
Most software vendors in the DER space pursue SOC 2 compliance on the Security category alone, while a few may add Availability. Pursuing all five criteria requires building and maintaining a far more extensive control environment and accepting a broader, more rigorous audit scope.
WeaveGrid invested in compliance across all five categories because grid edge orchestration demands complete accountability. Our DISCO platform orchestrates hundreds of megawatts of flexible load in the largest distribution optimization programs nationwide, handling real-time signals and sensitive customer energy data. Utilities and device manufacturers need a partner who can demonstrate through a trusted third party that their controls hold up across every operational dimension.
Scaling Multi-DER Load Flexibility on a Vetted Platform
DISCO gives utilities a single, trusted interface for grid edge orchestration, coordinating device-level load flexibility at the feeder, transformer, and bulk system level. It delivers a single dispatch center with comprehensive reporting, proven at scale.
As utilities look to leverage multi-DER load flexibility to support reliability and affordability objectives, they need a software partner they can trust with data, devices, and grid stability. Maintaining SOC 2 Type II compliance across all five Trust Service Criteria affirms that WeaveGrid is that partner.
What This Means for Our Partners
For current WeaveGrid utility and device partners, this report represents continued investment in the security and operational rigor of the platform you depend on. To request a copy of our SOC 2 Type II report of compliance, contact your WeaveGrid account team.
For utilities and device manufacturers evaluating grid edge DERMS solutions, we welcome the opportunity to discuss our security posture in detail as part of your due diligence process. Contact us here.
.png)




.png)







.png)








.png)




