Cultivation Utility Intelligence
Data Security Policy
Utility Credit Plus — Services & Data Security Policy
Purpose & Scope
This policy explains how Utility Credit Plus, LLC (“Utility Credit Plus,” “UCP,” “we,” “us”) delivers its services and protects customer data processed by our platform and professional services. Our services involve evaluating utility billing records, identifying delayed or improper billing (such as extended periods of no billing followed by sudden “catch-up” bills), filing credit or dispute requests, and working with utility providers to reduce or eliminate large, unexpected balances for eligible customers.
This policy applies to all UCP employees, contractors, systems, and approved subprocessors that access or store Utility Credit Plus data.
Services Overview
Our core services include:
- Initial eligibility screening and intake (no upfront cost to apply).
- Review of historical billing records across electric, gas, water, sewer, trash, and similar services.
- Assessment of legal and regulatory protections applicable to delayed or improper billing.
- Preparation and submission of claims, disputes, or credit requests to utility providers.
- Direct coordination with utility representatives to request credits, waivers, or payment accommodations.
- Ongoing updates and documentation management until final resolution.
Pricing: We operate on a results-based model — you pay only when credits or savings are realized. There is no cap on eligible utility credits captured for your account.
Data We Process
We collect only the data required to deliver our services effectively, including:
- Client / Account Holder Data: contact information, service addresses, utility account numbers, company identifiers (e.g., legal name, EIN), and authorized representatives.
- Billing Records & Evidence: copies of bills, meter reads, notices, statements, and correspondence showing delayed or inaccurate billing.
- Operational & Security Data: audit logs, device and IP attributes, usage telemetry, and support interactions.
Sensitive Identifiers: SSN/EIN and ID images present in billing files are treated as Confidential and protected with heightened controls.
Data Classification
- Confidential: utility account numbers, SSN/EIN, ID images, billing records, authentication secrets, encryption keys.
- Internal: configuration files, runbooks, internal documents, and non-public materials.
- Public: marketing content and publicly available help docs.
Controls scale based on classification, including encryption, limited access, retention policies, and monitoring.
Security Governance
The Head of Security (or designee) oversees this policy, risk assessments, vendor diligence, incident response, and compliance programs.
Security standards—including access control, key management, vulnerability management, SDLC practices, and DR/BCP—are reviewed annually or when material changes occur. Personnel receive security and privacy training annually, with additional requirements for privileged roles. Background checks are performed where lawful.
Access Control & Authentication
- Least privilege and role-based access control (RBAC).
- Multi-factor authentication (MFA) required for administrative access.
- Secure session controls including timeouts and anomalous login detection.
- Logical tenant data segregation preventing cross-tenant exposure.
Encryption & Key Management
- In Transit: TLS 1.2+ for all data transfers.
- At Rest: AES-256 or stronger for all Confidential data.
- Key Management: HSM-backed secrets manager with access logging and rotation.
Network & Infrastructure Security
- Segmented networks, private subnets, and restricted egress.
- WAF, DDoS protection, IDS/IPS, and endpoint detection tools.
- CIS-aligned operating system baselines and secure boot where supported.
Application Security (Secure SDLC)
- Development aligned with OWASP ASVS and OWASP Top 10.
- Automated dependency and secret scanning.
- Annual third-party penetration testing (summary available under NDA).
Vulnerability & Patch Management
- Continuous scanning across apps, containers, and infrastructure.
- Monthly external attack-surface scanning.
- Remediation SLAs: Critical 7 days, High 30 days, Medium 90 days.
Logging, Monitoring & Alerting
- Immutable, centralized logging for authentication, data access, configuration changes, and integrations.
- Minimum 12-month log retention in tamper-resistant storage.
- 24/7 alerting for anomalous events (e.g., mass exports, abnormal lookups).
Data Handling, Storage & Transmission
- Sensitive fields (SSN/EIN) masked in interfaces and redacted from logs.
- All uploads virus-scanned and content-validated.
- Emailing Confidential data is prohibited; secure portals or encrypted transfer required.
- Exports of Confidential data require elevated permissions and full audit logs.
Data Retention & Deletion
Utility case files are retained for the duration of the engagement and an additional period as needed for audits, dispute follow-up, or legal requirements—unless a shorter retention period is legally permissible and specifically requested by the customer.
Upon termination or verified deletion request, data is securely deleted or returned within agreed timelines. Backups are cryptographically destroyed at end-of-life.
Backups, Business Continuity & Disaster Recovery
- Encrypted daily backups and point-in-time recovery.
- Redundant infrastructure across availability zones.
- Target RPO ≤ 24 hours, RTO ≤ 48 hours for core services.
- Annual disaster recovery and incident response exercises.
Incident Response & Breach Notification
Our process includes preparation, detection, containment, eradication, recovery, and post-incident review.
We notify affected customers without undue delay after confirming a breach involving their data, following applicable laws including California CPRA/§1798.82.
Physical & Personnel Security
- Use of SOC 2 / ISO 27001-aligned data centers with 24×7 staffed security, access logs, and biometric controls.
- Office protections: badge access, visitor logs, secure shredding, clean-desk requirements.
- Corporate devices with full-disk encryption, mobile device management (MDM), and enforced screen locks.
Third-Party Risk Management
- Documented inventory of subprocessors and data flows.
- Security and privacy diligence at onboarding and annually for material vendors.
- Use of SOC 2 reports, pen-test summaries, and data-processing agreements (DPAs) where appropriate.
- Cross-border transfers follow applicable laws and standard contractual clauses.
Privacy & Consumer Rights
We maintain controls that support privacy rights under CCPA/CPRA and similar laws, including rights to access, delete, correct, port, opt-out of sale/share, and limit use of sensitive information, consistent with our Privacy Policy.
Customer Responsibilities (Shared Responsibility)
Customers are responsible for implementing user-level protections including:
- Configuring roles and MFA where supported.
- Securing API keys, SSO configurations, and endpoints.
- Limiting unnecessary printing or local storage of case files.
- Promptly notifying UCP of suspected credential or device compromise.
Prohibited Practices
- Storing production Confidential data in personal or unsecured drives.
- Circumventing MFA or sharing user accounts.
- Exporting Confidential data without valid business purpose and management approval.
Revisions
We may update this policy from time to time to reflect improvements, legal changes, or service updates. The posted Effective Date reflects the latest revision.
Security & Support Contact
Email: support@utilitycreditplus.com
Phone (business hours): (844) 438-9682
Mailing Address: Utility Credit Plus, LLC — 30 N Gould St, Sheridan, WY 82801
Website: utilitycreditplus.com