Data security
Secure the evidence before opening the account.
The first review collects limited information. Detailed utility and cultivation records move only after the matter is screened and an appropriate process is established.
Last reviewed: July 20, 2026
Public-form limits
The public form is not a secure document portal. Do not submit utility account numbers, login credentials, payment information, tax identifiers, license numbers, plant-tracking data, employee records, facility-security information, or unnecessary sensitive documents.
Data-minimization principles
- Collect only information reasonably needed for screening or the engagement
- Request records in stages rather than copying an entire environment by default
- Use exported records instead of shared passwords whenever practical
- Remove unrelated personal or regulated information
- Define who needs access and why
- Retain the source and version of material evidence
Document transfer
The appropriate method depends on sensitivity, volume, client systems, and engagement terms. Options may include a secure client portal, approved encrypted transfer, controlled cloud folder, or another agreed process. Ordinary email may not be appropriate for sensitive records.
Access and handling
Access should be limited to authorized personnel and service providers with a business need. Devices, accounts, storage, backups, and transmission methods should be configured with reasonable safeguards appropriate to the information.
Client responsibilities
Clients should confirm authority to provide records, maintain their own backups, avoid shared credentials, promptly remove access when no longer needed, and notify us of known security or confidentiality requirements.
Incident communication
Suspected unauthorized access or disclosure should be reported promptly to support@utilitycreditplus.com with enough information to identify the affected engagement. Do not include passwords in the notice.
Production configuration
Actual security depends on the production host, WordPress core, plugins, user accounts, SMTP, backups, logging, certificates, updates, and administrators. The launch checklist must be completed on the live environment.