Security
This page supports supplier security reviews of TOGL Energy Limited. It states what is true today about how this website and the TOGL platform handle security. Where a control or certification does not yet exist, this page says so rather than implying otherwise, and it will be updated as pilot scope and controls change.
Last updated
1. This website
The site is a statically rendered application hosted on Vercel and served entirely over HTTPS, with HTTP Strict Transport Security enabled. It operates no database and no user accounts by design: there is no stored credential set to breach, and no customer data store behind the site.
Analytics run under Google Consent Mode v2 and are switched off by default. No analytics or marketing cookies are set until a visitor consents, and consent choices can be changed at any time via the cookie policy.
2. Forms and your data
The site’s forms collect business contact details only: name, work email, company, and the content of an enquiry. No payment information is collected anywhere on the site. Submissions are validated on the server, rate limited, and passed to Brevo, which is the system of record for enquiries and early access requests. They are not stored on this website.
Form submissions are processed by serverless functions pinned to Vercel’s London region (lhr1), and Brevo, the recipient, is an EU provider. No form data is processed outside the UK and EEA by this website.
How personal data is used, the lawful bases, retention and your rights are set out in the privacy notice.
3. Sub-processors
Three third parties process data on TOGL’s behalf in connection with this website. The same list appears in the privacy notice.
- Vercel
- Website hosting and content delivery
- Brevo
- Transactional email and contact records for enquiries
- Analytics, only after a visitor has consented
4. The TOGL platform
The TOGL platform is being tested through closed pilots, with capability availability published on the platform page. Two security-relevant commitments are fixed in its design rather than added later. Access to vehicle and site data is permissioned per organisation: a fleet’s data is its own. And the failure mode is charging, not stranding: if TOGL cannot reach a vehicle or charger, the site falls back to charging in line with the duty cycle it has to meet, so optimisation degrades while readiness does not.
Specific platform controls, hosting arrangements and data flows will be published on this page as pilots begin, and are available to prospective partners under NDA before then via info@togl.co.
5. Certifications
TOGL Energy Limited does not currently hold a security certification such as Cyber Essentials or ISO 27001. This page will state the certification and date when that changes, and will not claim one before it is held.
TOGL is pursuing Cyber Essentials Plus, with the certification work beginning in September 2026. Cyber Essentials Plus includes an independent technical audit rather than a self-assessment alone, which is why it was chosen over the base scheme. Until the certificate is issued, TOGL is an organisation working towards it and nothing on this page should be read as implying otherwise.
6. Reporting a vulnerability
Reports of a vulnerability in this website or in any TOGL service are welcome and are read by the founding team. Email info@togl.co with enough detail to reproduce the issue, and do not access or modify data that is not yours in the course of testing. A machine-readable contact is published at /.well-known/security.txt.