Security & Compliance

Engineered to the standards critical infrastructure trusts.

GenieOS is designed in accordance with the cybersecurity frameworks that OT and energy operators rely on — defense-in-depth, segmentation, RBAC, encryption, and audit logging — with data that never has to leave your premises.

Aligned with ISA/IEC 62443Maps to NIST CSF 2.0CISA CPG 2.0 baselineNERC CIP-compatible architectureBuilt to ISA-101 HMI principlesSupports IEEE 1547 interoperabilityAir-gapped & on-premise data residencyDocumented quality system (QMS)

Designed and operated in accordance with these frameworks. DJIN EMS does not claim third-party certification.

Defense in Depth

Security built into the architecture.

GenieOS follows the principles of ISA/IEC 62443 — the international standard for industrial automation and control systems — applied as layered controls, not a bolt-on.

Zones & Conduits

Network segmentation

IT and OT live on separate, controlled networks. A managed Layer-3 switch with VLANs isolates field devices, and a firewalled router governs every conduit between zones.

  • Segmented IT / OT network architecture
  • VLAN isolation for field devices
  • Firewalled, controlled cross-zone traffic
  • Air-gap capable — runs with no internet at all
Identity & Access

Role-based access control

Every operator action is scoped to a role. Access is least-privilege by design, and remote access is secured and configurable to the site's policy.

  • Role-based access control (RBAC)
  • Least-privilege operator permissions
  • Secure, configurable remote access
  • Strong-authentication support at the perimeter
Confidentiality & Integrity

Encryption & audit logging

Communications between components are encrypted, and every meaningful event is recorded to a tamper-evident audit trail you can produce on demand.

  • Encrypted inter-component communication
  • Continuous audit logging & event tracking
  • Deterministic, native system service
  • Fault management for system integrity
Availability

Resilient by design

The platform is built to keep running when the world around it doesn't — offline-first, locally backed up, and independent of any cloud connection.

  • Offline-first operation — no cloud dependency
  • UPS-backed continuity
  • Cellular failover for connectivity
  • Local backups with off-site / cloud options
NIST Cybersecurity Framework 2.0

How GenieOS maps to the six CSF functions.

The dominant US risk-management framework organizes security into six functions. GenieOS maps cleanly to all six.

Govern

Documented quality system — controlled docs, revisions, and engineering rigor.

Identify

Asset integration and monitoring across every connected vendor in one inventory.

Protect

RBAC, encryption, network segmentation, air-gap capability, secure remote access.

Detect

On-prem AI anomaly detection, alarms, and continuous audit logging.

Respond

Real-time alerts, fault management, and AI-guided root-cause analysis.

Recover

Backups, UPS-backed continuity, and offline-first operation.

Mapping reflects GenieOS architecture and capability. It is not an audited assessment or a certification.

The Frameworks

Speak your security team's language.

Sophisticated OT and energy buyers evaluate against specific standards. Here is exactly where GenieOS stands against each — and where the line is.

OT Cybersecurity

ISA/IEC 62443

The international cybersecurity standard built specifically for industrial automation and control systems. GenieOS is architected in accordance with its foundational principles — defense-in-depth, zones and conduits, identity control, system integrity, and restricted data flow.

  • Built to the principles of the 62443 series
  • Covers technology, process, and people
  • No Security Level (SL) rating is claimed — that requires a formal 62443 assessment
Grid Regulatory

NERC CIP-compatible

DJIN is not a NERC-registered entity — those obligations sit with the asset owner. But the GenieOS architecture is compatible with NERC CIP and is built to support our customers' compliance programs: electronic security perimeters, access control, monitoring, and recovery.

  • Compatible architecture — not a registered entity
  • Supports CIP-005 / CIP-004 / CIP-007 themes
  • Timely as Category 2 IBR registration pulls more DER assets into scope
  • Behind-the-meter applicability confirmed with your Regional Entity
Baseline Practices

CISA CPG 2.0

GenieOS aligns with the CISA Cross-Sector Cybersecurity Performance Goals at the baseline level — the high-value IT and OT practices that have become table stakes for critical-infrastructure operators: access control, segmentation, logging, encryption, backups, and incident detection.

  • Aligned with CPG 2.0 foundational IT + OT practices
  • Mapped to the same CSF 2.0 structure
  • An accessible "we follow recognized baselines" foundation
Interfaces & Interoperability

ISA-101 & IEEE 1547

Operator interfaces are built to ISA-101 HMI principles for consistent, effective industrial displays. And because GenieOS integrates the equipment, it supports the interoperability and communication requirements of IEEE 1547-2018 for grid-connected DERs.

  • ISA-101 HMI design principles
  • Supports IEEE 1547-2018 interoperability
  • UL 1741 SB certification lives on the inverter/DER hardware, not the EMS
Data Residency

Your data stays where you are.

The strongest security control is the one you never have to make. GenieOS runs entirely on-premise — air-gapped if you want it — so operational data never has to leave the building.

On-premise first

The control system, the historian, and the local AI all run on your hardware. No cloud is required to operate the site.

Air-gap capable

GenieOS runs fully without internet. Disconnect it entirely and every core capability keeps working.

Cloud: view-only

The optional cloud layer sees everything and controls nothing — all control stays on-site, on your network.

Governance & Rigor

A documented quality system behind the platform.

Security is as much process as technology. DJIN maintains a documented quality management system with controlled documents and revision control — the "Govern" function of NIST CSF 2.0, made real.

Controlled documents & revisionsDocumented engineering processes Defined supply-chain practices Aligned with ISO 9001Aligned with ISO/IEC 27001SOC 2 Type II on the roadmap

Designed and operated in accordance with these frameworks. DJIN EMS does not claim third-party certification. Distinctions matter: alignment is engineering practice, attestation and certification are independent audits — and DJIN holds none today.

Have a security questionnaire?

Send it over, or book a demo and we'll walk your team through the GenieOS security architecture.