Security & ComplianceEngineered to the standards critical infrastructure trusts.
GenieOS is designed in accordance with the cybersecurity frameworks that OT and energy operators rely on — defense-in-depth, segmentation, RBAC, encryption, and audit logging — with data that never has to leave your premises.
Designed and operated in accordance with these frameworks. DJIN EMS does not claim third-party certification.
Security built into the architecture.
GenieOS follows the principles of ISA/IEC 62443 — the international standard for industrial automation and control systems — applied as layered controls, not a bolt-on.
Network segmentation
IT and OT live on separate, controlled networks. A managed Layer-3 switch with VLANs isolates field devices, and a firewalled router governs every conduit between zones.
- Segmented IT / OT network architecture
- VLAN isolation for field devices
- Firewalled, controlled cross-zone traffic
- Air-gap capable — runs with no internet at all
Role-based access control
Every operator action is scoped to a role. Access is least-privilege by design, and remote access is secured and configurable to the site's policy.
- Role-based access control (RBAC)
- Least-privilege operator permissions
- Secure, configurable remote access
- Strong-authentication support at the perimeter
Encryption & audit logging
Communications between components are encrypted, and every meaningful event is recorded to a tamper-evident audit trail you can produce on demand.
- Encrypted inter-component communication
- Continuous audit logging & event tracking
- Deterministic, native system service
- Fault management for system integrity
Resilient by design
The platform is built to keep running when the world around it doesn't — offline-first, locally backed up, and independent of any cloud connection.
- Offline-first operation — no cloud dependency
- UPS-backed continuity
- Cellular failover for connectivity
- Local backups with off-site / cloud options
How GenieOS maps to the six CSF functions.
The dominant US risk-management framework organizes security into six functions. GenieOS maps cleanly to all six.
Documented quality system — controlled docs, revisions, and engineering rigor.
Asset integration and monitoring across every connected vendor in one inventory.
RBAC, encryption, network segmentation, air-gap capability, secure remote access.
On-prem AI anomaly detection, alarms, and continuous audit logging.
Real-time alerts, fault management, and AI-guided root-cause analysis.
Backups, UPS-backed continuity, and offline-first operation.
Mapping reflects GenieOS architecture and capability. It is not an audited assessment or a certification.
Speak your security team's language.
Sophisticated OT and energy buyers evaluate against specific standards. Here is exactly where GenieOS stands against each — and where the line is.
ISA/IEC 62443
The international cybersecurity standard built specifically for industrial automation and control systems. GenieOS is architected in accordance with its foundational principles — defense-in-depth, zones and conduits, identity control, system integrity, and restricted data flow.
- Built to the principles of the 62443 series
- Covers technology, process, and people
- No Security Level (SL) rating is claimed — that requires a formal 62443 assessment
NERC CIP-compatible
DJIN is not a NERC-registered entity — those obligations sit with the asset owner. But the GenieOS architecture is compatible with NERC CIP and is built to support our customers' compliance programs: electronic security perimeters, access control, monitoring, and recovery.
- Compatible architecture — not a registered entity
- Supports CIP-005 / CIP-004 / CIP-007 themes
- Timely as Category 2 IBR registration pulls more DER assets into scope
- Behind-the-meter applicability confirmed with your Regional Entity
CISA CPG 2.0
GenieOS aligns with the CISA Cross-Sector Cybersecurity Performance Goals at the baseline level — the high-value IT and OT practices that have become table stakes for critical-infrastructure operators: access control, segmentation, logging, encryption, backups, and incident detection.
- Aligned with CPG 2.0 foundational IT + OT practices
- Mapped to the same CSF 2.0 structure
- An accessible "we follow recognized baselines" foundation
ISA-101 & IEEE 1547
Operator interfaces are built to ISA-101 HMI principles for consistent, effective industrial displays. And because GenieOS integrates the equipment, it supports the interoperability and communication requirements of IEEE 1547-2018 for grid-connected DERs.
- ISA-101 HMI design principles
- Supports IEEE 1547-2018 interoperability
- UL 1741 SB certification lives on the inverter/DER hardware, not the EMS
Your data stays where you are.
The strongest security control is the one you never have to make. GenieOS runs entirely on-premise — air-gapped if you want it — so operational data never has to leave the building.
The control system, the historian, and the local AI all run on your hardware. No cloud is required to operate the site.
GenieOS runs fully without internet. Disconnect it entirely and every core capability keeps working.
The optional cloud layer sees everything and controls nothing — all control stays on-site, on your network.
A documented quality system behind the platform.
Security is as much process as technology. DJIN maintains a documented quality management system with controlled documents and revision control — the "Govern" function of NIST CSF 2.0, made real.
Designed and operated in accordance with these frameworks. DJIN EMS does not claim third-party certification. Distinctions matter: alignment is engineering practice, attestation and certification are independent audits — and DJIN holds none today.
Have a security questionnaire?
Send it over, or book a demo and we'll walk your team through the GenieOS security architecture.