
Security
Security at Anchor Utility
At Anchor Utility, the trust our clients, partners, and employees place in us is something we work to earn every day. Protecting the data we’re entrusted with — and being transparent about how we do it — is a core part of how we operate, not an afterthought.
Our commitment to security
Anchor Utility is currently aligning its internal controls with the SOC 2 Trust Services Criteria, covering the security, availability, and confidentiality of the systems and data we manage on behalf of our clients. This is an ongoing program, built on practices including:
- Access management: Role-based access controls and least-privilege access to client and company systems.
- Data protection: Encryption of sensitive data in transit and, where applicable, at rest.
- Vendor oversight: Regular review of vendors and service providers who handle data on our behalf.
- Employee training: Ongoing security and privacy awareness training for our team.
- Incident response: Documented procedures for identifying, escalating, and responding to security incidents.
We’ll continue to update this page as our program matures.
Reporting a security or privacy concern
If you believe you’ve found a security vulnerability, a privacy issue, or suspicious activity involving Anchor Utility, we want to hear about it. This applies whether you’re a client, partner, vendor, employee, or independent researcher.
Email: security@anchorutility.com
When you reach out, please include as much of the following as you can:
- A description of the issue and where you observed it (URL, system, or process).
- Steps to reproduce the issue, if applicable.
- Any relevant screenshots, logs, or supporting details.
- Your contact information, so we can follow up with questions or updates.
This mailbox is monitored by our security team. We will acknowledge receipt of your report within 3 business days and will follow up as our review progresses. Reports are handled confidentially and shared only with the people who need to know in order to investigate and resolve them.
Responsible disclosure
We ask that anyone reporting a concern act in good faith: avoid accessing, modifying, or deleting data beyond what’s needed to demonstrate an issue, avoid disrupting our services, and give us a reasonable opportunity to investigate and address the issue before sharing it publicly. We will not pursue legal action against researchers who make a good-faith effort to follow this approach.
Other ways to reach us
For general questions about our privacy practices, please contact us through our standard support channels. For anything security-related, please use the email address above so it reaches the right team quickly.
