The two diligence questions no vendor page answers first: what happens if we disappear, and what the security posture actually is.
Continuity & security — the two questions diligence asks first
A note for investment committees, fund operations teams and their InfoSec
reviewers: what happens to your workflow if the vendor stops operating, and
what the security posture actually is. Both answers here are structural
rather than promissory, and every claim on this page is checkable — in the
product, on a published page, or in a walk-through on request. Where the
honest answer is "we don't have that", this page says so.
1. The two objections, named
CECadence is built and operated by a small team at Compounding Energy Ltd.
Vendor-continuity risk — the "key person" question — is therefore real, and
we would rather answer it with architecture than with reassurance. Likewise
on security: we hold no third-party certifications, and this page will not
imply otherwise. It states what is enforced, where it is enforced, and what
to ask for when your review needs more than a page.
2. Continuity: a licence you run, not our uptime
The continuity option is the on-prem / air-gapped deployment (the
Enterprise tier): the same product, running in your own VPC or on your own
hardware, under a signed licence.
Licence verification is fully offline. A customer-run build verifies
an Ed25519-signed licence at startup against a verifying key embedded in
the build. The signature check is local — there is no licence server to
reach and no call home — so a validly licensed deployment does not depend
on any Compounding Energy infrastructure being up, reachable, or staffed
for the duration of its licensed term.
Air-gapped operation is supported by design. In offline mode the
product makes no outbound network call: forward scenarios, site appraisals
and the 2022–2025 backtests all run from the data caches bundled with the
image. Live fetches and the trailing-anchor refresh are disabled
deliberately, not broken accidentally.
Data currency ages visibly, never silently. A customer-run deployment
ships a snapshot of the GB data (the published index plus the model
calibration), current to a stated date. Past the licensed freshness
window the deployment declares itself stale — a banner stating exactly how
old the bundled calibration is — and keeps operating. The numbers never
change silently; renewal delivers the current quarterly index and
recalibration bundle and clears the flag. The licence itself is an annual,
renewing relationship.
The honest limit. On-prem is sales-assisted (a contract, not a
checkout button), and a deployment that outlives its vendor would stop
receiving data updates — the staleness banner is the designed, visible
form of that decay. What the architecture removes is the cliff: your
analysts' tool, their saved runs, and their audit trail keep working on
your infrastructure, on data whose age is always on screen.
3. Audit & reproducibility
Every run carries its reproducibility key. Each model run is persisted
with a manifest recording the scenario id, the code version (the build's
git SHA), the run timestamp, and the random seeds — the audit trail is
reconstructable without re-running, and a specific number in a committee
paper can be traced to the exact build and inputs that produced it.
Validation rules are pre-registered in public. Every validation rule
is frozen in a dated commit before the data it is judged against is
fetched, and the grades are published whatever they say — the public
record, with freeze-commit hashes, dates and the published failures, is at
/heldout-protocol.html. A record that includes
its own FAIL verdicts and rejected model changes is one a reviewer can
weigh, not just trust.
The benchmark is measured from primary data. The quarterly CE GB BESS
Index is computed from Elexon settlement and NESO auction records under
their open licences, with every convention and exclusion quantified:
/quarterly/latest.html.
4. Security posture, stated plainly
What is true today, and checkable:
Entitlements are enforced server-side. Plan and feature gates are
checked on the API, per request — hidden buttons in the interface are a
courtesy, not the security boundary.
Tenant isolation is structural. Each customer's runs, labels and
scenarios live in a private per-tenant store, bound per request from the
authenticated key. API keys are never stored in plaintext — only salted
hashes, compared in constant time — and a key is shown once, at creation.
Role separation (viewer / analyst / admin) applies within each tenant.
The data supply chain is primary and open. Model inputs and the
published index come from Elexon (BMRS) and NESO open data under their
open licences. There is no third-party data-broker or commercial
benchmark-licence dependency to fail, be revoked, or carry someone else's
terms.
Hosting is deliberately simple. The hosted service runs in a single
region (London, close to the GB market it models) on Fly.io, with TLS
enforced for all traffic by the platform. The data volume is snapshotted
daily by the provider, and an offsite metadata archive — tenants, keys (as
hashes), run manifests, audit trail — can be produced with one command and
held off-platform. The restore path is exercised by an automated test in
the product's own suite: a backup that has never been restored is a hope,
not a backup.
What we do not claim. No SOC 2 or ISO 27001 certification today, and
no invented equivalents. A fund whose process requires a completed
security questionnaire, an architecture walk-through, or a review of the
controls above at source level can request any of them — that is the
designed route, not an exception.
5. Questions funds ask — where the answers live
The question
Where the answer lives
What happens to our workflow if the vendor stops operating?
No (§4) — questionnaires answered and controls demonstrated on request
How should a lender use the forecasts?
The underwriting note — the sizing procedure and exactly how to treat the published tail failure
Talking to your reviewers
For the security questionnaire, the architecture walk-through, on-prem
licensing terms, or a line-by-line reconciliation of any claim on this page,
email hello@compoundingenergy.com.
Forecasts are projections, not advice. This page describes product
architecture and operational posture; it is not a contractual service
commitment, which lives in the written agreement for your deployment.