Overview
Myrspoven publishes its security, privacy, and compliance posture at trust.myrspoven.com. The portal is the single source of truth for commitments, certifications, and documentation available on request. This page points to it and outlines what the rest of the chapter covers.
Procurement and legal: the trust portal holds the formal artifacts — ISO/IEC 27001:2022 certificate and scope, subprocessor list, security overview, privacy statement, questionnaire responses. Technical operations and integrators: this chapter covers the operational details that come up during onboarding and day-to-day use — building connectivity, myPortal access, incident handling.
Where to look
For formal artifacts, start at trust.myrspoven.com. The portal is kept current; this documentation site is not.
The trust portal covers:
Certifications. Myrspoven is certified to ISO/IEC 27001:2022. Certificate and scope are on the portal.
Security overview. Protection of customer data and building connections — hosting region, encryption, access control, incident handling.
Privacy and data handling. Personal data processing, retention, data subject rights, and the current product privacy statement.
Subprocessors. Third parties involved in delivering the service.
Authentication and access controls. Controls enforced by Myrspoven and those configurable by the customer.
Vulnerability disclosure. Reporting process and response expectations.
Questionnaire responses. Standard responses to common procurement questionnaires, available on request.
What's in this chapter
The pages in this chapter complement the trust portal with operational, customer-facing detail:
Building connectivity from a security standpoint — outbound-only connections, scoped setpoint writes, no inbound exposure of the Building Management System (BMS).
myPortal user access — per-user accounts, MFA, role-based permissions.
Handling of suspected security issues.
The trust portal owns the formal posture. The pages below cover practical operation.
Reporting a security concern
Suspected security issues affecting customer data or buildings are reported to the Myrspoven representative immediately and flagged as urgent. Vulnerability reports follow the disclosure process linked on trust.myrspoven.com.
Last updated
Was this helpful?

