Site security

    Security & Site Trust

    This page is published by Energy Innovation FZE so that security reviewers, corporate web filters and IT teams can verify how energyinnvo.com is operated. Last reviewed: August 2026.

    Encryption in transit

    All traffic to energyinnvo.com is served over HTTPS (TLS) with HTTP/2 and HTTP/3, using a publicly trusted certificate. Plain HTTP requests are redirected to HTTPS.

    Hosting & infrastructure

    The site is a static front-end hosted on a managed commercial hosting platform, with content and form data stored in a managed PostgreSQL service (Supabase). Administrative access to the content system is password protected and limited to company staff.

    Site purpose & content

    energyinnvo.com is the corporate website of Energy Innovation FZE, a UAE-based MEP, HVAC, fire protection and industrial engineering contractor and supplier. It publishes company, product and project information and contact forms. It hosts no downloads other than our own product brochures and newsletters, no advertising, no user-generated content and no third-party redirects.

    Suggested web-filter category: Business / Industry & Manufacturing.

    Reporting a security concern

    If you believe you have found a vulnerability or abuse of this domain, email info@energyinnvo.com. Please include steps to reproduce. We aim to acknowledge reports within two business days.

    Machine-readable contact: /.well-known/security.txt

    HTTP security headers

    HeaderValuePurpose
    Strict-Transport-Securitymax-age=31536000; includeSubDomainsBrowsers are told to only ever reach the site over HTTPS.
    X-Content-Type-OptionsnosniffPrevents browsers from guessing file types.
    X-Frame-OptionsSAMEORIGINBlocks the site being framed by third parties (clickjacking).
    Referrer-Policystrict-origin-when-cross-originLimits what referrer data leaves the site.
    Content-Security-Policyupgrade-insecure-requestsAny legacy HTTP asset request is upgraded to HTTPS.
    Permissions-Policygeolocation=(), microphone=(), camera=(), payment=()Sensitive browser APIs are disabled site-wide.

    Headers are applied at the web-server layer. Reviewers can verify them independently with any HTTP header inspector against https://energyinnvo.com.