Security & Site Trust
This page is published by Energy Innovation FZE so that security reviewers, corporate web filters and IT teams can verify how energyinnvo.com is operated. Last reviewed: August 2026.
Encryption in transit
All traffic to energyinnvo.com is served over HTTPS (TLS) with HTTP/2 and HTTP/3, using a publicly trusted certificate. Plain HTTP requests are redirected to HTTPS.
Hosting & infrastructure
The site is a static front-end hosted on a managed commercial hosting platform, with content and form data stored in a managed PostgreSQL service (Supabase). Administrative access to the content system is password protected and limited to company staff.
Site purpose & content
energyinnvo.com is the corporate website of Energy Innovation FZE, a UAE-based MEP, HVAC, fire protection and industrial engineering contractor and supplier. It publishes company, product and project information and contact forms. It hosts no downloads other than our own product brochures and newsletters, no advertising, no user-generated content and no third-party redirects.
Suggested web-filter category: Business / Industry & Manufacturing.
Reporting a security concern
If you believe you have found a vulnerability or abuse of this domain, email info@energyinnvo.com. Please include steps to reproduce. We aim to acknowledge reports within two business days.
Machine-readable contact: /.well-known/security.txt
HTTP security headers
| Header | Value | Purpose |
|---|---|---|
| Strict-Transport-Security | max-age=31536000; includeSubDomains | Browsers are told to only ever reach the site over HTTPS. |
| X-Content-Type-Options | nosniff | Prevents browsers from guessing file types. |
| X-Frame-Options | SAMEORIGIN | Blocks the site being framed by third parties (clickjacking). |
| Referrer-Policy | strict-origin-when-cross-origin | Limits what referrer data leaves the site. |
| Content-Security-Policy | upgrade-insecure-requests | Any legacy HTTP asset request is upgraded to HTTPS. |
| Permissions-Policy | geolocation=(), microphone=(), camera=(), payment=() | Sensitive browser APIs are disabled site-wide. |
Headers are applied at the web-server layer. Reviewers can verify them independently with any HTTP header inspector against https://energyinnvo.com.
