Operational status
Alvo readiness for demo, pilot, and production integrations.
This page shows which platform layers are operational, what still requires legal or production review, and which security mode is active now.
Data runtime
Current market-data path without secrets.
Shows whether the Nest/Postgres/Redis platform path is ready and whether Next may still use live OREE as a migration fallback.
This mode is suitable for demos and migration. For staging/production, disable fallback after the DB-read path is verified.
Production gates
Stable launch control.
Separate from basic health, this shows what is ready for paid pilots, what needs review, and what blocks production access.
Protected API
Production API access must run in protected mode with a server-side key and no secret leakage.
Owner: securityExternal auth
Paid workspaces need tenant identity, roles, SSO/MFA-ready auth, and access audit.
Owner: securityTenant RBAC
Roles and high-risk permissions must actually guard APIs, exports, and the future submit flow.
Owner: securityData freshness
OREE, licence-gated UEEX, and future sources need freshness checks, blocker handling, and fallback behavior.
Owner: dataDurable audit trail
Events must be tenant-aware and usable for evidence, exports, and incident review.
Owner: platformNotifications
Push/alert delivery needs keys, provider, subscription storage, and future role-based limits.
Owner: productTrust layer
Diia/QES/document flows require legal basis, consent, retention policy, and data-minimized UX.
Owner: legalSecurity
API key required: no
PWA notifications
Notification layer for signals, risk updates, and future alerts.
Shows whether browser subscription is only contract-ready or whether production delivery is configured through a provider, VAPID keys, and tenant storage.
Next step: add the production private key, choose the delivery provider, and connect tenant-scoped subscription storage.
Security posture
OWASP, SOC 2, HIPAA scope, and auth without overclaiming.
Shows the real control state: what already exists in code, what needs production review, and which auth layer should become the next foundation.
WorkOS
- Required
- no
- Configured
- yes
- Mode
- public demo
- Recommendation
- WorkOS
OWASP ASVS
The current baseline already has headers, CSP, validation, rate limiting, upstream allowlists, and an audit trail.
Before production, map every ASVS requirement to a test or owner.SOC 2
Initial technical evidence exists for Security: health, audit, API access control, and repeatable CI checks.
Next we need policies, evidence owners, incidents, vendor review, and change management.HIPAA
Out of scope while Alvo handles energy-market data and does not process PHI/ePHI.
Revisit HIPAA only if a healthcare or PHI workflow appears.Auth provider
We need a provider-agnostic OIDC/JWT layer with organizations, roles, MFA, SSO, and audit.
For B2B pilots, WorkOS is the first candidate, while domain code stays provider-independent.RBAC
Roles and permissions are defined as a code contract for tenant, API, trader, risk, and audit work.
Connect RBAC to the auth adapter, tenant id, and policy tests before paid pilots.Access and roles
Least-privilege model for teams, APIs, and future submit flows.
Roles are fixed before wiring the auth provider, so WorkOS/Clerk/Auth0 provide identity while Alvo owns domain policy.
Owner
Manages tenant, API, roles, settings, and critical approvals.
14 permissionsTrader
Works with market data, plans, AI briefs, BESS, and exports.
8 permissionsAnalyst
Prepares data, scenarios, backtests, and explanations without admin actions.
6 permissionsRisk control
Reviews risks, audit evidence, and future high-risk approvals.
5 permissionsAPI client
Service access to calculations and exports without tenant administration.
6 permissionsAuditor
Read-only access to audit trail, risks, and action evidence.
3 permissionsRBAC is enabled: next step is tenant-scoped policy tests for API and submit flows.
Data sources
Integration registry powering the trading decision.
Shows what is already connected, which sources require a token or approval, and what moves into later releases.
Market Operator
connectedOfficial DAM/IDM layer: hourly prices and indexes.
Used as the primary trading layer for DAM recommendations and market-day validation.API: /api/oree/prices, /api/oree/indexesSourceUkrainian Energy Exchange
reviewBCM BASE indexes for a longer-horizon benchmark context — licence-gated (require a written UEEX redistribution agreement).
Helps compare DAM spreads with longer contractual price indicators.API: /api/ueex/electricity-indexesSourceENTSO-E Transparency Platform
connectedLoad, generation, cross-border flows, and system context for price forecasting.
This layer improves forecasting quality and the explanation of price movements.API: connectedSourcePSE (Polish TSO)
reviewPolish day-ahead prices (RCE) as the UA↔PL neighbour-basis reference — TSO open data.
The Polish TSO publishes these as public-sector information; reuse is permitted with mandatory source attribution.API: reviewSourceUkrenergo
reviewSystem balance, consumption, generation, grid constraints, and outage signals.
Gives AI context for peak hours, shortage/surplus states, maintenance, and transmission constraints.API: reviewSourceWeather provider layer
reviewTemperature, wind, solar radiation, cloud coverage, and precipitation for load and generation forecasts.
Weather data is critical for solar/wind output, load spikes, and volatility explanations.API: reviewSourceFuel and carbon benchmarks
reviewGas storage, carbon intensity, and EU ETS as power-system and CBAM context.
Helps explain the fuel backdrop and risks for thermal generation and imports; not presented as a validated UA DAM price driver.API: reviewSourceEnergy Map
connectedUkrainian aggregated energy datasets for a broader market picture.
Can enrich the model with generation, consumption, regional, and reference datasets.API: connectedSourceNEURC
reviewRegulatory decisions, tariffs, licensing, and compliance signals.
Needed for risk control, audit-ready explanations, and the legal layer of the product.API: reviewSourceAntimonopoly Committee of Ukraine
reviewMarket monitoring, competition, concentration, and antimonopoly signals.
Useful for compliance explanations, market limits, and a future anti-manipulation layer.API: reviewSourceFreshness SLA
Supplemental SLA signals for platform jobs.
Shows the latest recorded signal for jobs outside provider cards. Meaning varies by row: ENTSO-E vintage archives report capture-attempt timing, not proof of usable content.
Air-raid alert capture
within SLA- Latest signal
- Jul 21, 2026, 10:30 PM
- Budget
- 10%
- Cadence
- live air-raid alert feed
UKRAINEALARMEntsoe Outages Hu
within SLA- Latest signal
- Jul 21, 2026, 2:45 AM
- Budget
- 66%
- Cadence
- daily ENTSO-E neighbour outage fact capture
ENTSOE_OUTAGES_HUEntsoe Outages Pl
within SLA- Latest signal
- Jul 21, 2026, 2:45 AM
- Budget
- 66%
- Cadence
- daily ENTSO-E neighbour outage fact capture
ENTSOE_OUTAGES_PLEntsoe Outages Ro
within SLA- Latest signal
- Jul 21, 2026, 2:45 AM
- Budget
- 66%
- Cadence
- daily ENTSO-E neighbour outage fact capture
ENTSOE_OUTAGES_ROEntsoe Outages Sk
within SLA- Latest signal
- Jul 21, 2026, 2:45 AM
- Budget
- 66%
- Cadence
- daily ENTSO-E neighbour outage fact capture
ENTSOE_OUTAGES_SKENTSO-E D-1 load forecast archive · DE
within SLA- Latest signal
- Jul 21, 2026, 8:16 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A65_LOAD_DAY_AHEAD_DEENTSO-E D-1 load forecast archive · HU
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A65_LOAD_DAY_AHEAD_HUENTSO-E D-1 load forecast archive · PL
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A65_LOAD_DAY_AHEAD_PLENTSO-E D-1 load forecast archive · RO
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A65_LOAD_DAY_AHEAD_ROENTSO-E D-1 load forecast archive · SK
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A65_LOAD_DAY_AHEAD_SKENTSO-E D-1 load forecast archive · UA
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A65_LOAD_DAY_AHEAD_UAENTSO-E D-1 renewables forecast archive · DE
within SLA- Latest signal
- Jul 21, 2026, 8:16 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A69_RENEWABLES_DAY_AHEAD_DEENTSO-E D-1 renewables forecast archive · HU
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A69_RENEWABLES_DAY_AHEAD_HUENTSO-E D-1 renewables forecast archive · PL
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A69_RENEWABLES_DAY_AHEAD_PLENTSO-E D-1 renewables forecast archive · RO
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A69_RENEWABLES_DAY_AHEAD_ROENTSO-E D-1 renewables forecast archive · SK
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A69_RENEWABLES_DAY_AHEAD_SKENTSO-E D-1 renewables forecast archive · UA
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A69_RENEWABLES_DAY_AHEAD_UAENTSO-E generation unavailability archive · DE
within SLA- Latest signal
- Jul 21, 2026, 8:16 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A80_GENERATION_UNAVAILABILITY_DEENTSO-E generation unavailability archive · HU
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A80_GENERATION_UNAVAILABILITY_HUENTSO-E generation unavailability archive · PL
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A80_GENERATION_UNAVAILABILITY_PLENTSO-E generation unavailability archive · RO
within SLA- Latest signal
- Jul 21, 2026, 8:16 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A80_GENERATION_UNAVAILABILITY_ROENTSO-E generation unavailability archive · SK
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A80_GENERATION_UNAVAILABILITY_SKENTSO-E generation unavailability archive · UA
within SLA- Latest signal
- Jul 21, 2026, 8:15 AM
- Budget
- 48%
- Cadence
- daily ENTSO-E pre-gate vintage capture
Capture heartbeat only: a fresh timestamp can accompany 0 parsed points or events and does not prove the captured content is usable.
ENTSOE_VINTAGE_A80_GENERATION_UNAVAILABILITY_UAHU day-ahead forecast capture
within SLA- Latest signal
- Jul 21, 2026, 8:30 AM
- Budget
- 47%
- Cadence
- daily day-ahead forecast capture
FORECAST_DA_CAPTURE_HUPL day-ahead forecast capture
within SLA- Latest signal
- Jul 21, 2026, 8:30 AM
- Budget
- 47%
- Cadence
- daily day-ahead forecast capture
FORECAST_DA_CAPTURE_PLUA day-ahead forecast capture
within SLA- Latest signal
- Jul 21, 2026, 8:30 AM
- Budget
- 47%
- Cadence
- daily day-ahead forecast capture
FORECAST_DA_CAPTURE_UAJAO cross-border auction capture
within SLA- Latest signal
- Jul 21, 2026, 8:25 AM
- Budget
- 39%
- Cadence
- daily cross-border auction capture
JAOForecast Precomputed Chronos
within SLA- Latest signal
- Jul 21, 2026, 10:50 AM
- Budget
- n/a
- Cadence
- daily chronos/hybrid precompute push
FORECAST_PRECOMPUTED_CHRONOSForecast Precomputed Hybrid
within SLA- Latest signal
- Jul 21, 2026, 10:50 AM
- Budget
- n/a
- Cadence
- daily chronos/hybrid precompute push
FORECAST_PRECOMPUTED_HYBRIDHow to read SLA statuses
Each status evaluates the latest signal under the SLA policy for that row; signal meaning varies by job.
- blocked
- The required signal is unavailable, or the job is blocked by access or configuration.
- breached
- The latest recorded signal violates the SLA policy for this row.
- no signal
- An SLA policy exists, but no signal has been recorded yet.
- at risk
- The latest signal still satisfies SLA, but is close to the policy limit.
- within SLA
- The latest signal satisfies the SLA policy for this row; read the signal-specific caveat before judging content.
- unclassified
- A signal exists, but this code does not have a classified SLA policy yet.
Trust and verification
Diia, signatures, and documents as a future trust layer.
This is not a live integration yet. We are documenting where Diia can support onboarding, signatures, and responsible-person verification before pilots or submit flows.
Diia.Signature
legal reviewElectronic signature for document signing or authorization through Diia.
Signing a contract, pilot request, decision package, or critical trader approval.Contract/approval: yesSourceDiia document sharing
legal reviewReceiving digital document copies and metadata after user approval.
Ukrainian company onboarding, representative verification, and KYC/KYB field prefill.Contract/approval: yesSourceDiia validation
plannedDigital document validation and protection against fake screenshots.
Responsible-person verification before paid pilot access or a submit-flow.Contract/approval: yesSourceQES / qualified e-signature
plannedSigned-document verification and compatibility with QES processes.
Fallback for legally significant documents when the Diia flow is unavailable.Contract/approval: noSourceReadiness checks
8 Pass · 2 Review · 0 Block
Next.js application
Marketing, workspace, PWA shell, and bilingual routes are available.
API surface
Strategy, BESS, backtest, AI brief, risk, audit, OREE price/index, gated UEEX index, health, and OpenAPI endpoints are registered.
API key mode
The current API key protection state is shown above; production API access should use protected mode.
Rate limiting
Requests are limited per route and client fingerprint.
Market data
OREE adapters are available; UEEX benchmarks stay gated until a written agreement and machine-readable feed exist. ENTSO-E, Ukrenergo, weather, fuel/carbon, Energy Map, NEURC, and AMCU are tracked in the data source registry.
Decision engine
DAM spread planning and backtesting run in deterministic server-validated code.
BESS engine
Charge/discharge planning supports capacity, power, efficiency, cycles, and degradation cost.
AI brief
V1 uses deterministic brief generation with Ukrainian and English output.
Audit trail
Workspace actions and API audit events use typed event creation.
PWA notifications
The Web Push contract is connected; production delivery needs a VAPID private key, provider, and tenant subscription store.
Need a technical integration?
The status page gives an operational signal, OpenAPI describes the contract, and the workspace lets you verify a DAM scenario quickly.