Trust and Equity
A platform managing critical energy infrastructure must earn and maintain trust at every level of its operations. Trust is not a communications stance – it is the cumulative result of consistent conduct.
As charging becomes essential infrastructure, the question of who benefits, on what terms, and with what protections is increasingly a sustainability question as much as a commercial one. This chapter addresses how AMPECO manages that responsibility – through the standards we set for our own people, the diligence we apply to our supply chain, the security controls that protect operators and drivers, and the governance structures that ensure these commitments are more than stated intentions.
Code of Conduct
AMPECO’s Code of Conduct sets out the standards of behavior expected from every person who works at or with AMPECO – employees, contractors, consultants, and suppliers alike. The current version, v1.5 published April 2026, reflects the most comprehensive revision to date and is publicly available at ampeco.com/code-of-conduct. It is structured around three areas of responsibility that directly mirror AMPECO’s sustainability pillars:
As a member of society
Environmental responsibility including digital decarbonization and Green Software principles, a formal net-zero commitment by 2030, diversity and inclusion, and upholding human rights in line with the UN Global Compact and the ILO Declaration.
As an employer
Expectations across health and safety, anti-harassment and anti-discrimination, freedom of association, professional standards, asset use, and communications – across physical and remote working environments.
As a business partner
Confidential information and personal data handling, cybersecurity risk management, conflicts of interest, intellectual property, and clear prohibitions on bribery, corruption, kickbacks, and money laundering.
Version 1.5 introduces three substantive additions reflecting how our operating context has evolved:
Cybersecurity as a conduct standard
All employees operating within AMPECO’s systems – including remote access via cloud-based tools – are within the company’s logical security perimeter and required to follow ISMS principles as a matter of conduct, not just policy compliance.
Responsible AI use
Employees apply AI tools with the same standards of integrity, accuracy, and confidentiality that govern all professional conduct. AI-generated outputs require human review before use. A Human-Centric AI principle requires that AI decisions affecting charging or operations be transparent, auditable, and free from algorithmic bias.
Data ethics
Beyond GDPR compliance, AMPECO treats user and energy data as a trust-based asset – including hardware agnosticism as an ethical commitment: we refuse to implement technical barriers or vendor lock-in that could restrict fair competition across the EV ecosystem.
Reporting and non-compliance. Our whistleblower policy provides clear guidance and protection for anyone reporting concerns. Reports may be made anonymously, and no person making a good-faith report will be subject to retaliation. In FY2025, reported whistleblower incidents remained at zero, consistent with 2024 – a figure we treat as a positive signal, not a reason to reduce vigilance. Every employee acknowledges the Code of Conduct at onboarding and at each material revision.
Supply chain due diligence
AMPECO’s supply chain is not complex in the traditional sense – no physical goods, no manufacturing tiers, no raw materials. What there is instead is a set of concentrated, high-consequence dependencies: the cloud infrastructure that runs the platform, the security auditors who validate our controls, and the professional services firms that support our operations. Even as a global company operating across 73 markets, more than 40% of our supplier base are local suppliers – a deliberate outcome supported by our Sustainable Local Purchasing and Hiring Policy.
Our approach is grounded in two interlocking policies: the Supplier Due Diligence Policy and the Supplier Review Policy. Every supplier classified as strategic – providing a key outsourced service, carrying annual cost above €25,000, or holding access to business-critical systems – undergoes a formal evaluation before engagement and an annual re-evaluation thereafter. All suppliers are expected to acknowledge the AMPECO Supplier Code of Conduct, publicly available at ampeco.com/supplier-coc.
The AI Usage and Governance element, added in May 2025, is the most significant structural change to the framework in FY2025: AMPECO now formally assesses how every strategic supplier uses AI within their products, services, and internal processes – including data handling, ethical safeguards, and compliance with the EU AI Act and ISO/IEC 42001. Looking ahead, priorities include moving Scope 3 Category 1 reporting from spend-based proxies to supplier-specific activity data, and embedding shared sustainability KPIs into our most strategic long-term relationships.
Cybersecurity and data privacy
A charge point management system sits at the intersection of personal data, financial transactions, energy infrastructure, and operator networks. At AMPECO, cybersecurity is not a feature or a compliance obligation – it is the governance foundation on which everything else in our platform rests.
Our information security practices are governed by an ISO/IEC 27001:2022-certified Information Security Management System covering the design, development, delivery, and support of our platform. In addition, AMPECO conducts SOC 2 Type II audits annually, assessed by an independent third party – providing evidence-based, audited assurance of our security, availability, processing integrity, and confidentiality controls over time.
We handle personal data on behalf of operators across more than 70 markets, acting as a data processor in the majority of cases. Data Processing Agreements are signed with all relevant suppliers and partners before data exchange begins. AMPECO also operates a responsible disclosure program – openness to scrutiny, not opacity, is the right posture for a company operating critical digital infrastructure.
- ISO/IEC 27001:2022 – core information security management framework.
- ISO/IEC 27017:2015 – cloud-specific security controls for our AWS-hosted infrastructure.
- ISO/IEC 27018:2019 – protection of personally identifiable information in public cloud environments.
- ISO/IEC 27701:2019 – privacy information management extension to ISO 27001.
- SOC 2 Type II – annual independent audit of operational controls.
Integrity and responsible business conduct
Fair competition
AMPECO competes on the merits of its platform: only truthful product information in sales and marketing, no false or misleading claims about competitors, and full compliance with antitrust and competition laws across all markets. Bid rigging, price-fixing, and any arrangement limiting fair competition are explicitly prohibited.
Accounting integrity
All business transactions are fully and accurately recorded in accordance with applicable accounting standards. Falsification, misleading entries, unrecorded funds, and undocumented payments are strictly prohibited, subject to internal review and external audit.
Transparency in operations
Our Service Level Agreements set defined, contractual commitments for availability, incident response, and resolution targets. Operators have direct access to uptime dashboards, session-level reporting, and incident status updates – and every metric in this report is supported by a documented methodology.
Shared outcomes
Informed by the Vested methodology, AMPECO structures client relationships around shared success rather than transactional delivery. We are actively developing formalised partnership agreements that incorporate shared sustainability KPIs – avoided CO₂ emissions, renewable energy utilization, and equitable access – directly into partnership governance.
Sustainability governance
Sustainability at AMPECO is not owned by a single function or reported upward from a team with no operational authority. It is integrated into how the company is led. The CEO holds ultimate accountability for sustainability performance, including the SBTi-verified net-zero commitment and the ISO 14001 EMS. Operational governance is distributed across a cross-functional group that coordinates data collection, methodology alignment, and reporting across functions.
This structure means sustainability topics surface in the same forums where business, product, and risk decisions are made. ESG risks are reviewed within AMPECO’s regular risk management process, alongside operational, financial, and commercial risks.
The EMS as backbone. Our ISO 14001:2015-certified EMS provides the formal structure within which environmental objectives are set, progress is tracked, and incidents are logged and reviewed. It defines binding internal targets – the cloud consumption intensity coefficient, the annual training coverage requirement, and the sustainable procurement spend threshold – and provides the governance backbone for our Atlas Metrics-supported carbon accounting from FY2025 onwards.
Managing emerging risks. Two areas received heightened governance attention in FY2025: digital and AI risk, where governance structures ensure AI use is subject to the same standards of security, privacy, and human accountability as any other part of the platform; and nature and water risk, where our TNFD LEAP-informed scoping exercise has begun informing infrastructure decisions. Recognizing evolving SFDR requirements, we have benchmarked our Carbon Intensity of Capital at 0.12 kgCO₂e per EUR of total assets – positioning AMPECO as a top-tier performer for tech-sector SFDR disclosures.



