Print dialog opening — choose Save as PDF, layout Landscape, margins None, and enable Background graphics.
LexaVolt builds a hardware-rooted secure gateway that lets OEMs and aggregators connect solar, batteries, and EV chargers into virtual power plants — without inheriting legacy-device cyber risk.
LexaVolt whitepaper, “Securing the Grid Edge” — Dmitri Hunt, Founder
DER adoption, VPP deployment, IEEE 2030.5 / CSIP mandates, Secure SunSpec Modbus, and smart-inverter cybersecurity guidance are collapsing into one market requirement.
Secure, interoperable, certifiable control at the grid edge — for every mixed fleet of solar, storage, and EV charging a utility program touches.
LexaVolt is the standards-native secure DER gateway for the OEMs and aggregators who must deliver that control and cannot build it themselves.
U.S. Department of Energy
Disclosed across Sungrow, Growatt, and SMA — three of the top six manufacturers worldwide.
Share of solar-system vulnerabilities disclosed over the prior three years.
Remote takeover paths reached devices through the manufacturer's own management cloud.
Sources: Forescout Vedere Labs (SUN:DOWN, 2025) · Dragos · CISA/NSA/FBI joint advisory · NIST IR 8498
With the enormous installed base of legacy SunSpec Modbus devices already in the field — no forklift upgrade available.
For VPP, utility, and DERMS programs, over a control path that survives a hostile network.
IEEE 2030.5 / CSIP, SunSpec Modbus, and emerging Secure SunSpec Modbus expectations — provable, not asserted.
Custom integration work on every program. Longer pilot cycles. Inconsistent security posture. Expensive utility onboarding, repeated per OEM.
California Rule 21 already requires DERs in IOU territories to use IEEE 2030.5 in the CSIP profile by default.
SunSpec Alliance
It authenticates, authorizes, translates, bounds, logs, and safely enforces every DER control — once, at the boundary.
SunSpec’s certification registry already lists gateways, clients, and aggregators from Enphase, Tesla, Generac, Schneider, SMA, Kitu, QCells, and others. Incumbents validate the category.
A brand-agnostic secure gateway focused on security-boundary enforcement — not a closed OEM ecosystem competing for the homeowner.
Sources: SunSpec Alliance product certification registry · Secure SunSpec Modbus specification
At $250–$450 ASP per gateway.
At $2–$6 per site per month.
Sources: FERC · DOE · SEIA · NREL
Primary customers: DER OEMs needing certified secure comms · aggregators and VPP operators needing fleet edge security · DERMS and utility-program integrators needing protocol translation.
SunSpec certification fees: $5,000 members / $10,000 non-members, plus authorized test-lab fees set independently. CSIP certification applies to clients, gateways, aggregators, and servers.
Certification is the near-term focus — it is the gate every OEM and aggregator buys behind. Phase 1 funds the test DERs, harness, and lab fees to get there; then $1M proves product-market fit with paying OEM and aggregator pilots.
Certification achieved on the target processor, validated against real DERs.
Paid pilots and repeatable design wins — the evidence that proves product-market fit.
Target-processor board bring-up, threat model freeze, pilot BOM
Secure boot, key provisioning, hardware root of trust on production silicon
CSIP client and Secure SunSpec Modbus hardened out of the simulation harness
Southbound adapters against real inverter, battery, and EVSE hardware
Pilot build, factory-test fixture, automated regression suite
Field-ready units with first OEM / aggregator evaluations underway
Pilot units in the field · two evaluation customers · certification submissions opened · field telemetry · a factory-test process · and a credible BOM and margin model.
A demonstrable prototype is running on the target processor, exercised against a LexaVolt-built simulation harness that emulates DERMS, aggregator, and legacy DER traffic.
Has delivered complex electronics systems into production inside highly regulated industries — the exact discipline a certified, grid-connected security device demands.
Finance and accounting professional, former associate at VC firms. Specializes in crossing the T's and dotting the I's that most startups never get right — diligence-grade books, controls, and reporting from day one.
First targets: inverter and battery OEMs without mature gateway security, aggregators running mixed fleets, DERMS integrators, and CSIP utility pilots.
Build to SunSpec test procedures early; budget pre-test and ATL iteration.
Sell as an accelerator, not a replacement — embedded license plus gateway SKU.
Ship CSIP and legacy SunSpec Modbus now; secure profile is the forward wedge.
Recurring security service, OEM licensing, factory-test automation.
Lead with paid pilots and compliance pain, not generic energy optimization.
Take the TRL 4 prototype to a pilot build on production hardware. Then $1M to prove product-market fit with certified, paid OEM and aggregator pilots.
The grid is moving from centralized assets to coordinated fleets. Somebody has to secure the boundary between internet-connected fleet control and local energy hardware. That is a structural requirement — not a bet on one OEM, one utility, or one VPP program.
For a device that governs real power at the grid edge, security is the product — not a feature.
LexaVolt · Securing the Grid Edge