It’s good that GivEnergy responded quickly and positively to this, you do have to ask whether there is enough proactive testing/white hat attempts to find weaknesses etc, and some statements about patch policy, security testing etc would have been worthwhile making.
The statement on the website is as @Rubikcube points out, written by the marketing department. Some of it is complete guff, having the software department as a separate legal entity does nothing for IT security, and whether the team is UK based or not matters not either. Given the challenges there are in getting new firmware updates developed, tested and rolled out and the random things that happen sometimes to the portal and app, just what those 30+ software engineers are doing and what the split between support, feature development, operational management, testing, etc is.
I also find it disappointing that there’s no statements about how the systems are secured, encryption at rest, in transit, account security policies (who has access to what), adherence to AWS best practice design, resilience of the infrastructure against single points of failure (which links in to how software changes are developed, tested and rolled out), testing automation (including security and resilience testing), etc.
I’m sure there is a lot more good stuff going on, its just not written about.