Skip to content
Security & data governance

Your emissions data is commercially sensitive. We treat it that way.

This page is written for the security reviewer, not the buyer. It describes how access is controlled, how data is handled, where our compliance posture actually stands today, and what we have not yet done.

Access & accountability

Who can see a figure, who changed it, and whether that change can be reconstructed later.

Role-based access control
Access is granted by role rather than per person, so entities, sites, and reporting periods are visible only to the roles scoped to them.
Available
Approval workflow
Submitted activity data can be routed for review before it is treated as reportable, keeping preparer and approver separate.
In development
Immutable audit trail on data changes
Changes to activity data, factor selections, and calculated figures are recorded as append-only history with actor and timestamp, so a restatement can be reconstructed.
In development
Session management
Authentication, session expiry, and sign-out across devices are handled by our managed authentication provider.
Available

Data handling

The mechanisms below are described as they work today. Where a specific parameter has not been fixed and published, we say so instead of filling the gap.

Where data lives
Application data and authentication are hosted with our managed database provider. We do not publish a residency region until we can state the one your tenant is actually provisioned in — ask in a vendor assessment and we will confirm in writing.
Encryption in transit and at rest
Traffic to the application is served over TLS, and stored data is encrypted at rest by the managed platform. Specific protocol versions and cipher configuration are inherited from that platform rather than set by us.
Backup and recovery
Backups are provided by the managed database platform. We do not publish recovery objectives we have not tested and committed to contractually.
Retention and deletion on request
Customer data is retained for the life of the engagement or licence. Deletion requests are actioned on the production dataset; backup copies age out on the platform's own cycle.
Tenant separation
Records carry an owning organisation and access is filtered at the database layer by row-level policy, so a query cannot return another tenant's rows.

Compliance posture

We are building toward ISO 27001 and align our practices to GDPR principles and Indonesia's Personal Data Protection Law (UU 27/2022). We are not currently certified against ISO 27001, and we will tell you that in a vendor assessment rather than let you discover it later.

What to send us

If you are running a security review, send your vendor questionnaire, DDQ, or DPA draft straight to us. We answer the questionnaire you already use rather than asking you to fill in ours, and we mark anything we cannot yet evidence as not in place.

Send a security questionnaire

Sub-processors

The providers below process customer data on our behalf.

ProviderPurposeData categoryRegion
SupabaseApplication database and authenticationContact form submissions and platform dataConfirmed on request

This list is maintained as part of our vendor assessment pack and the current version is available on request.

This page describes our current security posture and is not a contractual commitment. Contractual terms — including processing scope, sub-processor notification, and deletion obligations — live in the DPA and the master services agreement.

Next step

Ready to put numbers behind your climate commitments?

Tell us where you are — baseline, target-setting, disclosure, or carbon markets — and we'll propose a scoped starting point.

Start a conversation Chat on WhatsAppWe reply within 1–2 business days.