Your emissions data is commercially sensitive. We treat it that way.
This page is written for the security reviewer, not the buyer. It describes how access is controlled, how data is handled, where our compliance posture actually stands today, and what we have not yet done.
Access & accountability
Who can see a figure, who changed it, and whether that change can be reconstructed later.
- Role-based access control
- Access is granted by role rather than per person, so entities, sites, and reporting periods are visible only to the roles scoped to them.
- Approval workflow
- Submitted activity data can be routed for review before it is treated as reportable, keeping preparer and approver separate.
- Immutable audit trail on data changes
- Changes to activity data, factor selections, and calculated figures are recorded as append-only history with actor and timestamp, so a restatement can be reconstructed.
- Session management
- Authentication, session expiry, and sign-out across devices are handled by our managed authentication provider.
Data handling
The mechanisms below are described as they work today. Where a specific parameter has not been fixed and published, we say so instead of filling the gap.
- Where data lives
- Application data and authentication are hosted with our managed database provider. We do not publish a residency region until we can state the one your tenant is actually provisioned in — ask in a vendor assessment and we will confirm in writing.
- Encryption in transit and at rest
- Traffic to the application is served over TLS, and stored data is encrypted at rest by the managed platform. Specific protocol versions and cipher configuration are inherited from that platform rather than set by us.
- Backup and recovery
- Backups are provided by the managed database platform. We do not publish recovery objectives we have not tested and committed to contractually.
- Retention and deletion on request
- Customer data is retained for the life of the engagement or licence. Deletion requests are actioned on the production dataset; backup copies age out on the platform's own cycle.
- Tenant separation
- Records carry an owning organisation and access is filtered at the database layer by row-level policy, so a query cannot return another tenant's rows.
Compliance posture
We are building toward ISO 27001 and align our practices to GDPR principles and Indonesia's Personal Data Protection Law (UU 27/2022). We are not currently certified against ISO 27001, and we will tell you that in a vendor assessment rather than let you discover it later.
What to send us
If you are running a security review, send your vendor questionnaire, DDQ, or DPA draft straight to us. We answer the questionnaire you already use rather than asking you to fill in ours, and we mark anything we cannot yet evidence as not in place.
Send a security questionnaireSub-processors
The providers below process customer data on our behalf.
| Provider | Purpose | Data category | Region |
|---|---|---|---|
| Supabase | Application database and authentication | Contact form submissions and platform data | Confirmed on request |
This list is maintained as part of our vendor assessment pack and the current version is available on request.
This page describes our current security posture and is not a contractual commitment. Contractual terms — including processing scope, sub-processor notification, and deletion obligations — live in the DPA and the master services agreement.
Ready to put numbers behind your climate commitments?
Tell us where you are — baseline, target-setting, disclosure, or carbon markets — and we'll propose a scoped starting point.