Enterprise-grade, SMB-priced
Security & trust
Your emissions data is sensitive — it tells the world how your business runs. We treat it that way. Here's exactly how we protect it.
Encryption
- Data in transit: TLS 1.2 minimum (prefers TLS 1.3)
- HTTPS enforced across the entire application
- Data at rest: AES-256
Infrastructure
- Infrastructure providers host our application and data
- Security headers (CSP, HSTS) on all responses
- Rate limiting on API endpoints
Access Control
- Sign-in via OAuth (InsForge)
- Postgres row-level security isolates each workspace’s data
- Session timeout and automatic re-authentication
Data Handling
- Your data is yours. We never share or sell customer data.
- Uploaded files are parsed and emission factors applied; you can delete uploads at any time
- Payments processed by Stripe — we never store card details
- Export your data at any time from Settings — a machine-readable JSON download of your workspace
- “Delete my audit data” in Settings removes emissions entries and facilities immediately; full account deletion is available via support
Compliance
- Privacy and data-processing controls designed to support customers’ GDPR and CCPA obligations. See the Privacy Policy and DPA for scope, roles, subprocessors, retention, and request procedures.
- Carbon accounting methodology follows the GHG Protocol Corporate Standard and Scope 3 Standard
- SOC 2: in progress (Q3 2026)
How we handle your data
Transparency about what happens to your uploaded documents, extracted data, and generated reports.
Document upload and processing
When you import a CSV of activity data, we apply emission factors to each row. You can delete uploaded data at any time.
Data sharing and third parties
We never share, sell, or license your emissions data to third parties. Data you upload is used exclusively to provide the Service — generating emissions estimates, audit trails, and compliance reports. We do not train AI models on customer data. Integrations with QuickBooks, Xero, or other platforms are read-only where possible and require explicit OAuth authorization.
Employee and contractor access
Production access is restricted to authorized engineering and support staff, requires multi-factor authentication, and is logged and audited monthly. Support staff access customer data only to resolve specific, documented support requests with workspace owner consent.
Data export and deletion
You can export your data at any time from Settings as a machine-readable JSON download, and “Delete my audit data” in Settings removes all emissions entries and facilities immediately. Your account record stays until you request full account deletion via support; deletion requests are processed within 30 days.
Trust documentation
We publish our security and compliance documentation transparently. No NDA required for standard materials.
Questions about security?
We're happy to answer specific questions about our security posture, infrastructure, or compliance roadmap.