Home / Security
Security

The technical detail behind “we take security seriously.”

A platform that touches regulatory filings and, increasingly, credit and underwriting decisions has to earn a security review, not just assert one. This page is the detail your IT or security team will actually ask for.

ISO 27001-aligned controls

Information security management controls aligned to ISO 27001 across the platform — the baseline, not a premium tier.

SOC 2 Type II-aligned practices

Controls evaluated for how they operate over an observation period, not just whether they exist on paper at a single point in time.

Encryption in transit and at rest

Data is encrypted at every stage — in transit between systems and at rest in storage.

Role-based access control

Access to customer data is scoped by role, logged, and reviewed — least-privilege by default.

Data isolation

Customer data is logically separated; no customer's data is used to train models for another customer.

Audit logging

Every calculation, edit and export is logged — the same lineage that supports a disclosure filing also supports a security review.

Vendor & sub-processor review

Third-party infrastructure and sub-processors are reviewed before use; a current sub-processor list is available on request.

Incident response

A documented incident response process with defined customer notification commitments.


Data ownership

Your data stays yours.

Export it, query it through Climate Copilot, or move it to another system — nothing is locked behind a proprietary format, and nothing is used beyond what's needed to run the platform for you.

Have your security team review us directly.

We're happy to complete a security questionnaire or walk your IT team through the architecture before any data moves.