The technical detail behind “we take security seriously.”
A platform that touches regulatory filings and, increasingly, credit and underwriting decisions has to earn a security review, not just assert one. This page is the detail your IT or security team will actually ask for.
ISO 27001-aligned controls
Information security management controls aligned to ISO 27001 across the platform — the baseline, not a premium tier.
SOC 2 Type II-aligned practices
Controls evaluated for how they operate over an observation period, not just whether they exist on paper at a single point in time.
Encryption in transit and at rest
Data is encrypted at every stage — in transit between systems and at rest in storage.
Role-based access control
Access to customer data is scoped by role, logged, and reviewed — least-privilege by default.
Data isolation
Customer data is logically separated; no customer's data is used to train models for another customer.
Audit logging
Every calculation, edit and export is logged — the same lineage that supports a disclosure filing also supports a security review.
Vendor & sub-processor review
Third-party infrastructure and sub-processors are reviewed before use; a current sub-processor list is available on request.
Incident response
A documented incident response process with defined customer notification commitments.
Your data stays yours.
Export it, query it through Climate Copilot, or move it to another system — nothing is locked behind a proprietary format, and nothing is used beyond what's needed to run the platform for you.
Have your security team review us directly.
We're happy to complete a security questionnaire or walk your IT team through the architecture before any data moves.