A clear view of our security.
The controls behind it.
Understand the controls behind CarbonTrace and find the documentation you need for your own security review.
Encrypted connections
CarbonTrace uses HTTPS for connections to the platform. Our infrastructure providers supply encryption controls for stored data. Contact us about specific requirements for your review.
Organization access controls
Organization-scoped access checks and database row-level security policies help separate customer data. Security depends on these controls working together across the application.
Scoped API keys
Every API key belongs to one organisation. Revocable from the dashboard. Sandbox keys exist as a separate type so test traffic never touches live quotas.
Traceable audit events
Recorded security and administrative events provide an audit trail. Hash chaining helps detect changes to recorded events; this is not a claim that every interaction is logged.
EU data residency
Primary database in Frankfurt (eu-central-1). Edge functions occasionally serve from non-EU regions for latency, with Standard Contractual Clauses in place.
Multi-factor authentication
Add an authenticator app to protect your account with a second verification step. Store recovery codes securely so you can regain access if your device is unavailable.
Documentation for your review
Data protection documents and calculation references serve different purposes. Review the scope of each.
GDPR
Data processing terms available in our DPA
ISO 14040 / 14067
Lifecycle methodology references; no certification claim
GHG Protocol
Accounting context for supported IT reporting outputs
Reporting a vulnerability
Report a suspected vulnerability to security@carbontrace.cloud. Include the affected page, reproduction steps and the potential impact. Do not include passwords, API keys or other customer data.
Reviewing CarbonTrace for your organization?
Tell us which security questions and supporting documents you need. We can clarify the available controls, data processing terms and their scope.
Contact us about security