Security
Updated at 2026-07-04
How Nordic Carbon protects your sustainability data, platform access, and operational information.
Our commitment
Nordic Carbon is built for organizations that trust us with sensitive operational and sustainability data. Security is embedded in how we design, deploy, and operate our platform - not treated as an afterthought.
This page summarizes the practices we follow to protect customer data, maintain platform integrity, and support your compliance obligations.
Security and governance in the OS
Beyond standard SaaS controls, Nordic Carbon treats Security & Governance as a cross-cutting control plane across every engine boundary - tenant isolation, RBAC, connector credential policy, approval authority, AI tool permissions, audit logging, and data residency.
Ingestion, the Knowledge Writer API, Orchestration, Workflow, and the AI Agent Layer each enforce governance at their boundaries so automation accelerates work without bypassing review or traceability.
For the full architecture model, see OS Architecture documentation.
Data protection
We apply defense-in-depth controls across the Nordic Carbon platform to safeguard data at rest and in transit.
- Encryption in transit using TLS 1.2+ for all connections to our services.
- Encryption at rest for stored customer data and platform backups.
- Logical separation of customer environments to reduce cross-tenant exposure.
- Regular review of data retention policies and secure deletion workflows.
Infrastructure
Our platform runs on modern cloud infrastructure with hardened configurations, network segmentation, and continuous monitoring.
We restrict administrative access, patch systems promptly, and follow least-privilege principles for production environments.
Access controls
Customer accounts support role-based access so teams can grant the minimum permissions required for each user.
- Strong authentication requirements for platform access.
- Audit logging of key administrative and data-access events.
- Session management and automatic timeout for inactive users.
- Internal access to production systems is limited, logged, and reviewed.
ESG and operational data
Nordic Carbon processes sustainability metrics, facility data, supplier information, and reporting outputs on behalf of customers. We treat this data as confidential business information.
Data submitted through integrations, uploads, or manual entry is processed only to deliver the services you configure - including calculations, dashboards, and disclosure-ready exports.
Sustainability-specific controls
Beyond standard SaaS security, Nordic Carbon enforces controls designed for regulated sustainability operations and AI-assisted workflows.
- AI output approval gates - agent and model outputs that affect disclosures or external stakeholders require human review before trusted use.
- Evidence lineage - figures and facts link back to source documents, transformations, and approval history for audit readiness.
- Tenant-scoped connectors - connector credentials and sync jobs are isolated per customer; connectors cannot write trusted knowledge directly.
- Role-based access to supplier data - supplier twins, submissions, and health scores are limited by workspace roles and tenant scope.
- Audit logs for report generation - disclosure drafts, exports, and approval actions are logged for reconstructable reporting history.
- No direct model-provider access to customer data unless configured - model calls go through the AI Runtime under policy; providers receive only the context required for an approved task.
Third-party services
We use carefully selected subprocessors for hosting, email delivery, analytics, and other operational functions. Each vendor is evaluated for security posture and contractual data-protection obligations before onboarding.
We do not sell customer data. Third parties may access data only as needed to provide contracted services on our behalf.
Incident response
We maintain an incident response process to detect, contain, investigate, and remediate security events. When a confirmed incident affects customer data, we notify affected customers without undue delay in accordance with applicable agreements and law.
Compliance and assurance
We align our security program with recognized industry frameworks and customer expectations for enterprise SaaS. Specific certifications, audit reports, or security questionnaires can be requested by qualified prospects and customers.
Report a security issue
If you believe you have discovered a vulnerability or security concern related to Nordic Carbon, please contact us promptly. We appreciate responsible disclosure and will work with you to understand and address valid reports.
- Via Email: hi@nordiccarbon.tech
- Via this Link: nordiccarbon.tech/contact