Where your data lives, and who can see it
You are entrusting supply chain data to an external platform. Here is where it lives, how it is isolated, and what we do not claim.
Swiss hosting, and not only on paper
The site and all data are hosted by Infomaniak Network SA in Geneva, on infrastructure located in Switzerland. Infomaniak is ISO/IEC 27001 certified.
Sovereignty is verifiable and we verified it: the address block serving the site belongs to Infomaniak Network SA, registered in Switzerland, which anyone can check in the public RDAP registry. Many providers advertise Swiss hosting while renting capacity elsewhere.
No data is processed outside Switzerland, and no American subprocessor is involved in the hosting chain.
Isolation between companies
This is the essential property of a platform shared between competitors. Each company is isolated: a resource that does not belong to you does not appear empty, it simply does not exist for you.
This isolation is not an intention, it is an architectural rule checked by automated tests re-run on every code change. An access that would cross a company boundary fails the build.
A supplier's company carbon inventory is never visible to a house. Their assessments go only to the houses they designate, part by part, at the level of detail they choose, and any share can be revoked.
Who did what, and when
Every assessment carries an audit log: creation, modification, finalisation, publication, sharing and revocation, each with its author and date. The log cannot be modified or erased.
The log is itself compartmented: the names of a supplier's staff never reach its clients.
The technical measures in place
- Encryption in transit on every page, TLS 1.2 and 1.3 only, older versions refused.
- Passwords stored with Argon2, never in clear text, never reversible.
- Rate limiting on login and on public forms, against attempts in series.
- A complete set of HTTP security headers, including a content policy that forbids any external script.
- Daily backups, and a restore actually tested rather than assumed.
- Administrative server access by key only, application ports closed to the outside.
No third-party services
The platform loads no external resource: no remote font, no library hosted elsewhere, no analytics, no social network button. Everything is served from the same Swiss server.
The consequence is direct: your browser reports your visit to no one else. It is also what lets the privacy policy be true without reservation.
A single cookie is set, to remember your session and your language. There is no consent banner because there is nothing to consent to.
What we do not claim
The platform is not ISO/IEC 27001 certified. The host is. The platform's own measures are aligned with Annex A of ISO/IEC 27001:2022, without the platform itself being certified.
The distinction is routinely blurred in this sector, and we would rather write it down: certification requires a management system audited by an accredited body, which is a different job from technical measures.
Our measures are reviewed periodically, and the last check covered the code as well as the production server, not merely the intentions.
Report a vulnerability
If you find a security problem, write to us: we answer, we fix, and we do not pursue people who report in good faith. Our security contact details are published in the standard format, at the conventional address /.well-known/security.txt.
Further reading: the privacy policy · the legal notice · the calculation methodology · consolidating a scope 3.1 · the tools given to suppliers