Plain answers

Questions worth answering directly.

Including the ones with awkward answers. If something here is missing, ask and it gets added.

How is this different from an enterprise carbon platform?

Enterprise carbon platforms are measurement systems, built to calculate an emissions figure at scale for a large sustainability function with mature data infrastructure. Auditably sits after measurement. The question it answers is not what the number is, but whether it can be supported, which document it came from, who reviewed and approved it, and what changed. It does not replace a measurement platform; it replaces the spreadsheet-and-shared-drive workflow that has no record of review or approval when the assurance provider asks for one.

Which jurisdictions does Auditably support?

The core product supports IFRS S2 directly, Each reporting cycle records the jurisdiction you are reporting under, and that label appears on the cycle and in the export. It does not change the disclosure templates or apply jurisdiction-specific validation. Our published jurisdiction guides are maintained reference material, not a statement of product configuration.

How does Auditably handle external assurance?

Two ways. A read-only auditor role exists in the data model, but distinct permissions per role are not yet enforced in the product, so we do not offer it as a control today. What we do offer is the auditor pack export: it produces a ZIP containing PDF disclosures, the complete activity log (CSV and PDF), all evidence files with SHA-256 hashes, and a master index mapping every disclosure to its evidence: structured for ISAE 3000 and the forthcoming ISSA 5000 sustainability assurance standard.

Where is my data stored?

Customer data is held in Supabase (Postgres) with row-level security and tenant isolation, and application infrastructure runs on Cloudflare. Evidence files are stored encrypted at rest with SHA-256 hash verification on upload and export. SOC 2 Type I attestation is in progress and we are not certified today. We do not publish a target date for something outside our control. Custom DPAs and EU data residency are available on request.

Can I export everything if I cancel?

Yes. At any time, during your active subscription or your 14-day cancellation window, you can export a full archive of every reporting cycle, disclosure, data point, evidence file and the complete activity log, in CSV, JSON and PDF. Vendor lock-in is incompatible with audit-grade software. Your data is yours.

What if I am not the right person: my Group Reporting Manager is?

That is typical. The diagnostic is designed for the person doing the work: Group Reporting Manager, Sustainability Manager or ESG Lead. If you are a CFO or Audit Committee Chair evaluating tools, it gives you a 12-page report you can hand to your team. Forward it. We see this every week.

Do you have customers yet?

We are early: at the design-partner stage, working directly with first-cycle reporters and their advisors to harden the product against real assurance reviews. We will not pretend otherwise with fake logos or invented trusted-by numbers. If you would rather wait for a longer track record, that is fair. If you would rather help shape an audit-trail-first tool, and get founder-level attention while you do, this is the moment to start. The free readiness diagnostic costs nothing.

Is my data secure?

Customer data is isolated per tenant with row-level security in Postgres, served over HTTPS on Cloudflare. Evidence files are SHA-256 hashed on upload and re-verified on export, and the activity log is append-only. It cannot be edited or deleted, even with our own service credentials. SOC 2 Type I is in progress and not yet complete. We state security posture plainly and never claim a certification we do not hold.

What happens after my first reporting cycle?

Your cycle is preserved, locked, with its full audit trail intact, and the data stays yours. Pro accounts can roll forward into the next reporting year and run year-over-year comparisons, and everything you exported (disclosures, evidence, logs) remains reproducible. You are never locked in: a full archive export is one click away at any time.

Can my auditor access it directly?

Yes. Give your assurance provider the auditor pack export, which contains the disclosures, the complete activity log, and every evidence file with its hash. A read-only auditor login is in the data model but is not yet enforced, so we do not present it as a control. Or hand them the auditor pack export. Most teams do both.

Still deciding?

The diagnostic answers the only question that matters: where you stand against the 33 disclosure paragraphs.

Run the diagnostic Test the log