Product

Every disclosed figure carries its own supporting documentation.

Auditably structures a reporting cycle as a set of IFRS S2 disclosure requirements, holds the documentation behind each figure, records review and approval against named users, and writes every change to a log that cannot be edited or deleted.

It is built for the person who has to answer for the number, not the person who calculated it. A Group Financial Controller signing a climate statement is in the same position as with any other figure in the annual report, except that the data did not come out of the ledger, the methodology is younger than the people applying it, and the trail behind it usually lives in a shared drive. The product is an answer to that specific problem, not an emissions calculator.

Get your free readiness score See pricing

Where the numbers come from

You bring the inventory. We hold the record behind it.

Bring a verified emissions inventory from your adviser, your existing tool or your own workings. Auditably records where each figure came from, who reviewed and approved it, and what changed.

It is not a calculation engine. It does not compute Scope 1, 2 or 3, and it does not validate the inventory you bring. Those remain the responsibility of whoever prepared them. What this product adds is the part that is usually missing when an assurance provider starts asking questions: the documentation behind each figure, the review and approval record, and the change history.

Straight answers

Questions people ask.

What is the difference between carbon accounting software and disclosure controls software?

Carbon accounting software calculates the number. Disclosure controls software governs how that number reaches the annual report: what evidence sits behind it, who reviewed it, what changed since the last version, and what an assurance provider can test on request.

The two sit next to each other instead of competing. Auditably is the second kind. It does not calculate emissions.

What are disclosure controls under IFRS S2?

They are the record that a disclosed figure was prepared, reviewed and approved by named people on known dates, with the supporting documentation attached to the figure itself.

IFRS S2 does not prescribe a control framework. What it creates is an expectation that a climate figure can be tested the way a financial figure is, and that expectation is where the controls come from.

Does Auditably calculate our emissions?

No. It takes the figures you have already calculated, holds the documentation behind each one, records who reviewed and approved it, and exports a pack an assurance provider can test.

If you need a calculation engine you need a different product, and quite possibly both.

Evidence chain

Supporting documentation, attached to the figure it supports.

A data point is stored with the document it came from, the calculation method applied, and the emission factor with its source. Files are SHA-256 hashed on upload and re-verified on export, so the figure and its evidence stay together through to the assurance pack.

The reason to bind them at the point of entry rather than collect them later is that later does not work. The gap between publishing a figure and being asked to support it is measured in months, and in that time the analyst who built the workbook changes role, the shared drive is reorganised, and the supplier reissues the invoice with a corrected total. None of that is negligence. It is what happens to unstructured evidence over an ordinary year, and it is why reconstructing a trail costs several times what recording one does.

How a disclosed figure keeps its evidence, from source document to assurance exportFour stages run left to right: a source document hashed on upload, a data point carrying its method and emission factor, a disclosure reviewed and then approved against named users, and an assurance export in which the hash is re-verified. Beneath them an append-only log records an entry at every stage. An arc connects the first and last stage, marking that the file leaving in the export is provably the file that was filed.THE LIFE OF ONE FIGURESource documentmeter-readings-FY2025.xlsxhashed on uploadData point12,450 tCO2emethod and factorrecordedDisclosurereviewed, then approvedagainst named usersAssurance exportauditor-pack-FY2025.ziphash re-verifiedsame file, proven by SHA-256APPEND-ONLY LOGupdate and delete revokeddata point createdevidence attachedstatus changed,then approvedexport generatedEvery arrow writes a log entry. No stage can be altered afterwards, including by us.
One figure, from the spreadsheet it came out of to the archive an assurance provider opens. The digest taken at upload is recomputed on the way out, which is what lets a reviewer confirm the document they are reading is the document that was filed. The rail beneath is the activity log: an entry is written at each transition, and the table it lives in has update and delete revoked at database level.
data point IFRS S2 para 29(a)(i) approved
figure Scope 1 gross GHG emissions · 12,450 tCO2e location of the boundary and the factor recorded with the value
source meter-readings-FY2025.xlsx sha256 a3f9c1…7e42 · sealed at upload
09:12 UTC Entered by preparer 4 March 2026
14:38 UTC Reviewed by reviewer 6 March 2026
11:05 UTC Approved by approver 9 March 2026

Illustrative values. Preparer, reviewer and approver are recorded against each disclosure version. Distinct permission levels per role are in the data model but not yet enforced in the product, and we say so rather than implying otherwise.

The audit trail

The log rejects updates and deletes at database level.

Every write goes through one service that records the user, the change and the time. The activity table has UPDATE and DELETE revoked from every role, including ours, with a database trigger that raises on any attempt. The record of review and approval cannot be revised after the fact.

The distinction that matters here is between a setting and a grant. Most systems that describe themselves as having an audit trail implement it in application code: the software chooses not to offer an edit button. That holds until someone with database access decides otherwise, or until a bug writes over a row. A revoked privilege is different in kind. The database will refuse the statement even when the request is well-formed, authenticated and issued by our own service key.

You do not have to take that on trust, which is the point of putting it in writing. The proof page runs real UPDATE, DELETE and INSERT statements against the live table and prints what Postgres returns, SQLSTATE included. It needs no account and the rejection is not simulated.

What this does not protect against

A database owner can still do anything to a database, ours included, and any vendor telling you otherwise is describing their application layer. What an append-only grant removes is a whole class of quiet change: a figure edited after approval, a bug overwriting history, a compromised browser key planting an entry. It does not remove the operator from your threat model. The trust page sets out where the guarantee stops, and the proof page lets you test the part that holds.

GRANTS · public.activity_logSELECTINSERTUPDATEDELETEanonauthenticatedservice_roleREVOKE UPDATE, DELETE · enforced by trigger, not by application code

Coverage

Thirty-three tracked items, across the four pillars.

A cycle opens with the full IFRS S2 requirement set, each item referenced to the paragraph it comes from and carrying guidance. Progress is measured by what has cleared review and approval, not by what has been drafted.

One clarification, because the numbers invite a coincidence. We track 33 disclosure items, broken out at sub-paragraph level so that each one is small enough to own and evidence separately. The governance pillar, for instance, is a single paragraph of the standard split into the seven things it asks for. Separately, and by chance, the core content of IFRS S2 is also 33 paragraphs. They are different counts of different things, and the table below gives both.

Scroll sideways →

PillarIn the standardTracked items Where they come from
Governance3 paragraphs
5–7
7 The sub-paragraphs of paragraph 6, plus management's role.
Strategy16 paragraphs
8–23
9 Risks and opportunities, business model, transition plan, financial effects and climate resilience.
Risk management3 paragraphs
24–26
7 The sub-paragraphs of paragraph 25, plus integration.
Metrics and targets11 paragraphs
27–37
10 The cross-industry metric categories, and targets.

The standard's own structure is mapped paragraph by paragraph on our IFRS S2 reference page, which is the better place to start if you are scoping the work, not evaluating the software. What a fixed 33-item set makes possible, and who should not buy a single-standard tool, is argued in one standard, not a platform.

Assurance handover

The assurance request, answered by export.

A single archive: disclosures as PDF, the complete activity log as PDF and CSV, every supporting document, and a manifest listing each file with its SHA-256 hash. The structure is built for the way an engagement runs under ISAE 3000 today and ISSA 5000, which is effective for periods beginning on or after 15 December 2026, so the response is produced, not reconstructed.

The manifest is the part that repays attention. A folder of documents proves you kept some files. A manifest with a digest per file, matching the digest recorded when each was uploaded, lets a reviewer test the archive instead of read it. That is a different conversation, and a much shorter one.

The index does the other half of the job. It maps each disclosure to the evidence supporting it, so a reviewer who wants to know what stands behind one figure follows a row rather than asking someone to go and look. Most of the time an assurance provider spends on a first cycle is spent waiting for that answer, and it is the cheapest thing on this page to fix, because the mapping already exists inside the product. The export is only writing it down. Coming the other way, what the spreadsheet import checks and how the round trip avoids duplicate figures is in working with spreadsheets.

auditor-pack-FY2025.zip
disclosures.pdf
activity-log.pdf
activity-log.csv
evidence/ — 41 files
index.csv — disclosure → evidence map
manifest.txt — SHA-256 per file

Illustrative. What an assurer tests is set out in the four evidence tests.

See where your evidence position stands.

Twenty-five questions across the four pillars, scored against the requirements. A twelve-page gap report, written for the person who signs.

Get your free readiness score

No signup, no card. We are at design-partner stage, so you will be talking to the person who built it.

Two ways from here

Read on, or ask a person.

Everything stays open either way. The diagnostic is free and ungated, both prices are published, and the coverage matrix lists what the product does not do. If you would rather put a specific question about your entity to someone, that route exists too, and using it gives you nothing you cannot already read.

Start the free diagnostic →
Talk to a reporting specialist →