Back to CarbonAtlas

Security Overview

How CarbonAtlas protects your compliance data — encryption, access control, infrastructure, monitoring, and incident response, at a glance.

Last updated: 20 April 2026

Enterprise-grade security by default

CarbonAtlas is built for Fortune 500 CBAM declarants, Big 4 auditors, and EU regulators. Every layer of the platform — from data isolation to encryption at rest and in transit — is designed to meet enterprise procurement and audit standards from day one.

Encryption

  • All data encrypted in transit using TLS 1.2+ for every connection to the platform
  • Data encrypted at rest in our PostgreSQL database using AES-256
  • Sensitive fields (personal data, SMTP credentials, API keys, SSO client secrets) encrypted at the column level using Fernet (AES-128) before storage
  • Digitally signed verification reports use RSA-2048 with PSS/SHA-256 signatures, giving auditors an independently verifiable proof of authenticity

Access Control

  • Role-based access control (RBAC) enforced on every API endpoint — never trusted to the frontend alone
  • All customer data is scoped to the owning organisation at the database query level, preventing cross-tenant access
  • Cross-organisation access (verifiers, customs agents, auditors) requires an explicit, auditable invitation-and-acceptance mandate — never implicit or standing access
  • Enterprise Single Sign-On (SSO/OIDC) supported for Azure AD, Okta, Google Workspace, Auth0, and any RFC 8414-compliant identity provider
  • Time-limited, revocable guest access tokens are available for external auditors and verifiers, with automatic expiry and one-click revocation

Infrastructure

  • Hosted on production-grade cloud infrastructure with automated backups and point-in-time database recovery
  • Environment separation between development and production, with production secrets never present in development environments
  • Database migrations are version-controlled and applied automatically on deploy, with rollback support
  • Application-wide error boundaries contain unexpected failures to the affected screen, so a single rendering error can never expose a raw stack trace or take down the whole application
  • File and document storage (Mill Test Certificates, evidence items) is content-addressed and organisation-scoped, with a drop-in path to object storage (e.g. S3) at scale

Monitoring

  • An immutable, append-only audit log records every significant state change across the platform — who did what, to whose data, and when
  • Daily automated tamper-detection jobs verify cryptographic hashes across declarations, Digital Product Passports, and verification reports
  • Structured audit log export (CEF and NDJSON) integrates with enterprise SIEM tools including Splunk, Microsoft Sentinel, Elastic Stack, and Datadog
  • Rule-based anomaly detection flags emissions data that deviates from sector benchmarks, surfaced to verifiers before a positive opinion can be issued
  • All authentication events, failed login attempts, and privileged actions are logged and retained for audit review

Compliance & Regulatory Alignment

  • Built to support ISO 17029 accredited verification workflows for third-party emissions verifiers
  • GDPR-aligned by design: purpose limitation, data minimisation, and a right-to-revoke on every cross-organisation data-sharing mandate
  • Personally identifiable information (names, contact emails) is encrypted at the field level in line with SOC 2 CC6.1 confidentiality criteria
  • Immutable audit trail architecture aligned with SOC 2 CC7.2 (system monitoring) and CC7.3 (incident evaluation)
  • Time-limited auditor guest access and a one-click Audit Evidence Pack (SOC 2 control mapping, hash registry, audit log export) support external audit engagements
  • Full end-to-end regulatory workflows validated for every organisation type — importer, operator, verifier, and customs agent — as part of every release

Incident Response

  • A documented incident response process covers detection, containment, investigation, and customer notification
  • Security incidents affecting customer data are communicated to affected organisations without undue delay, in line with GDPR Article 33/34 notification obligations
  • The immutable audit log and daily tamper-detection runs give the incident response team a complete, verifiable timeline of any affected data
  • Compromised credentials (API keys, SSO configurations, SMTP relay credentials) can be revoked and rotated immediately by an organisation administrator
  • Security issues can be reported at any time to security@carbonatlas.app for prompt triage and response

Shared Responsibility Model

Ilumatra ArtIfice OÜ is responsible for:

  • Securing the underlying infrastructure, network, and hosting environment
  • Encrypting data in transit and at rest, and encrypting sensitive fields at the column level
  • Enforcing organisation-level data isolation and role-based access control at the application layer
  • Maintaining the immutable audit trail, tamper-detection jobs, and platform-wide monitoring
  • Patching, deploying, and testing the application, including the mandatory build and workflow verification gates run before every release

Your organisation is responsible for:

  • Managing user accounts, roles, and access within your organisation, including timely offboarding of departed staff
  • Choosing strong, unique passwords or enabling Single Sign-On (SSO) where available
  • Reviewing and approving cross-organisation mandates (verifier engagements, customs agent mandates) before granting access to your data
  • The accuracy of emissions, import, and declaration data entered or uploaded to the platform
  • Configuring and securing any third-party integrations you connect, such as ERP connectors and API keys

Penetration Testing

CarbonAtlas undergoes periodic security testing of its application and infrastructure. Findings are triaged and remediated according to severity, with critical issues addressed as a priority.

Enterprise customers may request a summary of our most recent penetration test results, subject to a mutual non-disclosure agreement, by contacting connect@ilumatraartifice.com.

Enterprise Security Review

If your organisation's procurement process requires a formal security questionnaire, SOC 2 evidence pack, architecture review, or vendor risk assessment, our team can support your review directly.

Request a Security Review

We typically respond to enterprise security review requests within 2 business days.

Contact

Ilumatra ArtIfice OÜ

Provider of the CarbonAtlas CBAM compliance platform

Security: connect@ilumatraartifice.com

Privacy: connect@ilumatraartifice.com

Legal: connect@ilumatraartifice.com