Security & Data Protection

Security & data protection

Your sustainability data, under your control

EcoLedger handles the climate, emissions and governance data at the heart of your regulatory disclosures, some of the most sensitive information your organisation produces. This page sets out, in plain terms, how that data is protected, and why with EcoLedger you decide where it lives.

01 You decide where your data lives

Most reporting platforms require you to upload everything into their cloud before you can start. EcoLedger doesn't, and you can change your mind at any time:

  • Keep it entirely on your own device. Work fully on-device and your reporting data stays in your browser, on your machine. In this mode it sends nothing back to us, there is simply no copy of your data on our side to secure, to request, or to breach.
  • Or opt in to encrypted cloud sync. If you want access across devices, you can choose to sync to cloud storage hosted on Cloudflare's global infrastructure.

Sensitive ESG data shouldn't be locked into a vendor by default. With EcoLedger, ownership and location stay with you.

02 Encryption & transport

Every connection to EcoLedger is served over HTTPS, with HTTP Strict Transport Security (HSTS) enforced, browsers are required to use a secure, encrypted connection. When you use cloud sync, your data is stored on Cloudflare, which encrypts data at rest by default. Data you keep on-device never travels to us in the first place.

03 Edge & application protection

EcoLedger is served entirely through Cloudflare's global network, which provides automatic DDoS mitigation at the edge, absorbing large-scale attacks before they reach the application. On top of that, EcoLedger applies defence-in-depth security headers on every response:

Content-Security-Policy Clickjacking protection MIME-sniffing protection HSTS

04 Enterprise-grade infrastructure

Our cloud option runs on Cloudflare, one of the world's largest and most security-focused infrastructure providers, operating an independently audited platform certified to SOC 2 Type II and ISO/IEC 27001. Your data sits on the same backbone that protects a significant share of the internet, rather than on a single self-managed server.

05 Secure payments

Checkout is handled by a payment provider certified to PCI-DSS Level 1, the highest standard for card-data security. EcoLedger never sees, handles or stores your card details.

06 Your data, your rights

You own your data. You can export it at any time and delete it whenever you choose, in on-device mode that's entirely in your hands, and in cloud mode deletion requests are honoured promptly. We never sell your data.

07 Privacy & regulatory compliance

How we handle personal data, the rights you have, and the legal bases we rely on are set out in full in our Privacy Policy, which covers the UK GDPR, EU GDPR and applicable US state privacy laws, including California.

08 Responsible disclosure

Security is never "finished." We keep our practices under continuous review and welcome scrutiny. If you believe you've found a vulnerability, or you have any question about how your data is handled, please get in touch, we take every report seriously and aim to respond quickly.

Questions, or reporting a concern?

Whether you're carrying out vendor due diligence or you've spotted something that needs attention, we're glad to help and to share further detail with prospective customers under NDA where appropriate.

Get in touch via our contact page.