Security and data
Your energy bills, fuel records and emissions figures are business information, so we keep them encrypted, separate from every other customer's, and in your control. Here is exactly how.
Where your data lives
- The app and its database run on Cloudflare's network (Cloudflare Workers and Cloudflare D1). There are no servers of our own to patch or lose.
- Card payments are handled entirely by Stripe. We never see or store full card numbers.
- We don't sell data or show adverts. The providers we use are listed in our privacy notice.
How it's protected
- Every connection is encrypted with HTTPS, and browsers are told to refuse anything else (HSTS).
- Passwords are never stored. We keep a salted PBKDF2-SHA256 hash, so even we can't read them.
- Sign-in sessions use a secure, HTTP-only cookie that scripts on the page can't read. Resetting your password signs you out everywhere.
- Repeated failed sign-ins are slowed down to stop password guessing.
- Pages are sent with strict security headers, including a content security policy and protection against being framed by other sites.
Who can see your data
- Each organisation's data is kept separate, and every request is checked against the organisation you're signed in to. Our automated tests check that one organisation can't read or delete another's data.
- Within your organisation, owners, admins and members have different permissions. Only owners and admins can change settings, invite people or manage billing.
- Invitations and password reset links are single-use and expire (7 days and 1 hour).
- Suppliers you ask for data reach a single form by a private link. They never see your account.
- Important changes, such as billing and settings changes, are recorded in an audit log.
Your data is yours
- Export every activity and emission line as a spreadsheet at any time while your plan is active, with the factor used for each figure.
- If you stop paying, nothing is deleted: choose a plan again and everything is where you left it.
- An owner can delete the organisation and everything in it from Settings. It is removed from the live database straight away.
Cookies and analytics
- Only the cookies needed to sign you in are set without asking. Google Analytics and Microsoft Clarity load only if you agree, and you can change your mind at any time with "Cookie settings" at the foot of each page.
- Cloudflare Web Analytics, which uses no cookies, counts page views.
What we don't have yet
We're a young service, so we'd rather tell you than leave you to find out. We don't yet have two-factor sign-in, single sign-on or an independent certification such as ISO 27001 or Cyber Essentials. Two-factor sign-in is next on our list. If your procurement team has a security questionnaire, send it to us and we'll answer it honestly.
Questions or a security concern?
Email support@carbonrecycling.co.uk. If you think you've found a vulnerability, please tell us privately first and we'll respond quickly. Read our privacy notice for how personal data is handled.