Plain answers

Questions worth answering directly.

Including the ones with awkward answers. If something here is missing, ask and it gets added.

How is this different from an enterprise carbon platform?

Enterprise carbon platforms are measurement systems, built to calculate an emissions figure at scale and priced from roughly $37,000 to $250,000 a year for a large sustainability function with mature data infrastructure. Auditably sits after measurement. The question it answers is not what the number is, but whether it can be supported: which document it came from, who reviewed and approved it, and what changed. It does not replace a measurement platform; it replaces the spreadsheet-and-Word-template workflow that has no record of review or approval when the assurance provider asks for one.

Which jurisdictions does Auditably support?

The core product supports IFRS S2 directly, plus jurisdiction-specific overlays for Malaysia (NSRF), the UK (UK SRS S2), Australia (AASB S2), Singapore (SGX), California (SB 261), Brazil (CVM), Pakistan (SECP), Nigeria (FRC), Mexico (CNBV) and Indonesia. An EU ESRS E1 crosswalk is available on request. If your jurisdiction uses vanilla ISSB without local modifications, you are covered out of the box.

How does Auditably handle external assurance?

Two ways. First, a read-only auditor seat: invite your assurance provider into the platform with view-only access to drill into any disclosure, see the data points, view the activity log and inspect evidence files. Second, the auditor pack export: one click produces a ZIP containing PDF disclosures, the complete activity log (CSV and PDF), all evidence files with SHA-256 hashes, and a master index mapping every disclosure to its evidence — structured for ISAE 3000 and the forthcoming ISSA 5000 sustainability assurance standard.

Where is my data stored?

Customer data is held in Supabase (Postgres) with row-level security and tenant isolation, and application infrastructure runs on Cloudflare. Evidence files are stored encrypted at rest with SHA-256 hash verification on upload and export. SOC 2 Type I attestation is in progress (targeted Q4 2026) — we do not claim certifications we do not yet hold. Custom DPAs and EU data residency are available on request.

Can I export everything if I cancel?

Yes. At any time — during your active subscription or your 14-day cancellation window — you can export a full archive of every reporting cycle, disclosure, data point, evidence file and the complete activity log, in CSV, JSON and PDF. Vendor lock-in is incompatible with audit-grade software. Your data is yours.

What if I am not the right person — my Group Reporting Manager is?

That is typical. The diagnostic is designed for the person actually doing the work — Group Reporting Manager, Sustainability Manager or ESG Lead. If you are a CFO or Audit Committee Chair evaluating tools, it gives you a 12-page report you can hand to your team. Forward it — we see this every week.

Do you have customers yet?

We are early — at the design-partner stage, working directly with first-cycle reporters and their advisors to harden the product against real assurance reviews. We will not pretend otherwise with fake logos or invented trusted-by numbers. If you would rather wait for a longer track record, that is fair. If you would rather help shape an audit-trail-first tool — and get founder-level attention while you do — this is the moment to start. The free readiness diagnostic costs nothing.

Is my data secure?

Customer data is isolated per tenant with row-level security in Postgres, served over HTTPS on Cloudflare. Evidence files are SHA-256 hashed on upload and re-verified on export, and the activity log is append-only — it cannot be edited or deleted, even with our own service credentials. SOC 2 Type I is in progress (targeted Q4 2026). We state security posture plainly and never claim a certification we do not hold.

What happens after my first reporting cycle?

Your cycle is preserved — locked, with its full audit trail intact — and the data stays yours. Pro accounts can roll forward into the next reporting year and run year-over-year comparisons, and everything you exported (disclosures, evidence, logs) remains reproducible. You are never locked in: a full archive export is one click away at any time.

Can my auditor access it directly?

Yes. Invite your assurance provider as a free read-only auditor seat — they can drill into any disclosure, inspect the data points and evidence, and read the complete activity log, without being able to change anything. Or hand them the one-click auditor pack. Most teams do both.

Still deciding?

The diagnostic answers the only question that matters: where you actually stand against the 33 disclosure paragraphs.

Run the diagnostic Test the log

Disclosure controls for IFRS S2

Climate disclosure, held to a financial reporting standard.

Every figure carries its supporting documentation, its review, and the record of who approved which version. Auditably keeps that record so a first assurance review has something to test.

No signup. No card. Six minutes.

activity_log append-only · live
09:14:02r.chen@updated Scope 1 gross emissions22.10 tCO2e22.77 tCO2e
09:14:02r.chen@attached evidence gas-invoice-mar.pdfsha256 4f2a9c…
11:38:47m.oduya@approved IFRS S2.29(a)(i) v3locked
11:52:10anonattempted UPDATE on activity_logrejected 42501
Real statement, real database. Two more tests →

Four rows from the demo tenant. The last one is a write the database refused. Try it yourself →

The disclosure was never the hard part.

First-cycle reporters measure carefully and write carefully, then lose the review on the one question nobody prepared for: show me how this number came to be.

Supporting documentation

Hashed at upload. Re-verified on export.

Each file is stored against the figure it supports, with the person who filed it, a timestamp and a size. The SHA-256 is computed when the file arrives and checked again when it leaves in the assurance export, so a reviewer can confirm the document they are reading is the document that was filed.

If the two hashes disagree, the export says so.

PDF
gas-invoice-mar-2026.pdf
sha256 4f2a9c1e7b83d0aa56cf914e2d7b6108…
r.chen@ · 2026-03-14 09:14 · 284 KB

One evidence record, as stored.

Three routes to the same disclosure

Most tools produce the number. Fewer produce the evidence behind it.

Scroll sideways →

ApproachWhat it producesWhere it breaks under review
SpreadsheetsA number, and a folder of files somewhere near it.Nobody can say which version was approved, or what changed after it was.
Carbon platformA measured emissions figure, calculated at scale.Built to calculate, not to evidence. The review trail sits outside the tool.
Disclosure controlsA figure, its supporting documentation, and the record of who reviewed and approved which version.Nothing to reconstruct at review. The trail is the product.

Recorded approval

Sign-off is a record, not a conversation.

Approval attaches to a version of a figure, not to the figure in general. That is the difference between a record a reviewer can test and a recollection.

sign-off record
DisclosureIFRS S2.29(a)(i)
ItemScope 1 gross emissions
Versionv3
Prepared byr.chen@
Prepared2026-03-14
Reviewed byj.pillai@
Reviewed2026-03-19
Approved bym.oduya@
Approved2026-03-22

A completed sign-off record. Nine fields, all populated at the moment the approval happened.

Append-only

The log refuses to be edited.

Not by policy, and not by a setting someone can switch off. Update and delete are refused by the database itself, for every role including our own service credentials.

The rejections on the right are real responses, not screenshots.

Run the test yourself
rejection log live
11:52:10anonUPDATE activity_log SET actor = …permission denied 42501
11:52:14anonDELETE FROM activity_log WHERE …permission denied 42501
11:52:19service_roleUPDATE activity_log SET value = …permission denied 42501
assurance-export.zip
assurance-export/
  disclosures/
    S2-29a-i-scope1.json 12 KB
    S2-29a-iii-scope3.json 31 KB
  evidence/
    gas-invoice-mar-2026.pdf 284 KB
    factor-set-2026.csv 9 KB
  activity_log.csv 1.4 MB
  sign-off-register.csv 48 KB
  hash-manifest.txt 6 KB

The export, as delivered.

The assurance request

Answered by export, not by a week of reconstruction.

A practitioner asks for the figures, the documents behind them, the approvals and the change history. That request is a single export: disclosures, evidence, the full activity log, the sign-off register, and a hash manifest so every file can be checked against what was filed.

Assembling that by hand is where first cycles lose their weeks.

The four questions

Why not keep doing this in spreadsheets?

Scroll sideways →

What a reviewer asksIn a spreadsheetHere
Who approved this figure?A name in a cell, if someone typed one.Approver, timestamp and version, recorded when it happened.
What changed since?File history, if nobody saved over it.Every change, attributed, with the old and new value.
Show me the source document.A shared drive, and a search.Attached to the figure, hashed at upload.
Can you prove it was not edited after sign-off?No. Anyone with the file can edit any cell.The log rejects updates and deletes at the database level.

A spreadsheet is a fine calculator. The problem is that it cannot testify. More questions answered →

Why we built this

I kept watching first-cycle reporters do everything right, and still get taken apart in their first assurance review. Not because the numbers were wrong. Because nobody could show how they were produced.

MR · Founder, Auditably

lineagesource → statement
Source documentgas-invoice-mar-2026.pdf
Activity data124,500 kWh
Emission factor0.18293 kgCO2e/kWh · national set 2026
Calculated22.77 tCO2e
Approvedm.oduya@ · 2026-03-22 · v3
Disclosed atIFRS S2.29(a)(i)

One figure, traced from the invoice it came from to the paragraph it is disclosed at.

Find out where you stand against IFRS S2.

Twelve pages, scored against the 33 disclosure paragraphs. No signup, no card.

Run the diagnostic Check my deadline