Plain answers
Questions worth answering directly.
Including the ones with awkward answers. If something here is missing, ask and it gets added.
How is this different from an enterprise carbon platform?
Enterprise carbon platforms are measurement systems, built to calculate an emissions figure at scale and priced from roughly $37,000 to $250,000 a year for a large sustainability function with mature data infrastructure. Auditably sits after measurement. The question it answers is not what the number is, but whether it can be supported: which document it came from, who reviewed and approved it, and what changed. It does not replace a measurement platform; it replaces the spreadsheet-and-Word-template workflow that has no record of review or approval when the assurance provider asks for one.
Which jurisdictions does Auditably support?
The core product supports IFRS S2 directly, plus jurisdiction-specific overlays for Malaysia (NSRF), the UK (UK SRS S2), Australia (AASB S2), Singapore (SGX), California (SB 261), Brazil (CVM), Pakistan (SECP), Nigeria (FRC), Mexico (CNBV) and Indonesia. An EU ESRS E1 crosswalk is available on request. If your jurisdiction uses vanilla ISSB without local modifications, you are covered out of the box.
How does Auditably handle external assurance?
Two ways. First, a read-only auditor seat: invite your assurance provider into the platform with view-only access to drill into any disclosure, see the data points, view the activity log and inspect evidence files. Second, the auditor pack export: one click produces a ZIP containing PDF disclosures, the complete activity log (CSV and PDF), all evidence files with SHA-256 hashes, and a master index mapping every disclosure to its evidence — structured for ISAE 3000 and the forthcoming ISSA 5000 sustainability assurance standard.
Where is my data stored?
Customer data is held in Supabase (Postgres) with row-level security and tenant isolation, and application infrastructure runs on Cloudflare. Evidence files are stored encrypted at rest with SHA-256 hash verification on upload and export. SOC 2 Type I attestation is in progress (targeted Q4 2026) — we do not claim certifications we do not yet hold. Custom DPAs and EU data residency are available on request.
Can I export everything if I cancel?
Yes. At any time — during your active subscription or your 14-day cancellation window — you can export a full archive of every reporting cycle, disclosure, data point, evidence file and the complete activity log, in CSV, JSON and PDF. Vendor lock-in is incompatible with audit-grade software. Your data is yours.
What if I am not the right person — my Group Reporting Manager is?
That is typical. The diagnostic is designed for the person actually doing the work — Group Reporting Manager, Sustainability Manager or ESG Lead. If you are a CFO or Audit Committee Chair evaluating tools, it gives you a 12-page report you can hand to your team. Forward it — we see this every week.
Do you have customers yet?
We are early — at the design-partner stage, working directly with first-cycle reporters and their advisors to harden the product against real assurance reviews. We will not pretend otherwise with fake logos or invented trusted-by numbers. If you would rather wait for a longer track record, that is fair. If you would rather help shape an audit-trail-first tool — and get founder-level attention while you do — this is the moment to start. The free readiness diagnostic costs nothing.
Is my data secure?
Customer data is isolated per tenant with row-level security in Postgres, served over HTTPS on Cloudflare. Evidence files are SHA-256 hashed on upload and re-verified on export, and the activity log is append-only — it cannot be edited or deleted, even with our own service credentials. SOC 2 Type I is in progress (targeted Q4 2026). We state security posture plainly and never claim a certification we do not hold.
What happens after my first reporting cycle?
Your cycle is preserved — locked, with its full audit trail intact — and the data stays yours. Pro accounts can roll forward into the next reporting year and run year-over-year comparisons, and everything you exported (disclosures, evidence, logs) remains reproducible. You are never locked in: a full archive export is one click away at any time.
Can my auditor access it directly?
Yes. Invite your assurance provider as a free read-only auditor seat — they can drill into any disclosure, inspect the data points and evidence, and read the complete activity log, without being able to change anything. Or hand them the one-click auditor pack. Most teams do both.
Still deciding?
The diagnostic answers the only question that matters: where you actually stand against the 33 disclosure paragraphs.