Security
Your operational data stays yours.
Verdant handles energy bills, fuel records, travel data, and supplier spend on behalf of your company. This page explains exactly how we protect it.
Encrypted in transit and at rest.
All data moving between your browser and our servers travels over TLS 1.2 or higher. We do not support older TLS versions or unencrypted HTTP connections to any authenticated endpoint. Certificate management is automated and certificates are renewed before expiry.
Data at rest is encrypted using AES-256. Encryption keys are scoped per environment, stored separately from the data they protect, and rotated on a scheduled cycle. Backup snapshots are encrypted under the same scheme as primary storage.
US-hosted, managed cloud.
Verdant runs entirely on US-based cloud infrastructure. Compute, object storage, managed databases, and the job queue that drives report drafting all operate within the United States. No customer data is written to infrastructure outside the US without an explicit residency agreement in place.
Infrastructure is provisioned through a major US cloud provider under their standard enterprise terms, which include physical security controls, environmental redundancy, and SOC 2 and ISO 27001 compliance at the infrastructure layer. Verdant's application-layer controls are described on this page.
Enterprise customers with specific data residency requirements should contact us at security@verdalytiq.com before signing. We will confirm what is available and commit to it in the order form.
Least privilege, logged, and audited.
Internal access to production systems follows a strict least-privilege model. No engineer holds standing access to customer data. Production access is role-based, gated behind multi-factor authentication, and requires a time-limited credential that is revoked automatically on expiry. All access events are written to a tamper-evident audit log.
Within your workspace, role-based permissions let your admins control who can upload data, review draft reports, export figures, and manage workspace settings. Team and Enterprise plans include a full audit trail of workspace activity exportable in structured format. Changes to permissions are logged with the actor and timestamp.
Offboarding a team member revokes their access to the workspace immediately. Session tokens are invalidated on logout and on password change.
Your data is sent to draft reports, not to train models.
Verdant is model-agnostic. When you submit operational data to generate a carbon or ESG report draft, your data is routed to one or more third-party LLM providers depending on your workspace configuration. This is the core reporting function of the Service.
In every case, the data processing agreement we hold with each LLM provider explicitly prohibits that provider from using your operational data, document contents, or draft report text to train, fine-tune, or otherwise improve its models. Your content is processed transiently within the provider's API and is not retained beyond the request window.
If your organization requires that sensitive operational data be redacted before it is sent to an LLM provider, contact us at security@verdalytiq.com. Enterprise plans support configurable redaction rules that can mask specific data fields before the report-drafting step.
A current list of the LLM providers your workspace may route to is available in your workspace settings and on request from security@verdalytiq.com.
Your workspace is not shared with other customers.
Each Verdant workspace is logically isolated at the data layer. Operational data, draft reports, GHG inventories, and methodology notes created in your workspace are never visible to another organization, regardless of plan or account status.
Workspace identifiers are scoped at the database level. Queries that retrieve customer content are constructed to include the organization identifier, so a misconfigured query cannot return data from another tenant. We test this isolation boundary on every major release.
We do not train on your operational data.
When you upload an energy bill, a fleet fuel report, a travel expense file, or any other operational data to Verdant, that content belongs to you. We process it to draft your report and for no other purpose. It is not stored in a training corpus, and it does not improve any shared model, whether ours or a provider's.
The same applies to the draft reports, GHG inventories, methodology notes, and workspace history your team accumulates. None of that content is used to train or fine-tune machine-learning models. All subprocessors with access to customer content are bound by data-processing agreements that reflect this restriction explicitly.
This is a firm architectural commitment, not a default setting that can be toggled off.
Durable storage and recovery.
Workspace data is backed up on an automated schedule. Backup snapshots are encrypted and stored separately from primary storage. We test restoration from backup on a regular cycle.
If you delete a file or report draft, it is removed from active storage immediately. Backup copies containing the deleted content are purged on a 30-day rolling cycle. If you close your account, we confirm receipt of the closure request and complete the purge of your data within that same window.
We maintain a public status page at verdalytiq.com/status where you can track platform availability and view historical uptime.
Report a security issue.
If you believe you have found a security vulnerability in Verdant, please report it to security@verdalytiq.com. We ask that you give us reasonable time to investigate and address the issue before any public disclosure. We will acknowledge receipt within one business day and keep you informed as we work toward a resolution.
We do not pursue legal action against security researchers who report issues in good faith, provide us with reasonable time to respond, and follow coordinated disclosure practices. Please do not access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability.
Where we are and where we are headed.
Verdant is a Pre-Seed company founded in 2023. We are honest about our current compliance posture: we are not yet SOC 2 Type II certified, but our controls are designed to meet the Trust Services Criteria for security, availability, and confidentiality. Third-party attestation is in progress and is a near-term priority.
Our privacy practices are aligned with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We honor rights requests from users in the European Economic Area and California regardless of where the request originates. See our Privacy Policy for details.
Penetration testing runs on a scheduled cycle conducted by a third-party provider. Findings are triaged by severity and remediated on a tracked timeline. Enterprise customers with specific compliance requirements, including sustainability-related data governance frameworks relevant to CSRD or CDP reporting, are encouraged to start the conversation early so we can plan together.
This page is updated as our posture matures. Material changes are noted in the Changelog.
Who processes your data on our behalf.
Verdant uses a limited number of subprocessors to deliver the Service. All subprocessors are bound by data-processing agreements that restrict their use of customer data to providing the specific service contracted and that prohibit training on customer content.
- Cloud infrastructure. We run on a major US cloud provider. Infrastructure includes compute, object storage, managed databases, and the job queue that manages report drafting. No customer data leaves the contracted US regions without an explicit residency agreement.
- LLM model providers. Report drafting routes operational data to one or more third-party LLM APIs under your workspace configuration. Each provider is bound by a data-processing agreement that prohibits using customer content to train or improve their models. Content is processed transiently and is not retained beyond the request window.
- Payment processing. Subscription billing is handled by a third-party payment processor. We do not store card numbers or bank account details on our own servers. The processor receives billing contact details and subscription metadata only.
- Transactional email. Account confirmations, password resets, billing receipts, and workspace alerts are delivered via a third-party email provider. Only the recipient address and the email body are shared with this provider.
- Error monitoring. Application errors and performance traces are captured by an error monitoring service to support debugging. We configure this service to minimize customer data in error payloads.
Enterprise and Team customers may request the current subprocessor list and the applicable data-processing agreements before signing. Send the request to security@verdalytiq.com.
Security questions before you sign?
For security questions, to request our full security questionnaire, or to report a vulnerability, contact us at security@verdalytiq.com or by post at:
Verdant Inc.
Attn: Security
1908 Pearl Street, Suite 210
Boulder, CO 80302
United States