Trust
How we protect your data
CBAM XML data contains commercially sensitive production figures. This page sets out the architecture, controls, and legal basis under which Carbon Mandate handles that data.
Live demonstration
See the engine live. 20 minutes.
We scan a real CBAM dataset and show you where the risk flags land. No slides.
Live demonstration
See the engine live. 20 minutes.
We scan a real CBAM dataset and show you where the risk flags land. No slides.
Data architecture
Each customer's data is isolated at the database layer via row-level security policies. No customer can access another customer's declarations, supplier data, or XML output. Enforcement is at the database, not the application layer. Service role credentials are never exposed to client code. All privileged operations run server-side only.
Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Encryption is applied at the infrastructure layer. It is not dependent on application-level configuration.
GDPR and UK GDPR
Carbon Mandate is incorporated in England and Wales (Companies House 17288007) and operates under UK GDPR. We do not sell, share, or use customer CBAM data for any purpose other than delivering the contracted service.
Sub-processors
Customer data is stored in EU (Stockholm).
Legal entity
Carbon Mandate Ltd. Registered in England and Wales. Companies House registration 17288007. Carbon Mandate is a registered trademark.
BOOK A DEMO
See your CBAM XML validated live.
20 minutes. No slides. We scan a real CBAM dataset, surface the risk flags, and hand back a Registry-ready package for your EU importer to file.
Carbon Mandate Ltd · Reg 17288007 · England & Wales