Building a Carbon & ESG Management SaaS - Episode 1: Security

While corporate climate impact data is increasingly becoming public, why does data security remain crucial when offering an online carbon management solution, and how do we address this at Tennaxia?

Patrick Nollet
Chief Technical Officer
Publication : 
15.06.2023
Table of Contents
Request a demo

On the importance of securing corporate carbon data and climate strategy.

Tennaxia ESG is a SaaS software platform that enables companies to measure their carbon footprint and implement action plans to reduce it. While more and more companies are tending, whether due to regulatory pressure or otherwise, to share their CSR initiatives and the overall results of their Carbon Footprint, the fact remains that measuring a carbon footprint is generally done using operational data that can sometimes be highly sensitive : purchases, energy expenditure, employee travel, industrial processes…

This is especially true when conducting a carbon assessment according to the most rigorous carbon methodological standards, as is the case at Tennaxia, as these standards require delving precisely into the details of a company's value chain: production methods, suppliers and service providers, investments, logistics, etc.

Since establishing a Carbon Footprint is merely the necessary prerequisite for taking action to reduce emissions, Tennaxia clients also manage their reduction trajectories and, most importantly, their associated decarbonization action plans on the platform. Because Tennaxia ESG allows for detailed modeling of both the carbon and financial impact of reduction actions, this requires the processing of strategic business data that is therefore critical to our clients.

It is therefore natural for Tennaxia clients to want to ensure that the data they entrust to us is properly secured.

Tennaxia is compliant with SOC 2 security standards.

Since the creation of Tennaxia ESG, we have applied to the design of our ESG software a number of key principles to ensure the implementation of a secure and reliable system. But more than the product itself, it is the entire company organization that must align to ensure our product maintains a high level of security and operational quality.

While there are regulations to comply with today, such as the GDPR (with which Tennaxia is, of course, compliant), which govern the processing of personal data and ensure its proper management, it remains essential for our clients that the proper application of best security practices by their suppliers be recognized by an independent body.

Standards have therefore been developed to audit and evaluate companies like Tennaxia on their ability to adhere to security best practices. Some of these standards are sector-specific, such as PCI-DSS for companies handling payments, while others are more general.

Thus, Tennaxia began by conducting a SOC 2 Type 1 audit toattest to the organization's and its product's ability to meet the most stringent security requirements.

We then conducted a new, more ambitious audit: SOC 2 Type 2. The difference between Type 2 and Type 1 is that compliance with our security commitments and procedures was tested over several months rather than at a single point in time. This provides an even greater guarantee of security. In our case, no failures to follow our procedures were identified.

SOC 2 audit categories

In general, a SOC 2 audit can evaluate criteria grouped into five main categories:

  • Security : The technical infrastructure must be protected against the risks it may face.
  • Availability : The technical infrastructure must remain available so that our tool remains accessible to clients.
  • Processing integrity : At all times, the information provided by the system must be reliable.
  • Privacy : information must only be available to authorized personnel.
  • Personal data : personal data must be managed and stored appropriately.

Our audit focused heavily on security.

How is data processed at Tennaxia?

What does this mean in practice for Tennaxia’s client data?

Here are a few examples:

  • Our clients' data is encrypted at rest and in transit, meaning while the data is moving from one computer to another.
  • We have implemented strict access management policies for our internal tools.
  • Our workstations are regularly updated, protected by antivirus, antimalware, and firewall solutions, and our drives are encrypted.
  • We regularly conduct penetration tests and vulnerability scans on our technical infrastructure.
  • All Tennaxia employees are trained on security issues, and phishing simulation campaigns are conducted regularly.
  • We have implemented procedures to manage potential incidents, and we test them regularly.
  • We have a strict policy for managing our subcontractors.

These are just a few examples, but it is clear that building a secure and reliable platform cannot be improvised; it requires time and investment from all Tennaxia employees.

Nevertheless, it remains essential to maintain the trust of our clients, meet the default expectations of large enterprise accounts, and be able to support all our clients in their climate strategies in the most precise and ambitious way possible.

The detailed results of Tennaxia's SOC 2 Type 2 audit are available upon request by email at: contact@tennaxia.com