METRIQOm® helps organizations manage ESG and regulatory reporting. Security, privacy and data residency are built into how we operate — not bolted on. This center summarizes our posture; detailed documentation is available on request under NDA.
A defence-in-depth posture across infrastructure, encryption, application and access — reviewed on every release.
METRIQOm® runs on leading managed cloud platforms — AWS for international & GCC, Yandex Cloud for Russia — within isolated private networks. Databases are not publicly reachable and are accessed only over the internal network.
Data is encrypted in transit (TLS 1.2+) and at rest using industry-standard managed encryption.
Authentication uses signed, expiring session tokens; passwords are stored only as salted one-way hashes. Access to data is scoped per tenant on every request.
Role-based, least-privilege access. Administrative access is restricted, protected by multi-factor authentication, and recorded in an append-only audit log. METRIQOm® staff have no standing access to customer sustainability data.
Changes go through review and automated checks before release; deployments are versioned and reversible.
Customer data belongs to the customer. We process it only to provide the service, and only on the customer's instructions.
Customer data belongs to the customer. We process it only to provide the service and only on the customer's documented instructions.
International & GCC data is hosted in-region on AWS. Russian data is hosted in-country on Yandex Cloud, aligned with 152-FZ. Customers can also run METRIQOm® single-tenant in their own cloud, so data never leaves their environment.
Customer data is retained for the life of the subscription and deleted or returned on termination, per the DPA.
We use a small, vetted set of providers (cloud hosting, payments, transactional email, AI). The current list and our change-notification process are available on request.
We assist customers in responding to access, correction and deletion requests, as set out in the DPA.
METRIQOm®'s AI features are powered by large language models accessed via API. Data sent to these models is used only to generate the requested output and is never used to train them. International deployments use enterprise AI (Anthropic / OpenAI) under terms that prohibit training on customer data. Russian deployments use in-country AI (YandexGPT) exclusively — no ESG data is sent to US or EU AI providers.
Automated, encrypted backups with point-in-time recovery.
RTO / RPO targets are defined in our DPA and shared on request.
Each region operates independently; an issue in one does not affect another.
Fully managed by METRIQOm®, with per-tenant data isolation. No servers to run — live in days.
Deployed inside the customer's own cloud account and region, under a license — maximum data control and residency.
We maintain an incident-response process. If a security incident affects your data, we notify you promptly and without undue delay — consistent with our DPA and applicable law — with the information you need to meet your own obligations.
Independent evidence, staged so it unblocks reviews today and builds toward formal certification.
This Trust Center is live today. Our GDPR-aligned Data Processing Agreement — with a 152-FZ variant for Russian operations — is available on request.
A shareable independent penetration-test summary, plus completed CAIQ and SIG Lite questionnaires, are available to qualified prospects on request.
ISO 27001 is on our security roadmap, scoped to the entity operating the platform and cloud, with certification targeted by the end of 2027.
We investigate all good-faith reports and will not pursue action against researchers who act responsibly and avoid privacy violations or service disruption.
To receive any of the following, contact our team. An NDA may apply.