Trust Center

Your sustainability data, protected by design

METRIQOm® helps organizations manage ESG and regulatory reporting. Security, privacy and data residency are built into how we operate — not bolted on. This center summarizes our posture; detailed documentation is available on request under NDA.

Last updated: July 2026·Questions? Contact our team
Security

Engineered to protect your data

A defence-in-depth posture across infrastructure, encryption, application and access — reviewed on every release.

Infrastructure

METRIQOm® runs on leading managed cloud platforms — AWS for international & GCC, Yandex Cloud for Russia — within isolated private networks. Databases are not publicly reachable and are accessed only over the internal network.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest using industry-standard managed encryption.

Application security

Authentication uses signed, expiring session tokens; passwords are stored only as salted one-way hashes. Access to data is scoped per tenant on every request.

Access control

Role-based, least-privilege access. Administrative access is restricted, protected by multi-factor authentication, and recorded in an append-only audit log. METRIQOm® staff have no standing access to customer sustainability data.

Secure development

Changes go through review and automated checks before release; deployments are versioned and reversible.

Privacy & data protection

You own your data

Customer data belongs to the customer. We process it only to provide the service, and only on the customer's instructions.

Ownership

Customer data belongs to the customer. We process it only to provide the service and only on the customer's documented instructions.

Data residency by region

International & GCC data is hosted in-region on AWS. Russian data is hosted in-country on Yandex Cloud, aligned with 152-FZ. Customers can also run METRIQOm® single-tenant in their own cloud, so data never leaves their environment.

Retention & deletion

Customer data is retained for the life of the subscription and deleted or returned on termination, per the DPA.

Sub-processors

We use a small, vetted set of providers (cloud hosting, payments, transactional email, AI). The current list and our change-notification process are available on request.

Data-subject requests

We assist customers in responding to access, correction and deletion requests, as set out in the DPA.

AI & your data

AI that never trains on your data

Your data generates output — it never trains a model

METRIQOm®'s AI features are powered by large language models accessed via API. Data sent to these models is used only to generate the requested output and is never used to train them. International deployments use enterprise AI (Anthropic / OpenAI) under terms that prohibit training on customer data. Russian deployments use in-country AI (YandexGPT) exclusively — no ESG data is sent to US or EU AI providers.

Availability & resilience

Built to stay up — and to recover

Backups

Automated, encrypted backups with point-in-time recovery.

Recovery objectives

RTO / RPO targets are defined in our DPA and shared on request.

Isolation of failures

Each region operates independently; an issue in one does not affect another.

Deployment models

Deploy the way your data policy requires

SaaS (multi-tenant)

Fully managed by METRIQOm®, with per-tenant data isolation. No servers to run — live in days.

Single-tenant / on-premise

Deployed inside the customer's own cloud account and region, under a license — maximum data control and residency.

Incident response & breach notification

If something happens, you hear it from us — fast

A defined incident-response process

We maintain an incident-response process. If a security incident affects your data, we notify you promptly and without undue delay — consistent with our DPA and applicable law — with the information you need to meet your own obligations.

Compliance & assurance

Our assurance roadmap

Independent evidence, staged so it unblocks reviews today and builds toward formal certification.

Phase 1 ● Available now

Trust Center & DPA

This Trust Center is live today. Our GDPR-aligned Data Processing Agreement — with a 152-FZ variant for Russian operations — is available on request.

Phase 2 ● On request

Pen-test summary & questionnaires

A shareable independent penetration-test summary, plus completed CAIQ and SIG Lite questionnaires, are available to qualified prospects on request.

Phase 3 ◷ Targeted · end of 2027

ISO 27001 certification

ISO 27001 is on our security roadmap, scoped to the entity operating the platform and cloud, with certification targeted by the end of 2027.

Responsible disclosure

Found a vulnerability?

We investigate all good-faith reports and will not pursue action against researchers who act responsibly and avoid privacy violations or service disruption.

Report a security issue
Request documents

Detailed documentation, on request

To receive any of the following, contact our team. An NDA may apply.

Data Processing AgreementPenetration-test summarySub-processor listCAIQ / SIG Lite
Request documents