Security & Legal

Transparency about how we protect your data, maintain compliance, and operate responsibly at Verdantix.

Last updated: June 15, 2025

Security Overview

At Verdantix, security is foundational to everything we do. As a green technology company handling sensitive environmental data, client energy records, and carbon analytics, we maintain a rigorous security posture aligned with industry best practices and regulatory requirements.

Security-First Philosophy

Every product we build and service we deliver incorporates security by design and default. Our team undergoes continuous security training and our systems are regularly audited.

24/7 Monitoring

Our infrastructure is monitored around the clock by an in-house security operations center (SOC) and third-party managed detection and response (MDR) provider.

Vulnerability Management

We run automated vulnerability scans daily and conduct quarterly penetration tests by independent security firms.

Zero Trust Architecture

All access to our systems follows a zero-trust model — no implicit trust based on network location. Every request is authenticated, authorized, and encrypted.

Continuous Improvement

Our security program evolves with emerging threats. We participate in industry threat intelligence sharing and maintain a responsible disclosure program.

Data Protection

We implement comprehensive data protection measures across all stages of the data lifecycle — from collection and processing to storage and deletion.

Data Classification

All data handled by Verdantix is classified according to sensitivity level, which determines the controls applied:

Classification Description Examples
Public Information safe for public disclosure Marketing materials, blog posts
Internal For internal use only Operational documentation, internal metrics
Confidential Sensitive business data Client energy data, financial records
Restricted Highly sensitive, strictly controlled PII, credentials, encryption keys

Data Retention & Deletion

  • Client data is retained for the duration of the contractual relationship plus a 30-day post-termination window.
  • Upon request, we securely delete all client data using cryptographic erasure or physical media destruction.
  • Logs and audit records are retained for a minimum of 12 months for compliance purposes.
  • We provide a Data Processing Agreement (DPA) template that can be customized for enterprise clients.

Infrastructure Security

Verdantix's infrastructure is built on enterprise-grade cloud platforms with redundant, geographically distributed architecture to ensure availability and resilience.

Cloud Providers

Our primary infrastructure is hosted on AWS and GCP, both of which maintain SOC 2 Type II, ISO 27001, and other leading certifications. We leverage their built-in security controls and compliance programs.

Infrastructure as Code

All infrastructure is provisioned through infrastructure-as-code (Terraform) with peer review and automated policy checks. No manual changes are permitted in production environments.

Network Security

  • All traffic between services is encrypted using mutual TLS (mTLS)
  • Web Application Firewall (WAF) rules protect against OWASP Top 10 threats
  • DDoS protection is provided at the network edge via Cloudflare and AWS Shield
  • Segmented VPCs isolate production, staging, and development environments
  • Strict egress controls prevent unauthorized data exfiltration

Encryption Standards

We encrypt all data both at rest and in transit using industry-standard cryptographic algorithms.

Context Algorithm Key Management
Data in transit TLS 1.3 (AES-256-GCM) Rotated certificates via ACM
Data at rest (databases) AES-256 AWS KMS / GCP Cloud KMS
File storage (S3/GCS) AES-256 Customer-managed keys available
API authentication JWT with RS256 Hardware-backed key storage
Email communications SMTP with TLS 1.2+ DMARC, DKIM, SPF enforced

Customer-Managed Keys

Enterprise clients can use their own encryption keys (BYOK) for data stored in Verdantix systems, ensuring full key sovereignty and control.

Access Control & Identity

Access to Verdantix systems and client data follows the principle of least privilege with comprehensive identity management.

Employee Access

  • Multi-factor authentication (MFA) is required for all employee accounts — no exceptions
  • Access is provisioned via role-based access control (RBAC) with quarterly access reviews
  • Privileged access is managed through a PAM solution with just-in-time provisioning and session recording
  • Offboarding procedures ensure immediate access revocation upon employee departure

Client Access

  • SSO integration via SAML 2.0 or OIDC for enterprise clients
  • Role-based permissions within the Verdantix platform (Admin, Editor, Viewer, Auditor)
  • API access via scoped OAuth 2.0 tokens with configurable expiration
  • Comprehensive audit logging of all user actions with 12-month retention

Incident Response

We maintain a formal incident response program aligned with NIST SP 800-61 and have conducted tabletop exercises quarterly.

Response Timeline

Phase Target Time Actions
Detection < 1 hour Automated alerts via SIEM, endpoint detection, and log analysis
Triage < 2 hours Severity classification, incident commander assignment, stakeholder notification
Containment < 4 hours Isolation of affected systems, blocking attack vectors, preserving evidence
Resolution < 24 hours Remediation, system restoration, verification of fix effectiveness
Post-Incident < 7 days Root cause analysis, lessons learned, updated procedures, client communication

Client Notification

In the event of a security incident affecting client data, we commit to notification within 72 hours of confirmed detection, in alignment with GDPR requirements and our contractual obligations.

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you believe you've found a security issue in Verdantix systems:

  • Email: security@verdantix.com
  • PGP key available at https://verdantix.com/.well-known/pgp-key.txt
  • We respond to all reports within 48 hours
  • We provide a bug bounty program for valid findings

Compliance & Certifications

Verdantix maintains compliance with leading industry standards and regulatory frameworks relevant to our operations in sustainability and green technology.

SOC 2 Type II

Annually audited against SOC 2 Trust Service Criteria for Security, Availability, and Confidentiality. Latest report available under NDA.

ISO 27001

Certified Information Security Management System (ISMS) following international best practices for information security.

GDPR

Fully compliant with EU General Data Protection Regulation. Appointed an EU-based Data Protection Officer (DPO).

CCPA/CPRA

Compliant with California Consumer Privacy Act and California Privacy Rights Act. Resident rights honored within 45 days.

Industry-Specific Compliance

As a green technology company, we also adhere to:

  • GHG Protocol — Greenhouse Gas Accounting and Reporting Standards
  • ISO 14001 — Environmental Management Systems certification
  • EU Taxonomy — Classification system for environmentally sustainable activities
  • CSRD — Corporate Sustainability Reporting Directive alignment
  • SEC Climate Disclosure Rules — Prepared for US regulatory requirements

Compliance Documentation

Our SOC 2 report, ISO certificates, and full compliance documentation package are available to prospective and existing clients upon request. Contact compliance@verdantix.com.

Privacy Policy

Effective Date: January 1, 2025

1. Information We Collect

We collect information in the following categories:

  • Personal Information: Name, email address, company affiliation, and contact details when you create an account, request a demo, or contact us.
  • Usage Data: How you interact with our platform, including pages viewed, features used, and access timestamps.
  • Environmental Data: Energy consumption data, carbon emissions metrics, and facility information that you choose to upload to our platform.
  • Device Information: IP address, browser type, device identifiers, and operating system information.
  • Communications: Content of support tickets, emails, and other communications with our team.

2. How We Use Your Information

  • Provide, maintain, and improve our sustainability and green technology services
  • Process and analyze environmental data for carbon analytics and reporting
  • Communicate with you about service updates, security notices, and product features
  • Comply with legal obligations and regulatory reporting requirements
  • Prevent fraud, abuse, and security threats

3. Data Sharing & Third Parties

We do not sell your personal data. We may share data with:

  • Service Providers: Cloud infrastructure (AWS, GCP), analytics, and communication tools — all bound by data processing agreements
  • Regulatory Bodies: When required by law or for compliance reporting
  • Professional Advisors: Legal counsel, auditors, and insurers under confidentiality obligations

4. Your Rights

Depending on your location, you may have the right to:

  • Access, correct, or delete your personal data
  • Port your data in a machine-readable format
  • Restrict or object to processing
  • Withdraw consent at any time (where processing is consent-based)
  • Lodge a complaint with a supervisory authority

5. Data Transfers

Our services may process data across borders. For transfers from the EEA/UK, we rely on EU Standard Contractual Clauses (SCCs) and/or adequacy decisions. We have completed Transfer Impact Assessments for all data processors.

6. Children's Privacy

Verdantix's services are not directed to individuals under 16. We do not knowingly collect personal data from children.

Terms of Service

Effective Date: January 1, 2025

1. Acceptance of Terms

By accessing or using Verdantix's platforms, services, or APIs, you agree to be bound by these Terms. If you are using Verdantix on behalf of an organization, you represent that you have authority to bind that organization to these Terms.

2. Service Description

Verdantix provides cloud-based sustainability analytics, carbon footprint tracking, energy management, and green technology consulting services. The specific features and scope of services are defined in your subscription agreement or service order.

3. Acceptable Use

You agree not to:

  • Use the service to violate any applicable law or regulation
  • Attempt to gain unauthorized access to any system or network
  • Interfere with or disrupt the integrity or performance of the service
  • Upload false, misleading, or fraudulent environmental data
  • Reverse engineer, decompile, or disassemble any software components
  • Use the service to generate content that infringes on third-party intellectual property

4. Data Ownership

You retain all rights to your data. Verdantix acts as a data processor and does not claim ownership of any data you upload. We may create aggregated, anonymized, and de-identified datasets for product improvement and industry benchmarking, but never data that could identify your organization.

5. Service Level Agreement (SLA)

Plan Uptime SLA Support Response
Starter 99.5% Business hours, < 24h
Professional 99.9% < 8h response
Enterprise 99.99% < 1h response, 24/7

6. Limitation of Liability

Verdantix's total liability shall not exceed the fees paid by you in the 12 months preceding the claim. We are not liable for indirect, incidental, or consequential damages. These limitations apply to the maximum extent permitted by law.

7. Termination

Either party may terminate the agreement with 30 days written notice. Upon termination, we will provide a 30-day data export window after which all data will be securely deleted.

8. Governing Law

These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Disputes will be resolved through binding arbitration in San Francisco, CA, except where injunctive relief is sought.

Contact Us

For security inquiries, vulnerability reports, compliance requests, or legal questions, please reach out through the appropriate channel below.

Get in Touch

We aim to respond to all security and legal inquiries within one business day.