Security & data

Multi-Tenancy & Data Isolation

How your organisation's data stays completely separate from every other customer's.

GUIDE
Security & data

The model

Many companies use Carbon Passport, and they all share the same software. But everything belonging to you — your documents, your line items, your emission records, your suppliers and your rules — is tied to your company and kept in its own space. No other customer can reach it.

How isolation is enforced

  1. We check who you are. You sign in, and we confirm the account is really yours.
  2. We check which company you belong to. You can only ever see a company you have actually been added to.
  3. We filter every request ourselves. When you ask for anything, we decide which company's data to return based on your account — not based on anything your browser asks for. This means editing a web address cannot get you into another company's data.
  4. Everything your data creates belongs to you too. Line items, emission records and anything else built from your documents all carry your company's ownership. And when something is deleted, the deletion never reaches beyond your own company.

Roles within your organisation

Inside your own company, an Org Admin has full control, an Org Editor can upload, review and run calculations, and an Org Viewer can only look at dashboards and reports. Think of it this way: your role decides what you are allowed to *do*, and your company membership decides whose data you can *see at all*.

Isolation guarantees

  • A request never returns data from a company you are not part of.
  • Which company's data you get is worked out from your account, not from anything sent by your browser.
  • Uploaded files are filed under your company and can only be opened through your company.
  • When your accounting software syncs, it syncs into your company only — data from two customers can never mix during a sync.