Hosting region, encryption, backups, deletion, and subprocessors — published without unverified certification claims. ISO 27001 / SOC 2 are not claimed here.
Application runtime and Firebase project services are configured for europe-west1 (EU).
IN TRANSIT
TLS
Public endpoints are served over HTTPS/TLS. Session cookies are HttpOnly.
AT REST
Provider encryption
Firestore and Cloud Storage data use Google Cloud encryption at rest under the Firebase/Google Cloud platform defaults.
AUTH
Session model
Firebase ID token → server createSessionCookie() → HttpOnly __session → server verification. Tenant and case ownership are enforced server-side.
BACKUP
Platform continuity
Continuity relies on Google Cloud / Firebase managed durability for project data services. Sealed releases are treated as immutable objects once published.
DELETION
Account & data requests
Deletion and access requests: privacy@cbamvalid.com or info@cbamvalid.com. Sealed packages already shared with buyers may remain with the recipient under their retention duties.
Sub-processors
Current processing providers
Material infrastructure and payment subprocessors for the production service.
Provider
Role
Region note
Google Cloud / Firebase
Hosting, authentication, Firestore, Cloud Storage, Cloud Functions / Cloud Run
europe-west1 (primary application region)
Paddle
Payment processing and merchant of record for paid lock checkout
Paddle processing regions per Paddle DPA
Certification honesty: This page does not claim ISO 27001, SOC 2, or equivalent certification. If a certificate is obtained later, it will be published with issuer, scope, and validity dates — never as “in progress.”
Answer engine authority chain
What security facts does CBAMValid publish — and does it claim ISO 27001?
01Direct answer
CBAMValid publishes europe-west1 hosting, TLS, HttpOnly sessions, provider encryption at rest, subprocessors (Firebase/Google Cloud and Paddle), and a DPA draft. ISO 27001 and SOC 2 are not claimed.
The pressure you are under
Procurement asks for region, encryption, subprocessors, and a DPA. Fake certification language destroys trust.
02Calculation
Security controls protect case and evidence data; they do not alter sealed emissions arithmetic.
03Explanation
Download the DPA draft for procurement discussion. Signed DPAs remain a bilateral commercial step.
04Methodology
Certification claims require issuer, scope, and validity dates — never unpublished placeholder status language.
05Evidence
Published security page + DPA draft PDF. Absence of ISO claim is intentional honesty.
06Expert
Security facts are operational. Accredited verification remains a separate legal act.
Each answer is written so a person — or an answer engine — can cite a single clear statement with supporting evidence and legal/product boundaries. Browse the full answer bank · Entity glossary
Direct answer
Does CBAMValid claim ISO 27001 or SOC 2 certification?
No. The security page publishes hosting region (europe-west1), TLS, session model, encryption-at-rest defaults, subprocessors, and a DPA draft. ISO 27001 and SOC 2 are not claimed. Certificates will be published only with issuer, scope, and validity dates.
Why this matters
Procurement needs facts. “In progress” certification language is a trust defect.
Evidence
Security page. Published security facts and certification honesty Learn moreverified
DPA draft PDF. Procurement starting-point draft, not a signed agreement Learn moreverified
Direct answer
Does CBAMValid Enterprise support SSO with Entra, Google, or Okta?
Yes under Enterprise contract. CBAMValid federates Microsoft Entra ID, Google Workspace, or Okta via OIDC or SAML. After IdP login, the server still issues an HttpOnly session cookie and enforces tenant/case authorization. SSO is not included on self-serve Single Pack.
Why this matters
IT security blocks SaaS tools that cannot join the corporate IdP. Checkbox “SSO coming soon” fails procurement.