Skip to main content
CBAM definitive period is now in force. 2026 annual declarations are due — prepare your evidence dossier early.Trust registry →See the ruleset →
CBAMValidCarbon Border Compliance Validation
ProductHow It WorksSamplePricingVerify
Sign InStart a Dossier
ProductHow It WorksSamplePricingVerifyPublished RulesetsMethodology & SourcesStructure ReviewTrust RegistrySecurity & DPABuyer Share LinkAnswer BankEnterprise ExclusivePartnersBook a DemoSign InStart a Dossier
Trust & security

Security & data protection
facts only

Hosting region, encryption, backups, deletion, and subprocessors — published without unverified certification claims. ISO 27001 / SOC 2 are not claimed here.

Download DPA draft (PDF)Download SLA draft (PDF)Enterprise ExclusivePrivacy policy
HOSTING

Primary region

Application runtime and Firebase project services are configured for europe-west1 (EU).

IN TRANSIT

TLS

Public endpoints are served over HTTPS/TLS. Session cookies are HttpOnly.

AT REST

Provider encryption

Firestore and Cloud Storage data use Google Cloud encryption at rest under the Firebase/Google Cloud platform defaults.

AUTH

Session model

Firebase ID token → server createSessionCookie() → HttpOnly __session → server verification. Tenant and case ownership are enforced server-side.

BACKUP

Platform continuity

Continuity relies on Google Cloud / Firebase managed durability for project data services. Sealed releases are treated as immutable objects once published.

DELETION

Account & data requests

Deletion and access requests: privacy@cbamvalid.com or info@cbamvalid.com. Sealed packages already shared with buyers may remain with the recipient under their retention duties.

Sub-processors

Current processing providers

Material infrastructure and payment subprocessors for the production service.

ProviderRoleRegion note
Google Cloud / FirebaseHosting, authentication, Firestore, Cloud Storage, Cloud Functions / Cloud Runeurope-west1 (primary application region)
PaddlePayment processing and merchant of record for paid lock checkoutPaddle processing regions per Paddle DPA
Certification honesty: This page does not claim ISO 27001, SOC 2, or equivalent certification. If a certificate is obtained later, it will be published with issuer, scope, and validity dates — never as “in progress.”
  1. Home/
  2. Security & data protection — facts only
Answer engine authority chain

What security facts does CBAMValid publish — and does it claim ISO 27001?

01Direct answer

CBAMValid publishes europe-west1 hosting, TLS, HttpOnly sessions, provider encryption at rest, subprocessors (Firebase/Google Cloud and Paddle), and a DPA draft. ISO 27001 and SOC 2 are not claimed.

The pressure you are under

Procurement asks for region, encryption, subprocessors, and a DPA. Fake certification language destroys trust.

  1. 02Calculation

    Security controls protect case and evidence data; they do not alter sealed emissions arithmetic.

  2. 03Explanation

    Download the DPA draft for procurement discussion. Signed DPAs remain a bilateral commercial step.

  3. 04Methodology

    Certification claims require issuer, scope, and validity dates — never unpublished placeholder status language.

  4. 05Evidence

    Published security page + DPA draft PDF. Absence of ISO claim is intentional honesty.

  5. 06Expert

    Security facts are operational. Accredited verification remains a separate legal act.

Related problems

  • Privacy noticeData handling
  • Trust registryPinned claims
  • Contact privacyRequests
  • Buyer share linkPublic token path
Defined entities
  • europe-west1
  • DPA draft
  • subprocessors
  • no ISO 27001 claim
Answer + Evidence

Security answers

Each answer is written so a person — or an answer engine — can cite a single clear statement with supporting evidence and legal/product boundaries. Browse the full answer bank · Entity glossary

Direct answer

Does CBAMValid claim ISO 27001 or SOC 2 certification?

No. The security page publishes hosting region (europe-west1), TLS, session model, encryption-at-rest defaults, subprocessors, and a DPA draft. ISO 27001 and SOC 2 are not claimed. Certificates will be published only with issuer, scope, and validity dates.

Why this matters

Procurement needs facts. “In progress” certification language is a trust defect.

Evidence

  • Security page. Published security facts and certification honesty Learn moreverified
  • DPA draft PDF. Procurement starting-point draft, not a signed agreement Learn moreverified

Direct answer

Does CBAMValid Enterprise support SSO with Entra, Google, or Okta?

Yes under Enterprise contract. CBAMValid federates Microsoft Entra ID, Google Workspace, or Okta via OIDC or SAML. After IdP login, the server still issues an HttpOnly session cookie and enforces tenant/case authorization. SSO is not included on self-serve Single Pack.

Why this matters

IT security blocks SaaS tools that cannot join the corporate IdP. Checkbox “SSO coming soon” fails procurement.

Evidence

  • Enterprise SSO page. Protocols, IdP examples, and provisioning steps Learn moreverified
  • Security session model. Server-verified HttpOnly __session remains authoritative Learn moreverified
Query fan-out

Questions this page is built to absorb

These follow-ups map topic → entity → internal link so answer engines can cite one clear page instead of stitching fragmented claims.

  • CBAMValid security
  • CBAMValid DPA
  • CBAMValid ISO 27001
Topical map

Continue in this topic cluster

Related pages that answer follow-up questions without repeating the same claim.

  • HomeCBAM exporter verification preparation
  • PrivacyPrivacy
  • Buyer share linkBuyer share link /d/token
  • Legal noticeLegal notice
  • Trust Evidence RegistryTrust evidence registry

Last content review 2026-07-26 · Ruleset claims use pinned EU instruments — not inventing deadlines.

CBAMValidCarbon Border Compliance Validation

Independent software for CBAM verification preparation — sealed, evidence-linked dossiers for exporters and EU buyers.

EU hostedGDPRTLS
info@cbamvalid.comDublin · Republic of Ireland

Product

  • Product
  • How It Works
  • Sample Dossier
  • Methodology & Sources
  • Pricing
  • Verify a Dossier
  • Book a Demo

Enterprise

  • Enterprise Exclusive
  • Structure Review
  • Published Rulesets
  • Buyer Share Link
  • Platform Architecture
  • Partners
  • Trust Registry

Guides

  • Answer Bank
  • CBAM Glossary
  • 2026 Definitive Period
  • Verification Preparation
  • Non-EU Producer Guide
  • Embedded Emissions
  • CN Code Scope Hub

Company

  • About
  • Contact
  • Security & DPA
  • Case Studies
  • Privacy
  • Terms
  • Legal Notice
PrivacyTermsCookiesRefundsSecurityLegal notice

© 2026 SectorCalc Corporation (CBAMValid). All rights reserved.

SectorCalc Corporation (CBAMValid)

4th Floor, One Burlington Plaza, Burlington Road, Dublin 4, Ireland · Ireland

Company Registration No: 315881

VAT ID: IE1857162AB

Data protection contact: Siobhan O'Connor, Data Protection Officer <info@cbamvalid.com> · privacy@cbamvalid.com

Support: +353 (0)1 676 2671 · info@cbamvalid.com

Independence Notice: CBAMValid is an independent software service for exporter-to-importer evidence packaging. It is not an EU institution, customs authority or accredited CBAM verifier. Actual emissions data must be independently verified where verification is legally required.