Enterprise GHG accounting platform

Every tonne.
Accounted. Auditable.

The multi-tenant system of record for corporate carbon accounting, from field-level activity data to audit-ready disclosure across Scope 1, Scope 2 and Scope 3.

0 emission-factor domains, fuels through land use
0 greenhouse gases, calculated per gas then summed
0 decimal places, fixed point, never floating
0 categories, factors or formulas written into the code

The book opens in

Months
Days
Hours
Minutes
Seconds

LAUNCHING 10 JUNE 2027

Corporate carbon accounting still runs on spreadsheets

Multi-unit organizations manage regulated emissions data in disconnected workbooks, with no version control, no governed emission factors, and no audit trail. Regulators, investors and auditors have stopped accepting that.

47tabs

The master workbook

2.3 million cells attempting to consolidate 60 business units. Minutes to open. Crashes weekly. Version control is _v2_final_FINAL.xlsx, and the number that reaches the board came out of it.

4sources

Ungoverned factors

EPA, IEA, DEFRA and the API Compendium, at different vintages in every unit. Consolidated totals nobody can defend.

0audit trail

Custody by email

Who changed what, when and why lives in inbox archives. Verification surfaces it as a finding, every year.

3regimes

Deadlines at once

SEC climate rules, EU CSRD and CDP land together, with no workflow and no visibility of what is at risk.

1quarter

The hidden month

A 340% one-month diesel spike disappears inside a quarterly total. Nobody sees it until an auditor asks.

One system of record, business unit to boardroom

Activity data flows in from every site. Governed calculation turns it into defensible tCO₂e. Workflow, audit trail and reporting carry it all the way to the regulator.

Portfolio overview
SCOPE 1 145,231.45 tCO₂e ▼ 3.2%
SCOPE 2 32,847.10 tCO₂e, location based ▲ 1.8%
SCOPE 3 CAT 1 8,934.02 tCO₂e ▲ 5.4%
Scope breakdown 187k tCO₂e
S1 78% S2 17% S3 5%
Emissions by data month
Awaiting review
Refinery, Gulf CoastIN REVIEW5,847.33
Upstream, Permian3,120.88
Offshore, North SeaAPPROVED7,410.02

Scope 1, direct

Stationary and mobile combustion, flaring, venting, process and fugitive emissions, captured at equipment level through forms generated from the source's own parameter schema.

Per gas: CO₂, CH₄, N₂O and the F-gases

Scope 2, energy

Purchased electricity, steam, heat and cooling. The location-based and market-based chains resolve independently and both are stored, because the GHG Protocol requires both and neither can be switched off.

Dual reporting, not optional

Scope 3, value chain

Purchased goods and services, transport, waste, business travel and the rest of the value chain, by spend-based and activity-based method, on the same governed factors as everything else.

Spend-based and activity-based

What it does

Versioned factor library

EPA's Emission Factors Hub and eGRID, UK DESNZ, IPCC and the API Compendium ship as cited seed data you adopt and then own. Every factor is effective-dated, and versions chain append-only so history never changes underneath a filed report.

Commercial catalogues stay licensed to you, never redistributed by us

Immutable snapshots

Every calculation freezes what it used, the factor version, the GWP set, the unit conversions and the boundary approach, into a snapshot that is never rewritten. A recalculation supersedes; it does not overwrite.

Supersede, never delete

Import that forgives

One staged pipeline serves every configurable entity, from structure and users to factors, formulas and activity data. Templates carry your own vocabulary and regenerate themselves when it changes. Rows validate against exactly the rules the screens use.

30-day rollback, and versioned entities land as drafts

Evidence where it belongs

Whether a source needs a supporting document is a property of that source, inherited from its category and overridable per source. Required means required: the submission will not move without it.

Optional, required or disabled, per source

A dashboard per job

A completion grid for the person entering data, a review queue with variance already computed for the person approving it, portfolio status for the administrator, and an evidence-first view for the auditor.

Four roles, four landing screens

Framework reporting

GHG Protocol, ISO 14064-1, CDP, TCFD, GRI 305 and EPA GHGRP outputs, generated only from approved and locked data. Each mapping is versioned data, so a questionnaire changing next year is an update, not a release.

Every report stamped so it can be reproduced exactly

Configuration is the product

Nothing about your industry, your structure or your methodology is written into the software. That is only useful if setting it up does not take a consultant, so the first thing a new administrator sees is not an empty dashboard.

Your structure, your names
TENANT OrganizationThe tenant itself, not a node in the tree. Its total is the sum of the roots. isolated
RANK 10 Business UnitMay nest inside itself, so a region containing countries containing sites is one level, not three. renameable
RANK 20 FacilityOptional. An organization without facilities archives the level rather than skipping it. optional
RANK 30 DepartmentOptional, and the ranks are gapped so a level of your own inserts between two existing ones. optional
SOURCE Emission sourceAttaches to any level you allow it to, and rolls up through every level above it. rolls up

Those three level names are seed rows, not an enumeration in a database column. Rename Business Unit to Legal Entity and every screen, every generated import template and every report follows. Add a fifth level called Asset or Region and nothing migrates.

Setup, start to finish
  1. 01Organization
  2. 02Business units
  3. 03Facilities
  4. 04Departments
  5. 05Users
  6. 06Assignments
  7. 07Reporting structure
  8. 08Categories
  9. 09Sources
  10. 10Parameters
  11. 11Factors
  12. 12GWP version
  13. 13Review

Every step writes real configuration, validated by the same rules the admin screens use. Leave at step six and come back next week to step six.

Parameters, once

Creating a source proposes the parameters it needs. Where one already exists that means the same thing, the system says so and offers it, instead of quietly creating a fourth field called Fuel Volume. Parameters version, and each record pins the version it was captured under.

Formulas without engineers

Build a calculation from parameters, factors, GWP values, constants and named variables in a visual editor. It parses against a closed grammar, the unit dimensions have to reduce to mass of CO₂e, and activating it runs its stored test cases and an impact preview first.

Six states. No ambiguity.

Every submission moves through one state machine, one submission per node per window, with each transition timestamped, attributed, and kept.

OpenA manager opens the period for a node. Until then there is no row, and nothing can be written.
DraftThe reporter enters data with a live tCO₂e preview and drafts that survive an interruption.
SubmittedCompleteness is enforced. An incomplete inventory cannot be submitted.
In reviewThe reviewer sees anomaly flags, prior-period variance and the attached evidence.
ApprovedNever by the author. Credentials are re-confirmed, and a flagged anomaly needs a written comment.
Locked The period is finalized. Edits are refused by the service, not hidden by the interface.

Rejected returns the submission to Draft with a documented reason, and the second review looks only at what changed. Nothing disappears.

Three gates, in order, on every write
GATE 1

Inside a reporting year

The data month has to fall within a reporting year somebody actually created. Data cannot arrive for a year that does not exist.

GATE 2

The month is not locked

The accounting freeze. A locked month stays closed until somebody reopens it for a documented reason, and finalizing a year cascades the locks.

MONTH_LOCKED
GATE 3

The period is open

The reporting cycle. Are we collecting for this window right now, or not? A month can be unlocked and still closed, which is the normal state between cycles.

PERIOD_NOT_OPEN

All three are checked in the service layer, never only in the interface. A node with nobody assigned to report on it cannot be opened at all, because a period that is open and unfillable helps no one.

Calculation you can put in front of a regulator

Multi-gas, unit-safe, asynchronous, and frozen the moment it is computed.

  • All seven species, CO₂, CH₄, N₂O, HFCs, PFCs, SF₆ and NF₃, calculated per gas and then summed
  • Fixed-point decimal to six places. A float never touches an emissions figure, a factor or a GWP value
  • Units carry dimensions, so a factor in kg per litre cannot be applied to a reading in MMBtu without a bridge factor that says how
  • Methane stays reportable as methane, in tonnes of CH₄, for OGMP 2.0, alongside its CO₂e
  • A missing factor, a missing GWP or a unit mismatch blocks the calculation and says so. Nothing is zero-filled, averaged, or guessed
  • Before any bulk recalculation touches a closed year, an impact preview shows exactly what would move

EtCO₂e = Σ ( AD × EFgas × GWPgas )

GASACTIVITYEFGWPtCO₂e
CO₂10,000 MMBtu53.061530.60
CH₄10,000 MMBtu0.001270.28
N₂O10,000 MMBtu0.00012730.27
TOTAL531.15
SNAPSHOT FROZEN, AR6 GWP-100, OPERATIONAL CONTROL
How a factor is chosen

Three tiers, one fixed order, resolved against the data month. The first that matches wins, and the ones below it are never consulted.

Tier 1 An override on this site stop if found
Tier 2 A factor you own stop if found
Tier 3 The library you adopted stop if found
Else Stop and say what is missing never a default

Tamper-evident by construction

An append-only ledger where every entry is hash-chained to the one before it. Break a link and the integrity check tells you exactly where.

  • Every create, update and workflow event is written, enforced in the database rather than trusted to the application
  • Full before and after state, the actor, their role, their address and a UTC timestamp on every entry
  • Reported figure to snapshot to factor version to activity record to source document, in three steps
  • An evidence package for a verifier is one action, not a fortnight of document requests
  • Nothing in the trail can be updated or deleted by any code path, including ours
09:15 UTC

Submission approved by the regional manager, with the variance comment attached

09:16 UTC

Calculation snapshot frozen against the factor version and GWP set in force for that data month

23:59 UTC

Period locked. Reopening it needs a stated reason, and the reason is part of the record

Four roles. One version of the truth.

Access is granted as a role at a point in your structure, and it covers everything beneath that point. The figures below are the design targets the product is built against, not results from customers we do not yet have.

Org Admin

Head of GHG reporting

Owns the structure, the people, the taxonomy, the factor library, the GWP set and the final sign-off. Runs the wizard, finalizes the year, and can export everything at any time without asking us.

Design target: organization set up in under a day

Data Manager

Regional sustainability

Opens periods, curates sources and factors within their part of the tree, and reviews what comes back with anomaly flags and prior-period variance already computed. Cannot approve their own work.

Design target: a flagged review in 45 minutes

Data Reporter

Field operations

The only role that can write activity data. Guided forms, automatic unit conversion, a live calculation preview, and drafts that survive a lost connection.

Design target: 3 minutes per source

Auditor

External assurance

Read-only across the whole organization, with the frozen snapshots, the workflow history and the hash chain. Self-service evidence packages, so the engagement stops being a document hunt.

Design target: any figure traced in 3 clicks

Built against the standards you are actually asked about

Report mappings and methodology follow the frameworks your regulators, investors and verifiers name. Each one is versioned data, so a questionnaire that changes for next year is an update rather than a release.

GHG ProtocolCorporate Standard ISO 14064-12018 CDPClimate questionnaire TCFDClimate disclosure GRI 305Emissions EPA GHGRP40 CFR Part 98 OGMP 2.0Methane reporting
Emission-factor coverage
01FuelsScope 1
02Energy carriersScope 1 / 3
03Purchased electricityScope 2
04Steam, heat, coolingScope 2
05Transport and freightScope 1 / 3
06WasteScope 3
07WaterScope 3
08Refrigerants and F-gasesScope 1
09Industrial processesScope 1
10Fugitives and flaringScope 1
11AgricultureScope 1
12Land useScope 1, net removals

Your industry is configuration, not a version of the product

Every organization starts from the GHG Protocol's own category set. Anything sector-specific arrives on top of it as an installable pack of seed data: categories, parameters and factors that you can edit, extend or archive. None of it is vocabulary compiled into the software, so no sector is a second-class citizen and none of it needs us to ship a release.

What a pack contains

Pre-configured emission categories with their activity parameters, the emission factors that go with them, and the methodology references behind each one.

How it installs

As data, at any point in an organization's life, not only at setup. Installing twice changes nothing, and archiving it puts the taxonomy back where it was.

What stays yours

Everything a pack brings is editable the moment it lands. Rename it, change a factor, add a category the pack never thought of. It is a starting point, not a schema.

If no pack fits

Build the taxonomy yourself in the setup wizard, or import it. The baseline works unassisted, and a pack is a shortcut rather than a requirement.

Isolation is the product

No organization can reach another organization's data. That is not a configuration setting, and it is not enforced in one place where a single mistake would undo it.

Four independent layers

Row-level security in PostgreSQL, a request-context guard, tenant filtering at the data-access layer, and role-and-node authorization above that. The database layer fails closed, and the application connects as a restricted role that cannot bypass it.

Encryption and access

AES-256 at rest, TLS 1.3 in transit, multi-factor authentication for privileged roles, and enterprise single sign-on over OIDC or SAML.

Even we are audited

Platform operators provision and support organizations. They cannot read an organization's emissions data, and where cross-organization read access exists at all it is read-only and written to the same audit trail as everything else.

Formula sandbox

The calculation builder parses a closed grammar with a fixed function whitelist. There is no evaluation of arbitrary code anywhere near it, so a formula cannot become a way into the system.

Where the book goes next

Published so you can hold us to it. If it is not on this list, nobody is quietly promising it to you in a sales call either.

2027

Launch

Scope 1 and 2 complete, Scope 3, the setup wizard, the calculation builder, universal import and export, and the framework report sets.

2028

Assistance at the row

AI working where the data is entered and reviewed, not in a separate chat window: flagging a reading that does not fit its own history, suggesting the parameter or factor a new source needs, drafting the variance explanation a reviewer would otherwise write by hand, and answering questions about an inventory in plain language. Every suggestion is attributable, refusable and recorded, because a figure a person did not choose is not a figure an auditor can accept.

2029

The rest of HSE

The same machinery extended past carbon to health, safety and environment reporting as a whole: incidents, water, waste, air quality and workforce safety, on the one structure, the one approval workflow and the one audit trail. One book for everything an operation has to report on.

The specification came first. All of it.

We did not design GHG Book by shipping screens and bending the data model around them afterwards. Every table, every endpoint, every audit invariant and every access boundary was specified, argued, and ratified, with the alternatives we rejected written down, before an interface existed. It is a slower way to start. It is also why an auditor will be able to trust what we build.

0 architecture decisions logged, each with the alternatives we rejected
0 specification documents ratified before the first screen was built
0 independent isolation layers, enforced at the database, not just the interface
0 emissions values held as floating point, anywhere in the system

Be first in the book

We are taking on a limited number of design partners ahead of the June 2027 launch. Early-access organizations shape the roadmap and lock in founding terms.

Your work address, e.g. you@company.com

NO NEWSLETTER, NO LIST SHARING, NO SPAM