Security

Your emissions data is business data. We treat it that way.

Energy use, sites, suppliers and costs say a lot about a business. Here is how Ayika keeps that data safe, where it lives, and where we are on compliance.

Compliance

We're working towards SOC 2, starting with a Type I report. If your procurement team needs something before then, we'll answer your security questionnaire directly.

FrameworkStatusNotes
SOC 2In progressType I first, then Type II.
Data hostingIn placeMicrosoft Azure, Australia East.
Azure Managed ApplicationAvailableDeploy Ayika into your own Azure tenant.
Microsoft MarketplaceComing soonBuy and deploy through your Microsoft account.
Emission factorsIn placeAustralian National Greenhouse Accounts Factors, by edition and date.

Where your data lives

Ayika runs on Microsoft Azure. Your data, including the database, uploaded files and backups, is stored in Australia.

  • Australia East region for the application, database and file storage.
  • Backups stay in Australia, with automated daily database backups.
  • Backed by Microsoft for Startups, running on the same Azure infrastructure large Australian enterprises use.

How it's protected

  • Encrypted in transit with TLS on every connection.
  • Encrypted at rest for the database and every stored file.
  • Separated by organisation. Every query is scoped to the signed-in user's organisation, and automated tests run on every change to prove one customer can't read another's data.
  • Secrets kept out of code, held in Azure Key Vault rather than in the application.

Deployment options

Choose where Ayika runs. Both options are the same product with the same features.

  • Ayika Cloud. Fully managed by us on Microsoft Azure in Australia East. Nothing to install or maintain.
  • Your own Azure tenant. Deployed into your Azure subscription as an Azure Managed Application. Your data stays in your tenant, under your network, identity and retention policies, and we manage updates.
  • Microsoft Marketplace, coming soon. Buy and deploy Ayika through your existing Microsoft account.

Who can see it

  • Microsoft Entra ID sign-in. Your people sign in with their work Microsoft account, so your MFA, passkeys and conditional access policies apply.
  • Invite-only. An admin in your organisation decides who joins.
  • Admin and member roles separate who can configure your organisation from who can enter and correct data.

Evidence and audit trail

An emissions figure is only as good as the paper trail behind it, so Ayika keeps both.

  • Source files kept first. Every upload is stored before anything reads it, and the original row stays attached to each activity.
  • Every change logged. Corrections are written to an audit log with who made them and when.
  • Nothing silently dropped. Rows that fail validation stay visible with a reason, and every total shows how many records it leaves out.

Calculation methodology

Scopes follow the GHG Protocol. Factors come from the Australian National Greenhouse Accounts Factors, applying the edition that matches each activity's date. Scope 2 electricity uses the location-based method, priced against the state grid the electricity was drawn from. Factor values are never edited by hand, and every figure shows the factor and edition used.

Reporting a vulnerability

If you think you've found a security issue, email [email protected] with "Security report" in the subject. We'll acknowledge it within two business days. Please don't access other customers' data or disrupt the service while testing. Our security.txt has the same details.