Enterprise GHG accounting platform

Every tonne.Accounted. Auditable.

The multi-tenant system of record for corporate carbon accounting, from field-level activity data to audit-ready disclosure across Scope 1, Scope 2 and Scope 3.

0 emission-factor domains, fuels through land use
0 greenhouse gases, calculated per gas then summed
0 decimal places, fixed point, never floating
0 categories, factors or formulas written into the code

The book opens in

Months
Days
Hours
Minutes
Seconds

LAUNCHING 10 JUNE 2027

IThe problem

Corporate carbon accounting still runs on spreadsheets

Multi-unit organizations manage regulated emissions data in disconnected workbooks, with no version control, no governed emission factors, and no audit trail. Regulators, investors and auditors have stopped accepting that.

47tabs

The master workbook

2.3 million cells attempting to consolidate 60 business units. Minutes to open. Crashes weekly. Version control is _v2_final_FINAL.xlsx, and the number that reaches the board came out of it.

4sources

Ungoverned factors

EPA, IEA, DEFRA and the API Compendium, at different vintages in every unit. Consolidated totals nobody can defend.

0audit trail

Custody by email

Who changed what, when and why lives in inbox archives. Verification surfaces it as a finding, every year.

3regimes

Deadlines at once

SEC climate rules, EU CSRD and CDP land together, with no workflow and no visibility of what is at risk.

1quarter

The hidden month

A 340% one-month diesel spike disappears inside a quarterly total. Nobody sees it until an auditor asks.

IIOne book

From fragmented spreadsheets to a single, audit-ready source of emissions truth.

  1. 01Activity data
  2. 02Governed calculation
  3. 03Workflow
  4. 04Audit trail
  5. 05Reporting

IIIThe platform

One system of record, business unit to boardroom

Activity data flows in from every site. Governed calculation turns it into defensible tCO₂e. Workflow, audit trail and reporting carry it all the way to the regulator.

Portfolio overview
SCOPE 1 145,231.45 tCO₂e ▼ 3.2%
SCOPE 2 32,847.10 tCO₂e, location based ▲ 1.8%
SCOPE 3 CAT 1 8,934.02 tCO₂e ▲ 5.4%
Scope breakdown 187k tCO₂e
S1 78% S2 17% S3 5%
Emissions by data month
Awaiting review
Refinery, Gulf CoastIN REVIEW5,847.33
Upstream, Permian3,120.88
Offshore, North SeaAPPROVED7,410.02
What it does
  • Versioned factor library

    EPA's Emission Factors Hub and eGRID, UK DESNZ, IPCC and the API Compendium ship as cited seed data you adopt and then own. Every factor is effective-dated, and versions chain append-only so history never changes underneath a filed report.

    Commercial catalogues stay licensed to you, never redistributed by us
  • Immutable snapshots

    Every calculation freezes what it used, the factor version, the GWP set, the unit conversions and the boundary approach, into a snapshot that is never rewritten. A recalculation supersedes; it does not overwrite.

    Supersede, never delete
  • Import that forgives

    One staged pipeline serves every configurable entity, from structure and users to factors, formulas and activity data. Templates carry your own vocabulary and regenerate themselves when it changes. Rows validate against exactly the rules the screens use.

    30-day rollback, and versioned entities land as drafts
  • Evidence where it belongs

    Whether a source needs a supporting document is a property of that source, inherited from its category and overridable per source. Required means required: the submission will not move without it.

    Optional, required or disabled, per source
  • A dashboard per job

    A completion grid for the person entering data, a review queue with variance already computed for the person approving it, portfolio status for the administrator, and an evidence-first view for the auditor.

    Four roles, four landing screens
  • Framework reporting

    GHG Protocol, ISO 14064-1, CDP, TCFD, GRI 305 and EPA GHGRP outputs, generated only from approved and locked data. Each mapping is versioned data, so a questionnaire changing next year is an update, not a release.

    Every report stamped so it can be reproduced exactly

IVCoverage

Scope 1, 2 and 3, on the same governed factors.

Each scope captured where it happens, and calculated on the same governed factors as everything else.

Keep scrolling

Scope 1, direct

Stationary and mobile combustion, flaring, venting, process and fugitive emissions.

Captured at equipment level through forms generated from the source's own parameter schema.

Per gas: CO₂, CH₄, N₂O and the F-gases

Sample portfolio figure0.00tCO₂e▼ 3.2% vs prior period

Scope 2, energy

Purchased electricity, steam, heat and cooling.

The location-based and market-based chains resolve independently and both are stored, because the GHG Protocol requires both and neither can be switched off.

Dual reporting, not optional

Sample portfolio figure, location based0.00tCO₂e▲ 1.8%

Scope 3, value chain

Purchased goods and services, transport, waste, business travel and the rest of the value chain.

By spend-based and activity-based method, on the same governed factors as everything else.

Spend-based and activity-based

Sample portfolio figure, Scope 3 Cat 10.00tCO₂e▲ 5.4%

VConfiguration

Configuration is the product

Nothing about your industry, your structure or your methodology is written into the software. That is only useful if setting it up does not take a consultant, so the first thing a new administrator sees is not an empty dashboard.

Your structure, your names

Hover a level to see what it rolls up into. Click Business Unit to rename it.

  1. TENANTOrganizationThe tenant itself, not a node in the tree. Its total is the sum of the roots.isolated
  2. RANK 10May nest inside itself, so a region containing countries containing sites is one level, not three.renameable
  3. RANK 20FacilityOptional. An organization without facilities archives the level rather than skipping it.optional
  4. RANK 30DepartmentOptional, and the ranks are gapped so a level of your own inserts between two existing ones.optional
  5. SOURCEEmission sourceAttaches to any level you allow it to, and rolls up through every level above it.rolls up

Those three level names are seed rows, not an enumeration in a database column. Rename Business Unit to Legal Entity and every screen, every generated import template and every report follows. Add a fifth level called Asset or Region and nothing migrates.

Setup, start to finish

  1. Organization
  2. Business units
  3. Facilities
  4. Departments
  5. Users
  6. Assignments
  7. Reporting structure
  8. Categories
  9. Sources
  10. Parameters
  11. Factors
  12. GWP version
  13. Review

Every step writes real configuration, validated by the same rules the admin screens use. Leave at step six and come back next week to step six.

VICustody

Six states. No ambiguity.

Every submission moves through one state machine, one submission per node per window, with each transition timestamped, attributed, and kept.

  1. 01 / 06

    Open

    A manager opens the period for a node. Until then there is no row, and nothing can be written.

  2. 02 / 06

    Draft

    The reporter enters data with a live tCO₂e preview and drafts that survive an interruption.

  3. 03 / 06

    Submitted

    Completeness is enforced. An incomplete inventory cannot be submitted.

  4. 04 / 06

    In review

    The reviewer sees anomaly flags, prior-period variance and the attached evidence. Rejected returns the submission to Draft with a documented reason, and the second review looks only at what changed. Nothing disappears.

  5. 05 / 06

    Approved

    Never by the author. Credentials are re-confirmed, and a flagged anomaly needs a written comment.

  6. 06 / 06

    Locked

    The period is finalized. Edits are refused by the service, not hidden by the interface.

Three gates, in order, on every write

GATE 1

Inside a reporting year

The data month has to fall within a reporting year somebody actually created. Data cannot arrive for a year that does not exist.

GATE 2

The month is not locked

The accounting freeze. A locked month stays closed until somebody reopens it for a documented reason, and finalizing a year cascades the locks.

MONTH_LOCKED
GATE 3

The period is open

The reporting cycle. Are we collecting for this window right now, or not? A month can be unlocked and still closed, which is the normal state between cycles.

PERIOD_NOT_OPEN

All three are checked in the service layer, never only in the interface. A node with nobody assigned to report on it cannot be opened at all, because a period that is open and unfillable helps no one.

VIIThe arithmetic

Calculation you can put in front of a regulator

Multi-gas, unit-safe, asynchronous, and frozen the moment it is computed.

  • All seven species, CO₂, CH₄, N₂O, HFCs, PFCs, SF₆ and NF₃, calculated per gas and then summed
  • Fixed-point decimal to six places. A float never touches an emissions figure, a factor or a GWP value
  • Units carry dimensions, so a factor in kg per litre cannot be applied to a reading in MMBtu without a bridge factor that says how
  • Methane stays reportable as methane, in tonnes of CH₄, for OGMP 2.0, alongside its CO₂e
  • A missing factor, a missing GWP or a unit mismatch blocks the calculation and says so. Nothing is zero-filled, averaged, or guessed
  • Before any bulk recalculation touches a closed year, an impact preview shows exactly what would move
Worked example

EtCO₂e = Σ ( AD × EFgas × GWPgas )

GasActivityEFGWPtCO₂e
CO₂10,000 MMBtu53.061530.600000
CH₄10,000 MMBtu0.001270.270000
N₂O10,000 MMBtu0.00012730.273000
Total531.143000
Snapshot frozen
AR6 GWP-100 · Operational control

EF in kg per MMBtu, so each line is divided by 1,000 to give tonnes. Six decimal places, fixed point.

How a factor is chosen

Three tiers, one fixed order, resolved against the data month. The first that matches wins, and the ones below it are never consulted.

Try it
  1. Tier 1An override on this sitestop if found
  2. Tier 2A factor you ownstop if found
  3. Tier 3The library you adoptedstop if found
  4. ElseStop and say what is missingnever a default

VIIIThe chain

Tamper-evident by construction

An append-only ledger where every entry is hash-chained to the one before it. Break a link and the integrity check tells you exactly where.

Integrity check: chain unbroken
#1245APPROVE
hash
9f2a…c41d
#1246CALCULATE
prev
9f2a…c41d
#1247LOCK
prev
71bd…08e2

Illustrative entries. In the product, the check runs over the whole trail.

  1. Submission approved by the regional manager, with the variance comment attached

  2. Calculation snapshot frozen against the factor version and GWP set in force for that data month

  3. Period locked. Reopening it needs a stated reason, and the reason is part of the record

  • Every create, update and workflow event is written, enforced in the database rather than trusted to the application
  • Full before and after state, the actor, their role, their address and a UTC timestamp on every entry
  • An evidence package for a verifier is one action, not a fortnight of document requests
  • Nothing in the trail can be updated or deleted by any code path, including ours

Reported figure to source document, in three steps

  1. Reported figure
  2. Snapshot
  3. Factor version
  4. Activity record
  5. Source document

IXFour roles

Four roles. One version of the truth.

Access is granted as a role at a point in your structure, and it covers everything beneath that point. The figures below are the design targets the product is built against, not results from customers we do not yet have.

  • 01

    Org Admin

    Head of GHG reporting

    Owns the structure, the people, the taxonomy, the factor library, the GWP set and the final sign-off. Runs the wizard, finalizes the year, and can export everything at any time without asking us.

    Design target< 1 dayorganization set up in under a day
  • 02

    Data Manager

    Regional sustainability

    Opens periods, curates sources and factors within their part of the tree, and reviews what comes back with anomaly flags and prior-period variance already computed. Cannot approve their own work.

    Design target45 mina flagged review in 45 minutes
  • 03

    Data Reporter

    Field operations

    The only role that can write activity data. Guided forms, automatic unit conversion, a live calculation preview, and drafts that survive a lost connection.

    Design target3 min3 minutes per source
  • 04

    Auditor

    External assurance

    Read-only across the whole organization, with the frozen snapshots, the workflow history and the hash chain. Self-service evidence packages, so the engagement stops being a document hunt.

    Design target3 clicksany figure traced in 3 clicks

XStandards

Built against the standards you are actually asked about

Report mappings and methodology follow the frameworks your regulators, investors and verifiers name. Each one is versioned data, so a questionnaire that changes for next year is an update rather than a release.

  • GHG ProtocolCorporate Standard
  • ISO 14064-12018
  • CDPClimate questionnaire
  • TCFDClimate disclosure
  • GRI 305Emissions
  • EPA GHGRP40 CFR Part 98
  • OGMP 2.0Methane reporting

Emission-factor coverage

  • FuelsScope 1
  • Energy carriersScope 1 / 3
  • Purchased electricityScope 2
  • Steam, heat, coolingScope 2
  • Transport and freightScope 1 / 3
  • WasteScope 3
  • WaterScope 3
  • Refrigerants and F-gasesScope 1
  • Industrial processesScope 1
  • Fugitives and flaringScope 1
  • AgricultureScope 1
  • Land useScope 1, net removals

XIIndustry packs

Your industry is configuration, not a version of the product

Every organization starts from the GHG Protocol's own category set. Anything sector-specific arrives on top of it as an installable pack of seed data: categories, parameters and factors that you can edit, extend or archive. None of it is vocabulary compiled into the software, so no sector is a second-class citizen and none of it needs us to ship a release.

  1. 01 / 04

    What a pack contains

    Pre-configured emission categories with their activity parameters, the emission factors that go with them, and the methodology references behind each one.

  2. 02 / 04

    How it installs

    As data, at any point in an organization's life, not only at setup. Installing twice changes nothing, and archiving it puts the taxonomy back where it was.

  3. 03 / 04

    What stays yours

    Everything a pack brings is editable the moment it lands. Rename it, change a factor, add a category the pack never thought of. It is a starting point, not a schema.

  4. 04 / 04

    If no pack fits

    Build the taxonomy yourself in the setup wizard, or import it. The baseline works unassisted, and a pack is a shortcut rather than a requirement.

XIIIsolation

Isolation is the product

No organization can reach another organization's data. That is not a configuration setting, and it is not enforced in one place where a single mistake would undo it.

Four independent layers
Row-level security in PostgreSQL, a request-context guard, tenant filtering at the data-access layer, and role-and-node authorization above that. The database layer fails closed, and the application connects as a restricted role that cannot bypass it.
Encryption and access
AES-256 at rest, TLS 1.3 in transit, multi-factor authentication for privileged roles, and enterprise single sign-on over OIDC or SAML.
Even we are audited
Platform operators provision and support organizations. They cannot read an organization's emissions data, and where cross-organization read access exists at all it is read-only and written to the same audit trail as everything else.
Formula sandbox
The calculation builder parses a closed grammar with a fixed function whitelist. There is no evaluation of arbitrary code anywhere near it, so a formula cannot become a way into the system.

XIIIWhat comes next

Where the book goes next

Published so you can hold us to it. If it is not on this list, nobody is quietly promising it to you in a sales call either.

  1. 2027

    Launch

    Scope 1 and 2 complete, Scope 3, the setup wizard, the calculation builder, universal import and export, and the framework report sets.

  2. 2028

    Assistance at the row

    AI working where the data is entered and reviewed, not in a separate chat window: flagging a reading that does not fit its own history, suggesting the parameter or factor a new source needs, drafting the variance explanation a reviewer would otherwise write by hand, and answering questions about an inventory in plain language. Every suggestion is attributable, refusable and recorded, because a figure a person did not choose is not a figure an auditor can accept.

  3. 2029

    The rest of HSE

    The same machinery extended past carbon to health, safety and environment reporting as a whole: incidents, water, waste, air quality and workforce safety, on the one structure, the one approval workflow and the one audit trail. One book for everything an operation has to report on.

XIVThe specification

The specification came first. All of it.

Order of work 000%

We did not design GHG Book by shipping screens and bending the data model around them afterwards. Every table, every endpoint, every audit invariant and every access boundary was specified, argued, and ratified, with the alternatives we rejected written down, before an interface existed. It is a slower way to start. It is also why an auditor will be able to trust what we build.

  • 0architecture decisions logged, each with the alternatives we rejected
  • 0specification documents ratified before the first screen was built
  • 0independent isolation layers, enforced at the database, not just the interface
  • 0emissions values held as floating point, anywhere in the system

∞Early access

Be first in the book

We are taking on a limited number of design partners ahead of the June 2027 launch. Early-access organizations shape the roadmap and lock in founding terms.

Your work address, e.g. you@company.com

NO NEWSLETTER, NO LIST SHARING, NO SPAM