Is this your company? Buyers are checking Greenly here. Claim greenly.earth free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Greenly
Trust level
Listed
Unverified
Listed
Domain
Report
Live
Sourced from public information. Not yet verified by the company.
Greenly is SOC 2 Type II compliant. Greenly also holds ISO 27001, and GDPR.
Compliance & infrastructure
Hosting
AWSGCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information
Documents
7Subprocessors
17- GGoogle Cloud Platform (GCP) · Cloud providerEurope (Europe west 9 - France)
- AAuth0 · Identity providerEurope (Multi-zone)
- DDatadog · Cloud monitoringEurope
- WWiz · SecurityEurope
- AAmazon Web Services · Cloud providerEurope (France)
- HHeroku · Cloud providerEurope (Ireland)
- KKandji / IRU · ITEurope
- MMongoDB Atlas · Data storage and processingEurope (France)
- HHubSpot · MarketingEurope (Multi-zone)
- CCustomer.io · MarketingEurope (Multi-zone)
- GGoogle Workspace · File storageEurope (Multi-zone)
- LLuzmo / Cumul.io · Data analyticsEurope (Germany)
Show all 17 subprocessorsShow fewer
- VVercel · EngineeringEurope
- IIntercom · Customer supportEurope
- OOkta · Identity providerEurope
- SSlack · Collaboration
- 11Password · Password management
Compliance leadership
The person who leads Greenly's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Greenly's penetration test vendor isn't listed yet.
Claim this profile to add it.
This listing is partial
6/11 details · 55%SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- DescriptionAdd a one-line description so buyers recognize you.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Greenly SOC 2 compliant?
Greenly is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Greenly ISO 27001 certified?
According to Greenly's public trust center, Greenly is ISO 27001 certified. On SOC2C this listing is Listed.
Is Greenly GDPR compliant?
According to Greenly's public trust center, Greenly is GDPR compliant. On SOC2C this listing is Listed.
Is Greenly SOC 2 Type I or Type II?
Greenly is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Greenly's SOC 2 for a vendor risk assessment?
Yes. Greenly's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Greenly penetration tested?
Greenly hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Does Greenly offer a Data Processing Agreement (DPA)?
Greenly publishes a DPA on its trust center; you can request access through SOC2C.
Does Greenly have an ISO 27001 certificate?
Greenly publishes an ISO certificate on its trust center; you can request access through SOC2C.
Can I get Greenly's SOC 2 report?
Greenly's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Greenly secure?
Security isn't a single yes/no, but Greenly is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Greenly have a bug bounty or vulnerability disclosure program?
Greenly hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@greenly.earth or via a /security page.
Who are Greenly's subprocessors?
Greenly lists 17 subprocessors on its trust center, including Google Cloud Platform (GCP), Auth0, Datadog, Wiz, Amazon Web Services. Buyers use this for fourth-party risk review.
Where does Greenly host or store data?
Greenly hosts on AWS, GCP, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Does Greenly offer a Data Processing Agreement (DPA)?
Greenly publishes a DPA on its trust center. You can request access through SOC2C.
Where is Greenly's trust center or security page?
Greenly's trust center is at https://trust.greenly.earth. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What actions has Greenly taken for data security? What is the Security Policy of the company?
Personal data is processed exclusively by Offspend, hosted by Amazon Web Service within the EU. We implement technical and organisational security measures to ensure the confidentiality, integrity and availability of your personal data. In addition, we are regularly audited by security specialists. To improve the security of our customers' data, Greenly has established a processing register listing all of our subcontractors. You can access our security policy by clicking on this link. Furthermore, Greenly has been SOC 2 Type 2 and ISO 27001 certified since 2023, demonstrating our commitment to data security and compliance with the highest industry standards. The trust of many customers, such as BNP Paribas, Arkea, Payfit, Ubisoft, RCI, etc., attests to our security policy, as these customers have audited our security systems. We have also been audited by the CNIL, who concluded that all our practices were compliant - something that is rarely noted. We're also happy to sign a confidentiality agreement (NDA) at your convenience.
What enterprise data do you collect?
The main function of the SAAS is to allow the realisation of the carbon footprint and the GHG report. This is done by carrying out various analyses. Data collection is made up of several main components : - The collection of the accounting entries file or accounting data for the extraction of expenses. - The collection of information via specific modules for physical analysis. - The collection of data from the company's employees for the calculation of commuting emissions. Greenly manually or automatically collects information on the client's company activity in order to produce a relevant carbon footprint measurement. Company data collected : - Expense data collected via accounting transactions - General company information (number of employees, revenue, region of activity, sector) - Data related to the company's buildings - Data related to the company's energy consumption - Data related to the consumption of equipment used indirectly by the company (data centers, networks etc.) - Any other data that allows us to characterise or refine the understanding of an internal process of the company (construction, manufacturing, marketing, distribution) - The quantity and quality of materials used in the construction of the company's products - The characteristics of the equipment used for the company's activity Information to characterise the company's internal logistic chains (in order to calculate the intermediate impacts) - Any other relevant information in pursuit of the objective of refining the accuracy of the carbon footprint calculation Action plans implemented in the company as part of the carbon footprint reduction project - The transportation data of the company's employees, as well as the meals habits of the employees.
What data do you collect about employees?
The main function of the SAAS is to allow the realisation of the carbon footprint and the GHG report. This is done by conducting a questionnaire on employee habits. - Identification data: e-mail address, residence - Transportation data: transportation means the method of work related travel and distance To the extent such information directly or indirect allows one to identify a natural person (e.g., Customer employees): - Meal habits: number of vegan and meat meals per week - Work location habits: Remote, co-working, or working sites
What kind of events are logged/audited?
- Log In / Log Off - Failed login attemps - Session Creation / Session Termination - Password Change - All Administrative actions and configuration changes performed - User Create / Read / Update / Delete actions, Document or Object Create / Read / Update - Delete actions - Metadata Create / Read / Update / Delete actions - Identifying users and the actions they performed - Integration logs: API call successes and failures - Infrastructure logs Hypervisor / OS - Database Log+Transaction Logs - Source IP address of the actor
Business & Industrial peers that completed SOC 2

Newsworthy.ai
newsworthy.ai · United States · Business & Industrial
SOC 2 Type IIRenewal not public

Octopus Deploy
octopus.com · United Kingdom · Business & Industrial
SOC 2 Type IIRenewal not public

1099-Prep
1099-prep.com · United States · Business & Industrial
SOC 2 Type IRenewal not public

Ask Ai
ask-ai.com · Business & Industrial
SOC 2 Type IIRenewal not public