SOC2C

Is this your company? Buyers are checking Greenly here. Claim greenly.earth free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Greenly logo

Greenly

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Greenly is SOC 2 Type II compliant. Greenly also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

7

Subprocessors

17
  • G
    Google Cloud Platform (GCP) · Cloud provider
    Europe (Europe west 9 - France)
  • A
    Auth0 · Identity provider
    Europe (Multi-zone)
  • D
    Datadog · Cloud monitoring
    Europe
  • W
    Wiz · Security
    Europe
  • A
    Amazon Web Services · Cloud provider
    Europe (France)
  • H
    Heroku · Cloud provider
    Europe (Ireland)
  • K
    Kandji / IRU · IT
    Europe
  • M
    MongoDB Atlas · Data storage and processing
    Europe (France)
  • H
    HubSpot · Marketing
    Europe (Multi-zone)
  • C
    Customer.io · Marketing
    Europe (Multi-zone)
  • G
    Google Workspace · File storage
    Europe (Multi-zone)
  • L
    Luzmo / Cumul.io · Data analytics
    Europe (Germany)
Show all 17 subprocessors
  • V
    Vercel · Engineering
    Europe
  • I
    Intercom · Customer support
    Europe
  • O
    Okta · Identity provider
    Europe
  • S
    Slack · Collaboration
  • 1
    1Password · Password management

Compliance leadership

The person who leads Greenly's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Greenly's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Description
    Add a one-line description so buyers recognize you.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Greenly SOC 2 compliant?
Greenly is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Greenly ISO 27001 certified?
According to Greenly's public trust center, Greenly is ISO 27001 certified. On SOC2C this listing is Listed.
Is Greenly GDPR compliant?
According to Greenly's public trust center, Greenly is GDPR compliant. On SOC2C this listing is Listed.
Is Greenly SOC 2 Type I or Type II?
Greenly is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Greenly's SOC 2 for a vendor risk assessment?
Yes. Greenly's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Greenly

Reproduced from Greenly's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What actions has Greenly taken for data security? What is the Security Policy of the company?
Personal data is processed exclusively by Offspend, hosted by Amazon Web Service within the EU. We implement technical and organisational security measures to ensure the confidentiality, integrity and availability of your personal data. In addition, we are regularly audited by security specialists. To improve the security of our customers' data, Greenly has established a processing register listing all of our subcontractors. You can access our security policy by clicking on this link. Furthermore, Greenly has been SOC 2 Type 2 and ISO 27001 certified since 2023, demonstrating our commitment to data security and compliance with the highest industry standards. The trust of many customers, such as BNP Paribas, Arkea, Payfit, Ubisoft, RCI, etc., attests to our security policy, as these customers have audited our security systems. We have also been audited by the CNIL, who concluded that all our practices were compliant - something that is rarely noted. We're also happy to sign a confidentiality agreement (NDA) at your convenience.
What enterprise data do you collect?
The main function of the SAAS is to allow the realisation of the carbon footprint and the GHG report. This is done by carrying out various analyses. Data collection is made up of several main components : - The collection of the accounting entries file or accounting data for the extraction of expenses. - The collection of information via specific modules for physical analysis. - The collection of data from the company's employees for the calculation of commuting emissions. Greenly manually or automatically collects information on the client's company activity in order to produce a relevant carbon footprint measurement. Company data collected : - Expense data collected via accounting transactions - General company information (number of employees, revenue, region of activity, sector) - Data related to the company's buildings - Data related to the company's energy consumption - Data related to the consumption of equipment used indirectly by the company (data centers, networks etc.) - Any other data that allows us to characterise or refine the understanding of an internal process of the company (construction, manufacturing, marketing, distribution) - The quantity and quality of materials used in the construction of the company's products - The characteristics of the equipment used for the company's activity Information to characterise the company's internal logistic chains (in order to calculate the intermediate impacts) - Any other relevant information in pursuit of the objective of refining the accuracy of the carbon footprint calculation Action plans implemented in the company as part of the carbon footprint reduction project - The transportation data of the company's employees, as well as the meals habits of the employees.
What data do you collect about employees?
The main function of the SAAS is to allow the realisation of the carbon footprint and the GHG report. This is done by conducting a questionnaire on employee habits. - Identification data: e-mail address, residence - Transportation data: transportation means the method of work related travel and distance To the extent such information directly or indirect allows one to identify a natural person (e.g., Customer employees): - Meal habits: number of vegan and meat meals per week - Work location habits: Remote, co-working, or working sites
What kind of events are logged/audited?
- Log In / Log Off - Failed login attemps - Session Creation / Session Termination - Password Change - All Administrative actions and configuration changes performed - User Create / Read / Update / Delete actions, Document or Object Create / Read / Update - Delete actions - Metadata Create / Read / Update / Delete actions - Identifying users and the actions they performed - Integration logs: API call successes and failures - Infrastructure logs Hypervisor / OS - Database Log+Transaction Logs - Source IP address of the actor

Business & Industrial peers that completed SOC 2