Skip to content
Security & trust

Security a bank can grade for itself.

A disclosure carries someone's signature, so the system behind it has to stand up to procurement. Here is how access, approval and evidence are controlled — laid out plainly for your own security team to assess, without badges we haven't earned.

Controls

The controls procurement will ask about.

Role-based access control

People see and do only what their role allows. Who can enter, who can approve and who can only read are separate permissions, set per workspace.

MFA & SSO

Multi-factor authentication on sign-in, and single sign-on so access follows your existing identity provider and joiner-mover-leaver process.

Immutable audit log

Every material action is recorded — who entered a figure, who approved it, what changed and when. The log is append-only, so the history can't be quietly rewritten.

Traceable to source

Each number ties back to the document it came from, the emission factor applied and the person who signed it off — the full chain, reviewable on demand.

Tenant isolation

Each organisation's data is kept in its own isolated tenant. One customer's records are never visible to another.

Data residency

Where your data lives matters to a GCC regulator, so residency is scoped with you at onboarding rather than assumed — raise your jurisdiction's requirements and we'll walk through them.

Why a number holds up

Approval and evidence, enforced by the system — not by convention.

Defensibility isn't a policy document; it's built into how a record moves. Nothing reaches a report without passing through it.

  1. Step 1

    Entered

    A maker creates the record under a named identity.

  2. Step 2

    Submitted

    Sent for review — the maker can't approve their own work.

  3. Step 3

    Reviewed

    A checker verifies the figure and its source document.

  4. Step 4

    Approved & locked

    The record locks, naming its approver. Nothing else changes it.

Standards: support, not a certificate.

Susmatic ESG helps your teams report against GRI, ISSB/IFRS S1 & S2 and CBB guidelines, and appends a framework index to reports. That is support for your reporting — it is not a certification, not a compliance guarantee, and not a substitute for your own auditor's opinion.

A modern institutional building, evoking an enterprise under review.
Assurance

The evidence an auditor asks for, already in place.

Access, approvals and an immutable audit trail aren't a policy you promise — they're how a record moves, so a review finds the chain intact.

Hand this to your security team.

Book a demo and we'll walk your security and procurement reviewers through access, approvals and the audit trail — with your questions in hand.