ēkotrace
Trust Center
v1.0 · July 2026
ēkotrace™ · ēkot Circular Solutions

Trust Center

This page states ēkotrace's security, privacy and compliance posture as it actually is — what is running in production, what is designed to align with a standard, and what is on the roadmap. We do not display certification badges we do not hold, and we mark every claim with its current status.

Last reviewed: July 2026 · v1.0 · Owner: innovation@ekot.nz

Section 1

Verify it yourself

ēkotrace's core integrity claim is independently checkable. Every material record is SHA-256 hash-chained, and the public verifier recomputes the entire chain from the original data on every request:

Open the public record verifier → No login required. If a single historical record had been altered, the chain would fail to recompute from that point forward.

Our public AI Use Statement documents exactly where AI is and is not used in the platform.

Section 2

Security controls

ControlDetailStatus
Tamper-evident chain of custodyEvery gate event is SHA-256 hash-chained to the previous event per material stream. Anyone can recompute the chain via the public verifier at /verify — no login, no trust in ēkotrace required.In production
Encryption in transitTLS 1.2+ enforced at the edge for all browser traffic; TLS on the application-to-database connection and on all third-party API calls.In production
Encryption at restProvider-managed encryption at rest on the primary database.In production
Database API lockdownRow Level Security enabled on every application table with all direct API privileges revoked — application tables are not reachable through any auto-generated database API.In production
Authentication on every internal routeEdge middleware enforces login on all non-public routes; the small set of public endpoints is explicitly enumerated and method-scoped.In production
Human-in-the-loop AIAI is used for one task only (document OCR) and a human operator must review and confirm every extraction before it enters the chain. No AI in the hash chain, routing engine or carbon calculations.In production
Evidence-based carbon figuresAll emission factors cited to Ministry for the Environment 2025 publications. ēkotrace reports verified-avoidance volumes; it does not issue or sell carbon credits.In production
Per-user accounts, RBAC & MFARole-based access (Operator / Reviewer / Verifier / Admin) with MFA for privileged roles.Roadmap
Multi-tenant isolationContractual gate before mixed-client production data shares a deployment.Roadmap
External penetration testingFirst external pen-test planned alongside ISO 27001 preparation.Roadmap

Today's access-control posture is appropriate for pilot, demo and single-tenant trial use. Multi-tenant production with mixed-client data is contractually gated on the roadmap items above.

Section 3

Data residency & sub-processors

Sub-processorPurposeRegion
Replit, Inc.Application hosting (autoscale runtime, TLS edge)United States (GCP infrastructure)
SupabasePrimary PostgreSQL databaseSingapore (AWS ap-southeast-1)
OpenAIDocument OCR only, via managed integration — no training on API inputs per provider termsUnited States
ResendTransactional email (team notifications only)United States

Residency roadmap: the current pilot deployment stores operational data in Singapore (database) with US-hosted application runtime. NZ/AU data residency is the contractual baseline we will stand up before onboarding Crown, Council or residency-sensitive enterprise clients — regional deployments are additive; client data is never consolidated into a single global database.

ēkotrace holds minimal personal information by design: no payment data, no marketing analytics, no location tracking, no customer-of-customer PII. Donor records are pseudonymous with masked contact hints only.

Section 4

Standards & certification roadmap

ēkotrace does not claim certification under any standard it has not been certified against. Where a client requires certification rather than alignment, we will engage a certification body as part of the engagement.

StandardPositionStatus
NZ Privacy Act 2020Designed to comply; data-minimisation and breach-notification posture documented. Formal DPA review scheduled.Designed to align — not certified
ISO/IEC 27001 (Information security)Control families used as the design reference. Certification targeted for 2027 with the first multi-tenant production deployment.Roadmap
SOC 2 Type 2Targeted alongside ISO 27001 in 2027.Roadmap
ISO/IEC 42001 (AI management)AI footprint designed to align; human-in-the-loop architecture documented in the public AI Use Statement.Designed to align — not certified
ISO 14064-1 / GHG ProtocolCarbon calculation methodology aligned; MfE 2025 emission factors cited per figure.Designed to align — not certified
ISO 59014 / 59020 (Circular economy)Material-flow methodology aligned.Designed to align — not certified
Algorithm Charter for Aotearoa NZ · NZ AI Forum principlesDesigned to align — relevant where public-sector clients rely on ēkotrace outputs.Designed to align — not certified
Section 5

Documents available to reviewers

The following reviewer-facing documents are available on request to procurement, IT-security and privacy teams under NDA where required:

  • Data Sovereignty Review (v1.0) — data inventory, cross-border flows, retention & deletion, breach notification, audit rights
  • Disaster Recovery Runbook — backup cadence, restore procedure, RPO/RTO posture
  • AI Use Statement (v1.0) — public at /ai-use
  • Emission-factor citation register (MfE 2025 sources per figure)

Request access: email innovation@ekot.nz with the subject line "Trust Center document request". We respond in writing within 5 business days.

Section 6

Responsible disclosure

If you believe you have found a security vulnerability in the ēkotrace platform, please email innovation@ekot.nz with the subject line "Security disclosure". We commit to acknowledging reports within 2 business days and will not pursue good-faith researchers who respect user privacy and avoid service disruption. Confirmed breaches affecting client data are notified to the affected client within 72 hours of detection.

This page supersedes earlier informal statements about ēkotrace's security posture. Material changes are re-versioned and dated.