Skip to content
CarbCut

Security

How we handle project data

Authentication, access controls, and the handling of uploaded files.

Authentication and multi-factor authentication

CarbCut uses a managed identity service, supports TOTP-based MFA, and validates every API request.

Organization and role-based access

Data is separated by organization, with permissions assigned through Owner, Admin, Editor, and Viewer roles.

Handling of uploaded files

Files are used to prepare documents for the relevant project and sent to the AI provider over an encrypted API connection.

Contact us for materials required for a security review or vendor assessment.