Security
How we handle project data
Authentication, access controls, and the handling of uploaded files.
Authentication and multi-factor authentication
CarbCut uses a managed identity service, supports TOTP-based MFA, and validates every API request.
Organization and role-based access
Data is separated by organization, with permissions assigned through Owner, Admin, Editor, and Viewer roles.
Handling of uploaded files
Files are used to prepare documents for the relevant project and sent to the AI provider over an encrypted API connection.
Contact us for materials required for a security review or vendor assessment.