Frameworks & compliance

Reporting frameworks Symbiosis ESG Compass helps your organization comply with, a scope-by-scope coverage matrix, platform security controls, and how to request enterprise attestations.

This page describes reporting frameworks the product helps you comply with, and platform-level security controls. Product-level certifications (SOC 2, ISO 27001) are stated only when independently attested - see the Attestation request section below. Maintained by Symbiosis LLC.

Framework coverage matrix

What's supported end-to-end today, what's partial, and what's on the near-term roadmap. Grouped by framework, 10 frameworks in total.

23 supported
2 partial
3 roadmap
FrameworkScope / datapoint groupStatus
CSRD / ESRSESRS 1 - General requirements Supported
·ESRS 2 - General disclosures Supported
·ESRS E1 - Climate change Supported
·ESRS E2 - Pollution Supported
·ESRS E3 - Water & marine Supported
·ESRS E4 - Biodiversity Supported
·ESRS E5 - Resource use & circular Supported
·ESRS S1 - Own workforce Supported
·ESRS S2 - Value-chain workers Supported
·ESRS S3 - Affected communities Supported
·ESRS S4 - Consumers & end-users Supported
·ESRS G1 - Business conduct Supported
·XBRL tagged filing export Roadmap
GRIGRI 1, 2, 3 Universal Supported
·GRI 200 Economic series Supported
·GRI 300 Environmental Supported
·GRI 400 Social Supported
IFRS S1General sustainability disclosures Supported
IFRS S2Climate-related disclosures Supported
TCFDAll 4 pillars, 11 recommendations Supported
GHG ProtocolScope 1 - Direct emissions Supported
·Scope 2 - Purchased energy (location + market) Supported
·Scope 3 - All 15 categories Supported
·Assurance-ready audit exports Partial
SASB77 industry standards cross-reference Partial
EO 14030Federal contractor sustainability Supported
CDPClimate, Water, Forests questionnaires Roadmap
EU TaxonomyEligibility & alignment screening Roadmap

Platform security controls

How the platform itself is built to keep your ESG data isolated and auditable.

Row-level tenant isolation

Every table in the platform is protected by PostgreSQL row-level security scoped to your organization ID. Users in one workspace cannot read or write another workspace's data at the database layer.

Least-privilege role model

Roles (admin, contributor, reviewer) are stored in a dedicated table separate from user profiles. Only org admins can grant or revoke roles within their own organization, and no user can modify their own role.

Reference-data hardening

Sensitive reference tables require authentication; internal security-definer helper functions used by RLS policies are not exposed through the public API.

Authentication

Email + password and Google OAuth are supported today. SSO/SAML is available for enterprise customers on request.

Evidence versioning

Uploaded documents are stored in a private object-storage bucket. Files can be superseded but never silently overwritten, so auditors can walk back to prior versions.

Auditable change history

Responses, readiness snapshots, and evidence carry timestamps and owner metadata so reviewers can reconstruct how a disclosure was prepared.

Attestation & DPA request

Enterprise procurement teams: tell us what you need for your security review and we'll respond with the current versions under NDA where required.

Select everything your procurement or security team needs.

Note on SOC 2 Type II and ISO 27001: Symbiosis does not currently hold these certifications. In line with our compliance page, we only claim certifications once they are independently attested. If you request either, we will share our current controls documentation and target attestation dates instead of a certificate that does not yet exist.

Submitting opens your email client with a pre-filled message to security@symbiosis-llc.com. We reply within 2 business days.

Shared responsibility

Symbiosis LLC operates the platform, maintains framework libraries, and enforces the security controls above. Your organization is responsible for the accuracy of the data you enter, the completeness of your evidence, and the sign-off process for disclosures you file with regulators or share with investors.