Reporting frameworks Symbiosis ESG Compass helps your organization comply with, a scope-by-scope coverage matrix, platform security controls, and how to request enterprise attestations.
This page describes reporting frameworks the product helps you comply with, and platform-level security controls. Product-level certifications (SOC 2, ISO 27001) are stated only when independently attested - see the Attestation request section below. Maintained by Symbiosis LLC.
What's supported end-to-end today, what's partial, and what's on the near-term roadmap. Grouped by framework, 10 frameworks in total.
| Framework | Scope / datapoint group | Status | Notes |
|---|---|---|---|
| CSRD / ESRS | ESRS 1 - General requirements | Supported | All disclosure requirements + datapoints |
| · | ESRS 2 - General disclosures | Supported | Governance, strategy, IRO management, metrics |
| · | ESRS E1 - Climate change | Supported | Transition plan, targets, Scopes 1–3 tie-in |
| · | ESRS E2 - Pollution | Supported | Air, water, soil, substances of concern |
| · | ESRS E3 - Water & marine | Supported | Withdrawal, discharge, high-stress areas |
| · | ESRS E4 - Biodiversity | Supported | Impacts, dependencies, sensitive sites |
| · | ESRS E5 - Resource use & circular | Supported | Inflows, outflows, waste |
| · | ESRS S1 - Own workforce | Supported | Working conditions, diversity, remuneration |
| · | ESRS S2 - Value-chain workers | Supported | Human-rights due diligence in value chain |
| · | ESRS S3 - Affected communities | Supported | Community impacts and remediation |
| · | ESRS S4 - Consumers & end-users | Supported | Product safety, information access |
| · | ESRS G1 - Business conduct | Supported | Anti-corruption, whistleblowing, culture |
| · | XBRL tagged filing export | Roadmap | iXBRL machine-readable output |
| GRI | GRI 1, 2, 3 Universal | Supported | Foundation + General + Material topics |
| · | GRI 200 Economic series | Supported | 201, 202, 203, 204, 205, 206, 207 |
| · | GRI 300 Environmental | Supported | 301–308 including emissions, water, waste |
| · | GRI 400 Social | Supported | 401–418 including labor, human rights, community |
| IFRS S1 | General sustainability disclosures | Supported | Governance, strategy, risk, metrics |
| IFRS S2 | Climate-related disclosures | Supported | Physical & transition risk, Scopes 1–3 |
| TCFD | All 4 pillars, 11 recommendations | Supported | Consolidated into IFRS S2 reporting flow |
| GHG Protocol | Scope 1 - Direct emissions | Supported | Stationary, mobile, process, fugitive |
| · | Scope 2 - Purchased energy (location + market) | Supported | eGRID, IEA, residual mix factors |
| · | Scope 3 - All 15 categories | Supported | Cat 1–15 with seeded DEFRA / EPA / IPCC / GLEC factors |
| · | Assurance-ready audit exports | Partial | CSV + PDF today; ISAE 3410 templates on roadmap |
| SASB | 77 industry standards cross-reference | Partial | 10 highest-demand industries mapped; remainder rolling out |
| EO 14030 | Federal contractor sustainability | Supported | GRI + IFRS S1/S2 pre-mapped starter kit |
| CDP | Climate, Water, Forests questionnaires | Roadmap | Auto-populate from Scope 1–3 and governance data |
| EU Taxonomy | Eligibility & alignment screening | Roadmap | For CSRD filers with EU activities |
How the platform itself is built to keep your ESG data isolated and auditable.
Every table in the platform is protected by PostgreSQL row-level security scoped to your organization ID. Users in one workspace cannot read or write another workspace's data at the database layer.
Roles (admin, contributor, reviewer) are stored in a dedicated table separate from user profiles. Only org admins can grant or revoke roles within their own organization, and no user can modify their own role.
Sensitive reference tables require authentication; internal security-definer helper functions used by RLS policies are not exposed through the public API.
Email + password and Google OAuth are supported today. SSO/SAML is available for enterprise customers on request.
Uploaded documents are stored in a private object-storage bucket. Files can be superseded but never silently overwritten, so auditors can walk back to prior versions.
Responses, readiness snapshots, and evidence carry timestamps and owner metadata so reviewers can reconstruct how a disclosure was prepared.
Enterprise procurement teams: tell us what you need for your security review and we'll respond with the current versions under NDA where required.
Symbiosis LLC operates the platform, maintains framework libraries, and enforces the security controls above. Your organization is responsible for the accuracy of the data you enter, the completeness of your evidence, and the sign-off process for disclosures you file with regulators or share with investors.