Skip to main content
Forest and Harvested Wood Product Carbon Platform
Back

Data Security

Approved by the Endowment

1. Overview

This Security Policy (“Policy”) describes the security measures and data protection practices for the Forestry Analytics for Carbon Tracking (“FACT”) platform, owned and operated by the U.S. Endowment for Forestry and Communities, Inc., a Delaware nonprofit corporation (the “Endowment”).

This Policy outlines key security considerations for FACT. Specifically, it focuses on data security relevant to FACT’s business requirements and on the broader context of data and software security baselines.

FACT is intended solely for Users located within the United States of America and Canada. Security measures described in this Policy are designed to comply with applicable U.S. federal and state requirements and applicable Canadian privacy and data protection legislation.

BETA PLATFORM NOTICE. FACT is an evolving platform that may contain errors, omissions, incomplete functionality, or data limitations. Features, datasets, methodologies, and outputs may be modified, updated, suspended, or removed without notice. Users acknowledge that service interruptions, technical issues, delayed updates, or temporary unavailability may occur and agree that such conditions are inherent to a beta-stage platform.

Users are given the option to not save the uploaded data.

For operations that don't require long-term storage of data, Users are given the ability to opt out of permanently saving the data they upload. In this case, the data will be stored only temporarily and only as far as fulfilling the technical requirements of the tools used to validate, calculate and visualize data.

All the calculations and post-processing of data (for example, generation of reports or exporting of calculated results to specific downloadable formats, if applicable) are then performed by associating a random task identifier to the calculations, without associating data, calculations, or outputs to any specific User.

Each User who wishes to not save uploaded data permanently can then check the status of calculations (for long-running calculations) and view results only by using the unique identifier provided when they start calculations on their data.

Once Users have retrieved their calculations' results, the underlying data is permanently deleted from FACT.

Users are provided with documentation on how the data is stored and processed.

A user-friendly version of key points from the final version of the present document may be used as part of documentation for Users, explaining how data is stored and processed.

Users’ raw data is anonymized and processed securely.

  1. Anonymization as avoidance of association of data to specific personal identities and personal identifiable information. In this context, Users will have the option to upload data without being logged into FACT (or even without having an account), with guarantee that data is only retained and processed as strictly necessary and permanently removed once calculations are completed and Users have viewed/downloaded calculation results. Likewise, Users may opt to upload data while logged in but choose not to save that data.
  2. Anonymization as a limitation to the ability to infer identifiable information about the individuals/teams/organizations behind specific scenarios being analyzed on the FACT platform. For example, areas of interest, sets of forest stands included in an analysis, etc., as well as any other information, data and metadata uploaded by Users. In this context, anonymization may be a contradictory goal with the aim of providing and processing detailed data for analysis.

Users will be able to securely access FACT and be given the option to upload and store data and reports

Authentication and authorization strategies suitable for FACT’s requirements will be in place to allow Users to manage data within their private section of FACT, as well as to permanently delete their data once they no longer need it.

2. Plain-Language Data Protection Summary

FACT is designed to limit the collection and retention of User-provided information where practical. Where FACT functionality permits, Users may upload information without creating an account or may choose not to save uploaded information permanently.

When a User chooses not to save uploaded information, the information is stored temporarily as needed to complete the requested validation, calculations, visualizations, reports, or exports. Access to calculations and results may be provided through a randomly generated task identifier rather than through an association with a specific User. The underlying information is deleted as described in this Policy after the User retrieves the calculation results.

Users should avoid submitting personal, confidential, or other sensitive information unless it is appropriate and necessary for their use of FACT.

3. Secure Processing and Protection of User Raw Data

Ensure minimization of exposure and secure processing of all personal and confidential information through a number of procedures.

4. Definition and Scope

  • Personal Data is any information related to an identified or identifiable person.
  • Confidential Information includes trade secrets, customer information, employee data, strategic plans, and any data with potential risk if disclosed.
  • These categories are protected under an Information Classification Policy, with three tiers: Confidential, Internal Use, and Public. The strictest applies in case of mixed content.

5. Handling in Test and Development Environments

  • Data used in non-production environments is anonymized or randomly generated, encrypted at rest and in transit, and subject to strict access restrictions.
  • Test data is securely deleted when no longer needed, in accordance with the Endowment’s Secure Development Policy.

6. Confidentiality Commitments

  • All employees and contractors are bound by confidentiality obligations, which extend beyond termination of employment. Data may not be disclosed, reused, or processed outside the strict scope defined by this Policy.

7. Security Incident Response and Breach Notification

Procedures will be maintained for responding to suspected security incidents affecting FACT data or systems. If a security incident involving personal information requires notification, notice will be provided in accordance with applicable legal, contractual, and regulatory requirements. The timing, content, and recipients of any notification will depend on the nature of the incident and the requirements that apply.

8. Storage and Transmission Protections

  • Google Drive is our exclusive storage platform for critical documentation, with AES-256 encryption at rest and TLS encryption in transit.
  • External media storage is prohibited unless encrypted and explicitly authorized.
  • Sensitive documents must be password-protected and shared over separate secure channels (e.g., password by SMS).
  • Files are not stored locally or on unauthorized platforms, and corporate information is forbidden on personal cloud/email systems.

9. Cloud and Development Security: Approved Cloud Services Only

  • Only services like Google Workspace, AWS, Google Cloud, GitHub, and Jira are authorized for storing/sharing data. Each is assessed against encryption, MFA, access controls, and compliance requirements.

10. Secure Development Lifecycle (SDLC) Requirements

  • Backend input validation
  • Centralized authentication and session management
  • Access-controlled source code repositories
  • Secure CI/CD pipelines with vulnerability scanning (e.g., Dependabot)
  • Strict separation of dev/test/prod environments with no use of real production data

11. Business Continuity and Disaster Recovery

FACT will maintain procedures intended to support the recovery of FACT operations following significant service disruptions, infrastructure failures, or other business continuity events. These procedures may include backups and restoration activities appropriate to FACT’s operational requirements.

12. ISO Standards

The FACT platform is developed and operated using security and quality management practices informed by recognized industry standards. Where applicable, the Endowment and its service providers may maintain certifications, audits, policies, or procedures aligned with standards including:

  • ISO/IEC 27001:2022, Information Security Management Systems
  • UNI EN ISO 9001:2015, Quality Management Systems

References to these standards do not represent a claim that the FACT platform itself, the Endowment, or every service provider is currently certified under those standards unless expressly stated and supported by the applicable certification.

13. Suspension and Termination

The Endowment reserves the right, at its sole discretion, to suspend, restrict, or terminate any User’s access to FACT at any time, without notice and without liability, for any reason, including suspected violations of these policies, security concerns, or operational requirements.

14. Limitation of Liability and Disclaimer

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE ENDOWMENT, ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, CONTRACTORS, SERVICE PROVIDERS, AND CONTRIBUTORS SHALL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES ARISING FROM OR RELATING TO ANY SECURITY BREACH, DATA LOSS, UNAUTHORIZED ACCESS, SYSTEM FAILURE, OR OTHER SECURITY INCIDENT AFFECTING FACT OR USER DATA, REGARDLESS OF THE CAUSE.

THE FACT PLATFORM AND ALL DATA, CONTENT, AND SECURITY MEASURES ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. THE ENDOWMENT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, REGARDING THE SECURITY, INTEGRITY, OR AVAILABILITY OF FACT OR ANY DATA STORED OR PROCESSED THROUGH FACT. USERS ACKNOWLEDGE THAT NO SYSTEM CAN BE GUARANTEED COMPLETELY SECURE AND THAT THEY ACCESS AND USE FACT AT THEIR OWN RISK.

IN NO EVENT SHALL THE ENDOWMENT HAVE ANY OBLIGATION TO INDEMNIFY ANY USER OR THIRD PARTY FOR ANY CLAIM ARISING FROM OR RELATED TO A SECURITY INCIDENT, DATA BREACH, OR OTHER EVENT DESCRIBED IN THIS SECURITY POLICY.

IN NO EVENT SHALL THE TOTAL LIABILITY OF THE ENDOWMENT ARISING FROM OR RELATED TO THIS SECURITY POLICY EXCEED ONE HUNDRED DOLLARS ($100.00).

This Policy should be read together with the FACT Terms of Use, Privacy Policy, and Cookie Policy.