Trust Centre

Built for the standards
your organisation demands.

The PSM Climate Performance Framework is designed for professional services firms, financial institutions, and enterprise organisations. This page documents how we protect your data, who can access it, and what certifications back our commitments.

19
In Place
2
Partial
1
In Progress
2
Roadmap

Our commitment to transparency

This page documents every security and compliance commitment — including those we do not yet fully meet. Items marked Partial or In Progress are known gaps with documented remediation plans, not undisclosed risks. We believe transparency builds more durable trust than marketing claims.

Compliance & Certifications

The PSM Climate Performance Framework is hosted on the Manus AI platform, which independently holds the following certifications. Full audit reports are available to enterprise customers under NDA.

SOC 2 Type II

In Place

The hosting platform holds a current SOC 2 Type II certification covering security, availability, and confidentiality trust service criteria.

Manus Trust Centre — trust.manus.im

ISO 27001:2022 — Information Security Management

In Place

The platform is certified against ISO 27001:2022, the international standard for information security management systems.

Manus Trust Centre — trust.manus.im

ISO 27701:2019 — Privacy Information Management

In Place

ISO 27701 extends ISO 27001 with privacy information management requirements, demonstrating commitment to GDPR-aligned data handling.

Manus Trust Centre — trust.manus.im

GDPR Compliance

Partial

Data processing agreements (DPAs) are available for enterprise customers. Standard Contractual Clauses (SCCs) are in place for international data transfers. EU data residency options are under review.

DPAs available on request — contact ERI

Infrastructure & Availability

The platform is built on enterprise-grade cloud infrastructure with redundancy, DDoS protection, and continuous monitoring.

Multi-Cloud Redundancy

In Place

Infrastructure is distributed across Amazon Web Services, Google Cloud Platform, and Microsoft Azure, providing geographic and provider redundancy with built-in DDoS protection at the network layer.

AWS, GCP, and Azure — Manus infrastructure overview

99.9% Uptime SLA

In Place

The Manus platform commits to a 99.9% monthly uptime SLA for production services. Planned maintenance windows are communicated in advance.

Manus Trust Centre — availability

Continuous Security Monitoring

In Place

All infrastructure is monitored continuously for anomalous activity, with automated alerting and incident response procedures in place.

Manus Trust Centre — monitoring

EU / Regional Data Residency

In Progress

Current AI sub-processors (Anthropic, Google Cloud, Microsoft Azure AI, AWS) are US-based. EU data residency options and SCCs for GDPR compliance are under active review.

Planned — in discussion with Manus platform team

Data Security & Encryption

All client data is encrypted in transit and at rest. No client data is ever used to train AI models.

Encryption in Transit (TLS 1.2+)

In Place

All communication between users and the platform is encrypted using HTTPS with TLS 1.2 or higher. Modern cipher suites are enforced; self-signed certificates are not used in production.

Encryption at Rest (AES-256)

In Place

All data stored in the database — including client portfolio data, assessment results, roadmap plans, and workspace configurations — is encrypted at rest using AES-256.

Managed by the Manus platform

File Upload Security

In Place

Uploaded files (Excel, CSV, JSON, images) are validated for type and size before processing. Files are stored in S3-compatible object storage — not in the database — and are accessible only to authorised workspace members.

AI Data Usage Policy

In Place

Data submitted to the PSM application is not used to train any AI model. AI processing is performed on-demand and results are stored only within the customer's workspace. No data is shared across workspaces.

Access Control & Identity

Access is controlled through federated identity, role-based permissions, and mandatory multi-factor authentication for staff accounts.

Federated OAuth 2.0 / OIDC Authentication

In Place

Users authenticate via Manus OAuth, an OIDC-based identity provider. No passwords are stored by the PSM application. CSRF protections are in place on all authentication flows.

Multi-Factor Authentication (TOTP)

In Place

Application-level TOTP authenticator app MFA is implemented and mandatory for all ERI staff accounts. Workspace owners can enforce MFA for all members of their workspace. MFA secrets are encrypted at rest using AES-256-GCM.

Implemented March 2026

Role-Based Access Control

In Place

Access within each workspace is governed by role-based permissions. Workspace owners control member access, and all permission changes are logged in the audit trail.

Corporate SSO / Azure AD Federation

Roadmap

Direct Azure AD federation is not currently supported. Enterprise users authenticate via Manus OAuth. Azure AD federation is on the roadmap for enterprise customers requiring corporate SSO.

Roadmap — dependent on Manus platform support

Workspace Isolation & Multi-Tenancy

Each organisation on the platform operates within a fully isolated workspace. Data from one organisation cannot be accessed by another — by design and by enforcement.

Logical Workspace Isolation

In Place

Every data record — client portfolios, project data, roadmaps, assessments, and configurations — carries a workspace identifier that is set at creation and enforced on every database query. This is the industry-standard multi-tenancy model used by Salesforce, Microsoft 365, and Google Workspace.

Server-Side Tenant Enforcement

In Place

Workspace boundaries are enforced at the API layer on every request. It is not possible for a client-side manipulation to access data from another workspace. All data access is validated against the authenticated user's workspace membership.

Workspace-Scoped Audit Logging

In Place

All significant actions within a workspace — including data access, member changes, and configuration updates — are recorded in a tamper-evident audit log accessible to workspace owners.

Physical Database Separation

Roadmap

All workspaces currently share the same underlying database infrastructure with strict logical isolation. Physical database separation per customer is on the roadmap as part of a planned migration to a dedicated high-security hosting environment.

Roadmap — planned for enterprise tier

Incident Response & Disclosure

ERI maintains a responsible disclosure policy and a documented incident response process. Security issues are taken seriously and addressed promptly.

Responsible Disclosure Policy

In Place

Security researchers and customers can report vulnerabilities directly to the ERI team. All reports are acknowledged within 48 hours and triaged within 5 business days.

Contact: [email protected]

Incident Response Process

In Place

A documented incident response process is in place, covering detection, containment, eradication, recovery, and post-incident review. Affected customers are notified within 72 hours of a confirmed breach, in line with GDPR Article 33 requirements.

Penetration Testing

Partial

The PSM application undergoes periodic penetration testing. Results are reviewed by the ERI engineering team and remediation plans are documented. Reports are available to enterprise customers under NDA.

Available under NDA — contact ERI

Dependency & Vulnerability Management

In Place

Automated dependency scanning is in place. Critical vulnerabilities in dependencies are patched within 7 days of disclosure. Security advisories are monitored continuously.

Frequently Asked Questions

Common questions from IT managers, procurement teams, and security reviewers.

Enterprise Security Documentation

Enterprise customers can request the full PSM Security Baseline Assessment report, the Manus SOC 2 Type II report (available under NDA), and ERI's data processing agreement. Contact the ERI team to initiate the documentation request.

This page was last updated March 2026. Security posture is reviewed on a continuous basis. For the most current information on the hosting platform's certifications, visit trust.manus.im.