Built for the standards
your organisation demands.
The PSM Climate Performance Framework is designed for professional services firms, financial institutions, and enterprise organisations. This page documents how we protect your data, who can access it, and what certifications back our commitments.
Our commitment to transparency
This page documents every security and compliance commitment — including those we do not yet fully meet. Items marked Partial or In Progress are known gaps with documented remediation plans, not undisclosed risks. We believe transparency builds more durable trust than marketing claims.
Compliance & Certifications
The PSM Climate Performance Framework is hosted on the Manus AI platform, which independently holds the following certifications. Full audit reports are available to enterprise customers under NDA.
SOC 2 Type II
In PlaceThe hosting platform holds a current SOC 2 Type II certification covering security, availability, and confidentiality trust service criteria.
Manus Trust Centre — trust.manus.im
ISO 27001:2022 — Information Security Management
In PlaceThe platform is certified against ISO 27001:2022, the international standard for information security management systems.
Manus Trust Centre — trust.manus.im
ISO 27701:2019 — Privacy Information Management
In PlaceISO 27701 extends ISO 27001 with privacy information management requirements, demonstrating commitment to GDPR-aligned data handling.
Manus Trust Centre — trust.manus.im
GDPR Compliance
PartialData processing agreements (DPAs) are available for enterprise customers. Standard Contractual Clauses (SCCs) are in place for international data transfers. EU data residency options are under review.
DPAs available on request — contact ERI
Infrastructure & Availability
The platform is built on enterprise-grade cloud infrastructure with redundancy, DDoS protection, and continuous monitoring.
Multi-Cloud Redundancy
In PlaceInfrastructure is distributed across Amazon Web Services, Google Cloud Platform, and Microsoft Azure, providing geographic and provider redundancy with built-in DDoS protection at the network layer.
AWS, GCP, and Azure — Manus infrastructure overview
99.9% Uptime SLA
In PlaceThe Manus platform commits to a 99.9% monthly uptime SLA for production services. Planned maintenance windows are communicated in advance.
Manus Trust Centre — availability
Continuous Security Monitoring
In PlaceAll infrastructure is monitored continuously for anomalous activity, with automated alerting and incident response procedures in place.
Manus Trust Centre — monitoring
EU / Regional Data Residency
In ProgressCurrent AI sub-processors (Anthropic, Google Cloud, Microsoft Azure AI, AWS) are US-based. EU data residency options and SCCs for GDPR compliance are under active review.
Planned — in discussion with Manus platform team
Data Security & Encryption
All client data is encrypted in transit and at rest. No client data is ever used to train AI models.
Encryption in Transit (TLS 1.2+)
In PlaceAll communication between users and the platform is encrypted using HTTPS with TLS 1.2 or higher. Modern cipher suites are enforced; self-signed certificates are not used in production.
Encryption at Rest (AES-256)
In PlaceAll data stored in the database — including client portfolio data, assessment results, roadmap plans, and workspace configurations — is encrypted at rest using AES-256.
Managed by the Manus platform
File Upload Security
In PlaceUploaded files (Excel, CSV, JSON, images) are validated for type and size before processing. Files are stored in S3-compatible object storage — not in the database — and are accessible only to authorised workspace members.
AI Data Usage Policy
In PlaceData submitted to the PSM application is not used to train any AI model. AI processing is performed on-demand and results are stored only within the customer's workspace. No data is shared across workspaces.
Access Control & Identity
Access is controlled through federated identity, role-based permissions, and mandatory multi-factor authentication for staff accounts.
Federated OAuth 2.0 / OIDC Authentication
In PlaceUsers authenticate via Manus OAuth, an OIDC-based identity provider. No passwords are stored by the PSM application. CSRF protections are in place on all authentication flows.
Multi-Factor Authentication (TOTP)
In PlaceApplication-level TOTP authenticator app MFA is implemented and mandatory for all ERI staff accounts. Workspace owners can enforce MFA for all members of their workspace. MFA secrets are encrypted at rest using AES-256-GCM.
Implemented March 2026
Role-Based Access Control
In PlaceAccess within each workspace is governed by role-based permissions. Workspace owners control member access, and all permission changes are logged in the audit trail.
Corporate SSO / Azure AD Federation
RoadmapDirect Azure AD federation is not currently supported. Enterprise users authenticate via Manus OAuth. Azure AD federation is on the roadmap for enterprise customers requiring corporate SSO.
Roadmap — dependent on Manus platform support
Workspace Isolation & Multi-Tenancy
Each organisation on the platform operates within a fully isolated workspace. Data from one organisation cannot be accessed by another — by design and by enforcement.
Logical Workspace Isolation
In PlaceEvery data record — client portfolios, project data, roadmaps, assessments, and configurations — carries a workspace identifier that is set at creation and enforced on every database query. This is the industry-standard multi-tenancy model used by Salesforce, Microsoft 365, and Google Workspace.
Server-Side Tenant Enforcement
In PlaceWorkspace boundaries are enforced at the API layer on every request. It is not possible for a client-side manipulation to access data from another workspace. All data access is validated against the authenticated user's workspace membership.
Workspace-Scoped Audit Logging
In PlaceAll significant actions within a workspace — including data access, member changes, and configuration updates — are recorded in a tamper-evident audit log accessible to workspace owners.
Physical Database Separation
RoadmapAll workspaces currently share the same underlying database infrastructure with strict logical isolation. Physical database separation per customer is on the roadmap as part of a planned migration to a dedicated high-security hosting environment.
Roadmap — planned for enterprise tier
Incident Response & Disclosure
ERI maintains a responsible disclosure policy and a documented incident response process. Security issues are taken seriously and addressed promptly.
Responsible Disclosure Policy
In PlaceSecurity researchers and customers can report vulnerabilities directly to the ERI team. All reports are acknowledged within 48 hours and triaged within 5 business days.
Contact: [email protected]
Incident Response Process
In PlaceA documented incident response process is in place, covering detection, containment, eradication, recovery, and post-incident review. Affected customers are notified within 72 hours of a confirmed breach, in line with GDPR Article 33 requirements.
Penetration Testing
PartialThe PSM application undergoes periodic penetration testing. Results are reviewed by the ERI engineering team and remediation plans are documented. Reports are available to enterprise customers under NDA.
Available under NDA — contact ERI
Dependency & Vulnerability Management
In PlaceAutomated dependency scanning is in place. Critical vulnerabilities in dependencies are patched within 7 days of disclosure. Security advisories are monitored continuously.
Frequently Asked Questions
Common questions from IT managers, procurement teams, and security reviewers.
Enterprise Security Documentation
Enterprise customers can request the full PSM Security Baseline Assessment report, the Manus SOC 2 Type II report (available under NDA), and ERI's data processing agreement. Contact the ERI team to initiate the documentation request.
This page was last updated March 2026. Security posture is reviewed on a continuous basis. For the most current information on the hosting platform's certifications, visit trust.manus.im.
