Carbonly helps UK businesses measure, report and reduce their greenhouse gas emissions. Upload the bills and invoices you already have and get an auditable emissions ledger, UK SRS-aligned disclosures, and reports your assurance provider can verify line by line.
The product is organised the way the work is: capture activity data, turn it into disclosure-ready reporting, and manage the reductions that follow.



Every number in a Carbonly report can be walked backwards to what produced it. The calculation engine is deterministic and version-stamped; results are append-only, so recalculation supersedes — it never overwrites history.
Every insert, update and delete writes a tamper-evident audit event — who, what, before and after, chained by hash.
Conversion factors only exist inside versioned datasets published by the control plane. Nothing is hard-coded, nothing is invented.
Reported periods reject silent changes — corrections go through restatements with a recorded explanation.

Carbonly is not a shared database with a customer column. Each client runs their own deployment — isolation is physical, then enforced again in code.
A dedicated PostgreSQL database per client — plus tenant-scoped query filters and an interceptor that treats any cross-tenant write as a security incident, not a bug.
A dedicated object-storage bucket for evidence, reports and AI model artefacts, and dedicated message queues for the processing pipeline.
Web app, API and workers run as your own containers, with your branding, locale, reporting year and feature configuration — updated without redeployment.
A new client's entire stack — database, migrations, storage, queues, configuration and admin invitation — is provisioned by a single idempotent, resumable operation.
The same stack shape runs on a single server or on Kubernetes, so the platform grows with its clients rather than being rebuilt for them.
Annual Defra releases are detected, imported and published to every client automatically — each year's activity calculated against its own year's factors.
Invitation-only registration, mandatory multi-factor authentication, passkey support, bot protection and breached-password checks on every account.
Role-based access down to individual pages — including a read-only Auditor role — with per-client SSO available by configuration.
Signed container images with a software bill of materials, dependency and vulnerability scanning in CI, and encryption in transit and at rest via the hosting platform. DPIA, disaster-recovery and penetration-test readiness packs included.
The ledger follows the GHG Protocol — all three scopes, all fifteen Scope 3 categories, Scope 2 dual reporting. Disclosure requirements cross-reference adjacent frameworks so the same data answers more than one question.
The UK SRS workbook is structured on the public IFRS S1/S2 four-pillar framework while the final FCA/DBT rules are pending — Carbonly says so in the product, and the official mapping replaces the template by configuration the day it is published. Pathway checks against the SBTi rate are a configurable criterion, not an SBTi validation.
A demo takes half an hour — bring a handful of real bills and watch them become an auditable ledger.
Book a demo