4
Article-4

Updated May 2025

Platform Transparency

Enterprise procurement teams and ESG auditors often need to verify the environmental and security posture of software vendors. This page provides a clear, honest overview of how Article-4 is built and operated.

Infrastructure & data residency

๐Ÿ—„๏ธ

Database & authentication

Supabase on AWS eu-central-1 (Frankfurt, Germany)

All user data, training records, and certificates stored in the EU.

๐ŸŒ

Application hosting

Vercel โ€” EU edge region (primary)

Serverless functions run in EU. Static assets served from nearest CDN node.

โœ‰๏ธ

Transactional email

Resend Inc. โ€” US (Standard Contractual Clauses)

Only your email address and name are sent to Resend for delivery.

๐Ÿ’ณ

Payment processing

Stripe โ€” EU (Stripe Payments Europe Ltd., Dublin)

Payment card data never touches Article-4 servers. Processed entirely by Stripe.

Environmental commitments

Article-4 is a cloud-native SaaS product. We own no physical hardware. Our environmental footprint is primarily Scope 2 (purchased electricity) and Scope 3 (cloud provider upstream emissions).

Scope 1 emissions

Zero

No owned offices or hardware. Fully remote team.

Scope 2 emissions

Negligible

AWS Frankfurt runs on renewable energy (100% renewable target by 2025). Vercel uses CDN with green hosting.

Scope 3 โ€” cloud

Minimised

Serverless architecture โ€” compute only runs on request. No idle servers.

Paper reduction

Digital-first

All certificates, invoices, and compliance records are digital. Zero paper output.

Cloud provider sustainability references: AWS Sustainability ยท Vercel Climate Partner

Security posture

โœ“

TLS 1.2+ encryption in transit

All API calls and web traffic

โœ“

AES-256 encryption at rest

Database (Supabase/AWS)

โœ“

Role-based access control

Least-privilege by design

โœ“

Row-level security (RLS)

Supabase RLS on all tables

โœ“

Dependency scanning

GitHub Dependabot (automated)

โœ“

No password storage

Supabase Auth handles credentials

โœ“

Session token rotation

Automatic via Supabase Auth

โœ“

Admin key isolation

Service role key never client-side

Security issues may be reported to hei@article-4.com. We aim to acknowledge within 24 hours and resolve within 7 days.

Accessibility

We are committed to making Article-4 accessible to all employees, including those with disabilities.

Target standard

WCAG 2.1 Level AA

IN PROGRESS

Keyboard navigation

Supported throughout platform

DONE

Colour contrast

AA compliant on all text

DONE

Screen reader support

Semantic HTML, ARIA labels

IN PROGRESS

Language

Norwegian (Bokmรฅl) + English

DONE

To report an accessibility issue, email hei@article-4.com.

Data retention summary

Data typeRetention periodLegal basis
Account & profile dataActive subscription + 30 daysContract performance
Training records & certificates7 yearsAudit requirement (CSRD/ESRS S1)
Invoice records5 yearsNorwegian Bookkeeping Act
Email logs90 daysSecurity / debugging
Technical logs (IP, session)90 daysSecurity monitoring

CSRD & ESG disclosure

For customers conducting CSRD sustainability reporting, Article-4 can serve as verifiable evidence for ESRS S1 (own workforce โ€” training and skills development).

What Article-4 covers for your CSRD report

ESRS S1-1

Policies related to own workforce โ€” AI literacy policy evidence

ESRS S1-4

Taking action on material impacts โ€” documented training completion

ESRS S1-13

Training and skills development โ€” hours, completion rates, scores

ESRS G1-1

Business conduct โ€” compliance training as governance evidence

Export your evidence log from /app/evidenceโ†’ "Export for audit" to get a structured CSV ready for your sustainability auditor.

Service levels

99.5%

Target uptime

Excl. planned maintenance

2 days

Support response

Via hei@article-4.com

24 hours

Maintenance notice

Via email to admin users