For technical teams
Architecture, APIs, integrations, security, and how the platform fits your stack.
Klappir is a modular, cloud-based data infrastructure (platform) hosted on Amazon Web Services (AWS) in Sweden. The architecture is built on four layers: cloud infrastructure (compute, network, storage, security, scalability), the canonical data model (UNSPSC-based resource data structure), a shared platform interface (identity, access control, integration, analytics), and the product layer (Sustainability, Strategy, Finance, LogCentral, Port).
Yes. The platform uses a multi-tenant architecture with isolated data and shared infrastructure. Each organization's data is fully segregated while benefiting from shared platform capabilities, updates, and ecosystem network effects.
The platform is hosted on AWS and designed for scalability, it accommodates growing data volumes, additional entities, new value chain participants, and increasing user counts. The modular architecture means you can start with core sustainability data and expand across resource categories, geographies, and reporting frameworks as your needs evolve.
Yes. Klappir provides a API for access to the platform. Integration methods include automatic API and SFTP data streams, semi-automatic data sharing through a data portal, and manual input and uploads. API documentation is available to customers upon request.
Klappir is hosted on Amazon Web Services (AWS) infrastructure in Sweden. All platform services are deployed within the AWS EU (Stockholm) region to meet European data residency requirements. Third-party services used for analytics and observability also store data within the EU at Klappir's requirement.
Klappir is hosted on AWS infrastructure certified for compliance with ISO/IEC 27001:2013, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, ISO 22301:2019, ISO 9001:2015, and CSA STAR CCM v4.0. These certifications cover information security management, cloud security controls, protection of personally identifiable information in cloud environments, privacy information management, business continuity, quality management, and cloud security assurance.
Yes. Klappir is fully compliant with the General Data Protection Regulation (EU) 2016/679. We have documented processes for all data subject rights including access, correction, erasure, restriction of processing, data portability, and withdrawal of consent. Requests are responded to within one month. Where personal data is transferred to third-party service providers, we require Standard Contractual Clauses adopted by the European Commission, and third parties may only process data on our instructions and under a duty of confidentiality.
Klappir employs encryption for data in transit and at rest, with appropriate security measures to prevent data from being accidentally lost, accessed in an unauthorised way, altered, or disclosed. Access to data is limited to employees, agents, and contractors with a business need, all of whom are subject to a duty of confidentiality.
All third-party service providers are required to respect the security of your data and treat it in accordance with applicable law. Third parties may only process data for specified purposes and in accordance with Klappir's instructions, they cannot use your data for their own purposes. Where data is transferred outside the European Economic Area, we use Standard Contractual Clauses adopted by the European Commission as the legal transfer mechanism.
Klappir's data structures, conversion factors, and calculation methodologies were designed to meet ISAE 3000 assurance standards and have previously been audited by Deloitte. The platform's architecture continues to enforce immutable audit logs (append-only transaction history), versioned entities with full lineage, and deterministic calculations, the same rigour expected of accounting systems.
Yes. Klappir has been in continuous development since 2014, over a decade of focused innovation in data management, software engineering, and regulatory compliance. The company is publicly listed on Nasdaq First North Iceland (KLAPP-B), operates with approximately 99% recurring revenue and positive EBIT, and has validated its business model across both public and private sectors in Iceland before expanding to Denmark, the UK, Germany, and other markets.
Yes. Klappir is designed to integrate with APIs, SFTP, file-based connectors, and manual upload. The platform is cloud-based with no on-premises installation required, minimising operational disruption during implementation.
The canonical data model is a standardized schema that classifies every sustainability transaction using UNSPSC codes (55,000+ categories organized in a four-level hierarchy: Segment, Family, Class, Commodity). Each transaction is tagged with the UNSPSC code, supplier identifier, invoice reference, conversion factors, asset/location, legal entity, and timestamp. This creates a universal data structure that enables cross-organization data exchange without point-to-point translation.
An authoritative data model is the single source of truth for how data is defined, structured, and interpreted within a domain. It matters because without authority, every system, team, or vendor quietly invents its own version of reality, making comparison, aggregation, and assurance impossible. Authority in the model, not in downstream reports, ensures consistency over time and across organizations.
All incoming data, regardless of source format, is harmonized, classified, validated, and enriched through the canonical data model pipeline. The platform normalizes disparate data into a single consistent structure, so you don't need to manually reconcile data from different systems, suppliers, or business units.
By separating ownership of data from ownership of definitions. Each organization controls its own inputs, but all participants adhere to shared schema, classifications, validation rules, and versioning governed by the canonical model. Governance is enforced technically, through schema, APIs, and validation, not socially, which is the only way it scales beyond bilateral trust.
By preserving lineage from every aggregated value back to its original source record, including source system, timestamps, transformations, classifications, and calculation logic. Nothing is overwritten, everything is versioned, and transformations are deterministic and inspectable, so an auditor can always reconstruct how a number was produced, even years later.
Longitudinal data is data collected and preserved consistently over time using stable definitions and structures. It's critical because most sustainability obligations, targets, baselines, trends, and reductions, are inherently temporal. Without longitudinal integrity, changes in methodology or tooling masquerade as performance changes. Klappir maintains a seven-year data retention policy for exactly this reason.
Klappir supports integrations with ERP systems, business intelligence tools (including Power BI), utility providers, and other enterprise systems. Integration methods include APIs, FTP-based file transfers, and direct database connectors.
Your data remains yours. Klappir supports data export in standard formats including JSON, CSV, and Excel, so you can extract your structured data at any time. The canonical data model means your data is in a standardised format that retains its value outside the platform.