
Bardo
Bardo is a Swedish carbon accounting platform for companies under CSRD obligations. It rebuilds Scope 1, 2 and 3 inventories from invoices and ERP data, calculating product by product not from spend, so every tonne traces to a document.
What is Bardo?
Bardo is a carbon accounting platform published by Bardo Technology AB in Stockholm. Its own metaphor is bookkeeping for carbon: the emissions inventory is treated as a ledger, built from data the company already holds, namely invoices, ERP exports and accounts payable, rather than from a survey or a spreadsheet exercise.
The method is activity-based and product-level, not spend-based. Instead of multiplying an amount paid by a sector factor, Bardo works out what was actually bought: a line reading 'IT equipment' becomes an iPhone 16 Pro Max from a named supplier. The published examples show what that changes. Two monitors in the same category at similar prices come out at 168 kg CO2e each under a spend-based factor, but at 112 kg and 231 kg at product level, a 2.06x spread hidden inside one category. A purchase of 100 laptops carries roughly 340 kg CO2e per unit under a spend factor, against roughly 119 kg from the manufacturer's own lifecycle data.
The pipeline runs in seven steps: documents go into a secure dataroom, AI reads every line, the environmental documentation for each product is retrieved, the factor is applied and calculated, uncertain cases go to human specialists, the full inventory is assembled, and simple analytics sit on top. Extraction is stated at 99%+. Factor quality is graded on five levels, A to E, by how specific the source is, so the confidence behind each number is visible rather than assumed.
Coverage spans Scope 1, 2 and 3 across every entity of a group under a single methodology. Every number traces back to a source document: an auditor can sample 50 activities and statistically verify the entire dataset, just like a financial audit. Audit logs are immutable, carrying user, timestamp and a before/after snapshot.
It is delivered as a managed service, with no console to operate and no software to learn. The claimed frameworks are GHG Protocol alignment, CSRD-ready reporting, SOC 2 Type II, EU hosting and end-to-end encryption. Bardo states 100+ customer companies and that 100% of customers continue after seeing their results. Named references include Deloitte, Tele2, Storytel, Stegra, Aura Group, Bjare Kraft, First Camp, KEYTO Group and Ernstromgruppen. At KEYTO, a major emission source turned out to be fertiliser at a gardening subsidiary, invisible in manual reporting.
What it does
- Reads invoices, ERP exports and service bills in any format, including PDF, XML, EDI and image files
- Identifies the actual product or service behind each line, with its named supplier, instead of stopping at the spend category
- Retrieves the environmental documentation for that product (supplier LCA, EPD, product specifications) and applies the most specific emission factor available, graded A to E
- Routes uncertain cases to human specialists for review before anything is published
- Produces a complete Scope 1, 2 and 3 inventory aligned with the GHG Protocol and ready for CSRD reporting, across every entity of a group
- Locks a snapshot at filing and assembles the auditor evidence pack, with an audit trail down to the source document
- Exports every activity to CSV or Excel and compares suppliers on carbon performance alongside cost
When to use Bardo / When not to
A quick filter to help you decide if Bardo is the right fit.
When to use Bardo
- Sustainability and ESG managers who have to file a CSRD or ESRS disclosure and need Scope 3 figures that hold up under limited assurance and auditor sampling.
- Multi-entity groups that need every subsidiary measured under a single methodology, so the consolidated inventory is comparable from one reporting cycle to the next.
- Manufacturers, retailers and industrial groups whose Scope 3 sits in the physical goods they buy, where a category average can hide a factor of two between two similar products.
- Finance and controlling teams asked to stand behind a carbon number, who want the same audit trail they expect from a financial ledger: activity, supplier, factor, calculation, source document.
- Procurement and sourcing teams that want supplier carbon performance next to cost on the same line, in organisations with no data engineer to spare, since Bardo runs as a managed service.
When not to use Bardo
- Anyone looking for a self-service tool: there is no sign-up, no published price and no way in other than a sales meeting.
- Teams that want to own and operate the calculation themselves. Bardo is a managed service with, in its own words, no console to manage and no software to learn.
- Companies that want a fast, cheap spend-based estimate, or a better spreadsheet. Bardo deliberately refuses to multiply an amount spent by a sector factor.
- Banks, insurers and investors measuring financed emissions across a portfolio: the site itself sends that use case to Persefoni.
- Organisations that cannot pull together 500 to 1,000 invoices in a single category, which is the lightest entry point the site publishes.
How to use Bardo
A typical end-to-end flow, from setup to results.
- Book a slot through the site. Every button, whether 'Book a demo', 'Start a capability demo' or 'Talk to our team', opens the same HubSpot booking link; there is no online sign-up.
- Agree a capability demo: a sample of 500 to 1,000 invoices from a single category, run through the same pipeline as paying customers.
- Upload the files to the secure web dataroom, which loads directly into the Azure environment hosted in Sweden. PDF is preferred, other image formats are accepted.
- For a pilot, invoice access alone is enough. For a full delivery, add the accounting metadata (invoice coding) so results can be split by cost centre, business unit or subsidiary.
- Leave the data as it is. No restructuring or reformatting is asked of the customer; Bardo handles extraction and structuring.
- Read the returned slice of the footprint: a working section of the inventory, traceable line by line, built on real numbers from your own data.
- Move to a recurring transaction feed once the sample holds up, then to deeper API integrations with your existing systems.
- Work the review queue as questions arise: specialists respond within one business day, and critical exceptions are resolved within five business days.
- Take delivery each cycle: an activity list with factor and scope decisions per line, a locked snapshot, an auditor evidence pack and a full CSV export.
- Use the analytics to filter by cost centre, operating unit, supplier, product or category without a data analyst, and commission custom ERP integrations or off-roadmap features as a separate engagement if needed.
Pros & Cons
Pros
- End-to-end traceability: every tonne goes back to an invoice, which is exactly what limited assurance and auditor sampling need.
- The product-level method surfaces differences a category average hides, up to 2.06x between two monitors of the same category at similar prices, and it means cleaner purchasing choices actually read as lower emissions instead of being drowned in price inflation year on year.
- Factor quality is graded A to E, so the confidence behind each number is explicit rather than assumed.
- One methodology across every entity of a group, which makes CSRD consolidation comparable, and the methodology stays in the system instead of leaving with the person who carried it.
- Managed service: no data pipeline to maintain, no software to learn, and no data restructuring asked of the customer.
- Documented security posture: SOC 2 Type II, Swedish hosting on Azure, encryption, RBAC and MFA, immutable logs, plus a subprocessor list published and dated with change notification.
- Low-commitment entry point, a 500 to 1,000 invoice sample before any contract, and a subscription that includes methodology updates, factor database refreshes and regulatory adaptations.
Cons
- No public pricing of any kind: no pricing page, no tier and no amount anywhere in the site's pages or its 23-URL sitemap, so a budget cannot be scoped before a sales meeting.
- No terms and conditions and no legal notice are published, only a privacy policy, so the contractual relationship is not readable in advance. There is no contact page either: a footer mailto and a HubSpot booking link are the only routes in.
- The site contradicts itself on hosting: 'Nothing leaves the EU' on the security page sits alongside four subprocessors located in the United States in the published list (Twilio SendGrid, Exa.ai, Tavily, SerpAPI), under standard contractual clauses.
- The site contradicts itself on training: 'Customer data is never used for AI model training' sits alongside 'Human review labels are stored as training data' and 'Labeled examples flow into a training pipeline for the reasoning models'.
- ISO 27001 is announced as in progress, with certification work planned to complete this year. It is not held; only SOC 2 Type II is certified. The trust centre at trust.bardo.se renders nothing without JavaScript, so the security claims are only verifiable on the security page.
- A recent entrant, and the site says so itself: 'as a newer entrant, Bardo's integration library and public case studies are still growing'. No third-party connector is named, deeper API integrations are announced as a later stage, and there is no public API documentation.
- Entry is only through a sales appointment, with no self-service trial, and the interface is English only, with no other language announced.
Pricing & Plans
No amount is published. Bardo has no pricing page, and no price, tier or currency appears anywhere in the site's pages or in its 23-URL sitemap; access runs through a sales conversation. The model described is a subscription whose scope is set out on the methodology page: 'everything that keeps the platform current is included', meaning methodology updates, emission factor database refreshes and adaptations to regulatory change (CSRD, ESRS, GHG Protocol revisions), under the stated principle that 'You don't pay extra to stay compliant.' The analytics layer that identifies emission hotspots and reduction priorities is included as well. Some items sit outside that scope and are quoted separately: custom integrations to a specific ERP, features outside the roadmap, and customer-specific data residency arrangements on request. SSO is included in Enterprise contracts and is otherwise a paid option. The published entry step is a capability demo on 500 to 1,000 invoices, presented as commitment-free; the site never states that it is free of charge. No free plan and no free trial is announced.
- the site lists no tiers and no amounts
- and every route into the product is a sales conversation.
- the only contractual distinction named on the site. It includes SSO
- which is otherwise a paid add-on.
- the only entry step published
- run on a sample of 500 to 1
- 000 invoices from a single category
- with no price attached to it.
- sample first
- then a recurring feed of transactions
- then deeper API integrations.
- custom ERP integrations
- features outside the roadmap
- and data residency arrangements.
Data, GDPR & hosting
A consolidated view of how Bardo handles your data.
GDPR overview
GDPR compliance is claimed explicitly: 'GDPR compliant. DPA with SCCs where applicable.' The controller is Bardo Technology AB, registration number 559471-5954, Norra Stationsgatan 93a, 113 64 Stockholm, Sweden, and the privacy policy is dated 24 August 2026. Access, rectification, erasure, restriction, objection, portability and withdrawal of consent are exercised at info@bardo.se, answered within one month; an address that has objected is kept on a suppression list solely so it is not contacted again. The supervisory authority is the Swedish IMY, and breaches are notified within 72 hours. Storage is in the EU/EEA where possible, with US transfers under the EU-US Data Privacy Framework or standard contractual clauses. A DPA is available and the security team offers to work through the customer's own. No Article 27 representative is designated, and none is required for an EU-established company.
Who owns the data?
The site is explicit: 'Who owns the data? You do.' Bardo processes and stores customer data on the customer's behalf, and ownership does not transfer. Every activity and every calculation can be exported as Excel or CSV at any time. Legally, Bardo acts as processor for customer data and as controller for its own website and prospect data, under a separate DPA with standard contractual clauses where applicable. One published nuance is worth reading: generated emission factors and methodology improvements become part of the platform, while emission factors tailored to a specific business can be securely and exclusively controlled by that customer.
Reuse rights
Access is read-only, with no write-back to the customer's systems. Bardo reads accounts-payable metadata, purchase orders and supplier information, invoices and receipts in PDF, XML, EDI or image formats, and shipping and travel data. Processing excludes personally identifiable information; bank details and personal identifiers are masked at ingestion, and field-level rules govern exports and APIs with masking or pseudonymisation options. On model training the site publishes two statements that do not fully agree. The product pages state that 'customer data is never used for external model training', that 'Customer data is never used for AI model training', and that no third-party provider receives customer data with training rights, with reasoning models running in controlled environments. The security page then adds that 'Human review labels are stored as training data, but raw documents are not', and the methodology page that 'Labeled examples flow into a training pipeline for the reasoning models', new models running in shadow mode before promotion. So raw documents are excluded from training; the labels produced when a human reviews a case are not. Separately, website and prospect data is processed on legitimate interest, consent, contract or legal obligation, with contact data sourced from LinkedIn, LinkedIn Sales Navigator, employer sites, public registers and ZoomInfo. No personal data is sold.
Data retention & training
Hosting summary
The product is hosted in Sweden, on Microsoft Azure: 'All hosting and processing happens in Swedish-hosted Azure infrastructure. Nothing leaves the EU.' Customer-specific data residency is available on request. Encryption is TLS 1.2+ in transit and AES-256 at rest. A subprocessor list is published, effective 4 June 2026, with change notification. It places Azure, Google Cloud and AWS in Sweden, Auth0 in the EU (Frankfurt), New Relic and Linear in the EU, and Cloudflare on a global edge network where data stays at the nearest PoP, under SCCs and controller-to-processor BCRs. It also places four suppliers in the United States: Twilio SendGrid for transactional email, Exa.ai and Tavily for emission factor web search, and SerpAPI for travel queries, all under standard contractual clauses. So 'nothing leaves the EU' describes where the inventory lives, not where every subprocessor sits, and the site publishes both statements. Transfers outside the EU/EEA rely on the EU-US Data Privacy Framework or standard contractual clauses. Published vendor criteria: ISO 27001, SOC 2 Type II or equivalent, rights support, incident response, current SCCs.
Things to keep in mind
Risks and trade-offs to weigh before adopting Bardo.
- The site contradicts itself on hosting: the security page states 'Nothing leaves the EU', while the published subprocessor list places Twilio SendGrid, Exa.ai, Tavily and SerpAPI in the United States, under standard contractual clauses. Both statements are the publisher's own; ask which one governs your contract.
- The site contradicts itself on training: the product FAQ states 'Customer data is never used for AI model training', while the security page states that 'Human review labels are stored as training data' and the methodology page that 'Labeled examples flow into a training pipeline for the reasoning models'. Raw documents are excluded from training; the review labels are not.
- Exa.ai, Tavily and SerpAPI receive queries derived from customer activity data, including product names and descriptions and flight itineraries, for emission factor research. Customer-derived content therefore leaves for third-party search services.
- ISO 27001 is announced as in progress, not certified, and only hosting practices are described as aligned with it. Only SOC 2 Type II is actually held. The trust centre at trust.bardo.se, cited twice by the site as the source for controls and compliance status, is an empty JavaScript application without a browser, so the commitments are only verifiable on the security page.
- Neither terms and conditions nor a legal notice is published, and no price is either: the contractual relationship and the budget are both invisible until a sales conversation.
- Generated emission factors and methodology improvements become part of the platform; only factors tailored to a specific business can stay under the customer's exclusive control. Since Bardo runs as a managed service, the calculation expertise also sits with the vendor rather than being built inside the team, so it is worth checking what leaves with you if you leave.
- The domain bardo-technology.com is very recent, registered 29/04/2026 with a first Wayback capture on 10/06/2026, while the company has existed since 2024: do not read domain freshness as company age. Note also the outbound prospecting documented in the privacy policy, with ZoomInfo and LinkedIn Sales Navigator as sources of business contact data.
Setup & Integrations
Technical difficulty
Low technically, moderate organisationally. No technical skill is required: files are dropped into a web dataroom, no integration work is needed up front, there is no console to manage and no software to learn, and no data restructuring or formatting is asked of the customer. For a pilot, invoice access alone is enough. The real cost of entry is internal: extracting 500 to 1,000 invoices from one category, adding accounting metadata for a full delivery, which means involving finance, and agreeing scope, ownership and sequence. Deeper API integrations come later, possibly as a separate engagement.
Deployment
Behind Bardo
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Bardo.
Frequently asked questions
What data does Bardo need to get started?
Is a full integration needed on day one?
How does this differ from a spend-based method?
How is the quality of the calculation assured?
Are the results auditable?
Where is the data hosted?
Which certifications does Bardo hold?
Who owns the data, and is it used to train models?
How long is data kept, and is a DPA available?
What does Bardo cost?
Should you pick Bardo?
Bardo is a deliberately vertical tool: audit-ready carbon accounting for companies under CSRD obligations, not a general-purpose platform. The promise rests on one chain, invoice to product to supplier to emission factor, and on the A to E grading that makes the confidence behind each number visible. Where a category average would report two similar monitors at the same figure, the product-level calculation separates them by a factor of two, and that is the whole argument for the method.
It is delivered as a managed service. That means little work on the customer's side and, correspondingly, little hands-on control over the calculation: no console to run, no software to learn, no pipeline to maintain. Whether that reads as a feature or a limit depends on whether the team wants to own its methodology.
Credibility is reasonably documented: SOC 2 Type II, Swedish hosting on Azure, a subprocessor list published and dated, and named customers including Deloitte, Tele2, Storytel, Stegra, Bjare Kraft, First Camp, KEYTO and Ernstromgruppen.
The reservations are real and worth stating. No price is published anywhere. No terms and conditions exist on the site, only a privacy policy. ISO 27001 is in progress, not held. Bardo is a recent entrant and says so itself. And two of its own statements sit uneasily together: Nothing leaves the EU on the security page against four US-located subprocessors in the published list, and Customer data is never used for AI model training against human review labels stored as training data and labelled examples feeding a training pipeline. Neither is hidden, both are on the site, and a buyer should raise them.
The publisher proposes its own test, and it is fair: run a sample of your own invoices through and look at the numbers that come back.
- Choosing a selection results in a full page refresh.
- Opens in a new window.