Under GHG Protocol, digital operational emissions sit inside Scope 3 Categories 1 and 8. Under ESRS E1 §46-51, IFRS S2 §29 and CDP C6.5, they must be substantiated with a defensible, source-linked method. In practice, almost no enterprise inventory captures the pre-consent slice, and no existing framework tells you how. This is the paper on how Pipelit closes that line.
Open method · CC-BY. UK grid intensity live from NESO. Reproducible from first principles by any external assurance provider.
“Across 46 UK enterprise sites, pre-consent tracker payload accounts for more than 500 tonnes of CO2e per year, a Scope 3 slice sitting inside Category 1 that no current inventory captures, and that no framework has told CSOs how to measure.”
The Ghost Carbon™ Report · A Pipelit Publication · read the full report
Scope 3 Categories 1 (purchased goods & services) and 8 (upstream leased assets) both contain digital operations. GHG Protocol acknowledges it. Every major disclosure standard requires it. And almost no CSO has a defensible number for it.
“Purchased goods and services include all upstream (cradle-to-gate) emissions from the production of products purchased by the reporting company”, digital services included.
Value-chain emissions must be disclosed “on a consistent basis and using a method that supports the level of assurance required.” Estimated proxies without source data will not pass limited assurance.
Scope 3 measurement must reflect activity data where available. For enterprises with digital-first operations, this includes traffic-level emissions data at operational granularity.
Reporting entities must disclose the methodology used to calculate each Scope 3 category. “Not measured” is a permitted answer, but it is scored, and it is public.
The whole cycle, measurement, remediation, verification, reporting, runs on the same open method, so the number the auditor sees in March is the same number the developer saw in October.
Every public URL scanned across Chrome, Firefox and Safari. Only the pre-consent tracker bytes are counted, not the page content, not consented analytics.
The waste is multiplied by the grid intensity of the jurisdiction where the visitor actually loaded the page, using the Open Grid feed.
Findings are given with the exact remediation, typically a tag manager firing rule. Reduction, not just reporting.
Every scan produces a report and a raw dataset. Both are exportable, both are reproducible from the CC-BY method by an external assurance provider.
Every scan produces exactly what a limited assurance engagement needs to walk your figure: the reproducible calculation and the raw data trail underneath it.
A one-page assurance package: figure, method reference, calculation trail, and the grid intensity used at measurement time.
Per-request byte counts, tracker classification, jurisdiction resolution, and per-minute grid intensity used in the calculation. Suitable for an assurance provider to sample.