Trust

Compliancy holds sensitive information about how organisations operate. This page explains how we protect it, what we commit to, and where to find supporting documentation.

Security

Compliancy runs the security practices we expect our customers to run: access control with least privilege, encryption in transit and at rest, logging, change management and periodic review.

  • Role-based access with least privilege
  • Encryption in transit and at rest
  • Change approval before production release
  • Logging and monitoring of platform activity
  • Regular review of access and vendors

Privacy

We process customer data to provide the platform. We do not sell personal data. Our privacy notice describes what we collect, why, and how long we retain it.

Our own compliance posture

We publish our current posture rather than implying certifications we do not hold. Where an assessment is in progress, we say so, and we share available documentation under NDA on request.

Data handling

Customer data is logically separated per organisation. Retention and deletion behaviour is described in our data processing agreement, and deletion requests are honoured within the agreed timeframes.

Subprocessors

We maintain a current list of subprocessors used to deliver the service, including the purpose of each and where processing takes place.

Availability

Platform availability and incident history are published on our status page. Incidents affecting customer data are communicated directly to affected customers.

Reporting a vulnerability

Security researchers and customers can report suspected vulnerabilities to security@compliancy.example.com. We acknowledge reports and keep reporters informed while we investigate.