Trust & Security

How we protect your data.

Complai is a compliance product, so we hold ourselves to the bar we help our customers hit. This page documents what we do today, what's in progress, and the direct contact path for security questions.

All systems operational Live status →
01

Encryption, everywhere

TLS 1.2+ in transit and AES-256 at rest on every primary store. No customer data leaves an encrypted channel.

02

Least-privilege access

Employee access to production data is role-scoped, audit-logged, and reviewed quarterly. MFA required for all admin surfaces.

03

Short sub-processor list

We use a deliberately small set of vendors. Every one is listed below with what it processes and a link to its DPA.