High-risk evidence should leave your boundary as little as possible.
This page is maintained by Compliance Now to answer common security and privacy questions about how we handle your compliance evidence. We separate what we store from what we attest to, by risk tier.
Our position
EU AI Act high-risk evidence (Annex IV technical documentation, model internals, training-data summaries, FRIA artifacts) is the most sensitive material a compliance platform touches. Our preferred mode for that tier is no-file custody — evidence stays in your S3, Snowflake, or SharePoint; we connect read-only and store only a content hash and pointer. Where customers prefer hosted storage, we offer EU-resident, encrypted, BYO-key-optional storage instead.
Free & Starter — metadata-first
Free tier stores no files at all. Starter and Pro use an in-app evidence vault scoped per user, with row-level security and per-file signed download URLs.
Pro — in-app vault
Encrypted at rest. Signed URLs for downloads. Files are scoped to your account; cross-tenant access is blocked at the database level.
Business — hosted, regional
EU-resident storage, customer-managed encryption keys optional, published sub-processor list, and a Data Processing Addendum signed at order.
Enterprise — BYO-storage / no-file
Connect your own S3 / Snowflake / SharePoint. Evidence never leaves your boundary. We index content hashes, pointer URIs, and attestation signatures only.
Platform security today
- All traffic over HTTPS. Authentication tokens are short-lived and rotated.
- Database access is gated by row-level security; every record carries an owner ID and is queryable only by that owner.
- Evidence storage is a private bucket — no public URLs. Downloads require a signed URL that expires.
- Password reset, email confirmation, and OAuth flows go through managed identity infrastructure with industry-standard hashing.
Roadmap commitments
- SOC 2 Type I — target Q1 2027.
- SOC 2 Type II — follows Type I.
- Published sub-processor list and EU residency disclosure — Release 2.
- BYO-storage connectors for S3, Snowflake, SharePoint — Release 2 with the high-risk module.
Compliance Now is not currently SOC 2 or ISO 27001 certified. This page describes what's enabled today and what's funded next. Builder-stated facts; not an independent attestation.