Skip to main content

Security Built Into Every Layer

Your compliance data is among the most sensitive information your firm handles. We protect it with the same rigor you apply to your regulatory obligations.

AES-256

Encryption at rest

TLS

Encryption in transit

MFA

Authenticator-app 2FA

Data Encryption

  • AES-256 encryption for all data at rest, including database storage, file storage, and backups (Google Cloud managed encryption)
  • TLS 1.2/1.3 for all traffic between your browser and the platform; plaintext HTTP is not served
  • Database reachable only over a private VPC address inside our Google Cloud project — it has no public IP
  • MFA secrets and SSO client secrets are additionally encrypted with AES-256-GCM before they are stored

Access Controls

  • Role-based access control with 8 roles (employee, access person, compliance analyst, compliance reviewer, CCO, firm admin, read-only auditor, platform admin)
  • Per-tenant data isolation — every query is scoped to your firm; data is never shared across organizations
  • Multi-factor authentication (authenticator app, RFC 6238 TOTP) with one-time backup codes, available to every user
  • Passwords hashed with bcrypt (cost 12); minimum 12 characters with complexity requirements; failed-login lockout
  • SSO via SAML 2.0 or OpenID Connect (Microsoft Entra ID, Okta, Google Workspace, or any compatible provider) on Enterprise plans

Infrastructure

  • Hosted on Google Cloud Platform (Cloud Run, Cloud SQL, Cloud Storage, Memorystore) in the us-central1 region (United States)
  • Cloud SQL (PostgreSQL 16) with automated daily backups, 7 retained, and 7 days of transaction logs
  • Auto-scaling Cloud Run services; the background worker is not reachable from the internet
  • Rate limiting on every API endpoint, with tighter limits on sign-in, sign-up, uploads, and AI analysis
  • Security headers on every response: HSTS, Content-Security-Policy, X-Frame-Options DENY, X-Content-Type-Options nosniff

Audit Logging

  • Every create, update, delete, sign-in, and approval is recorded with timestamp, user, client IP address, user agent, and before/after state
  • Audit logs are scoped to your firm, searchable and filterable, and exportable for examinations
  • Audit entries are retained for the life of your subscription and cannot be edited or deleted through the application
  • Published policy versions are archived with a SHA-256 hash you can re-verify at any time

Session Management

  • Access tokens expire after 30 minutes; refresh tokens after 7 days and are rotated on every refresh
  • Automatic sign-out after 15 minutes of inactivity
  • Tokens are revoked on sign-out and on password reset; you can see and revoke your other active sessions under Settings → Security

Data Handling

  • Multi-tenant architecture with strict tenant-scoped database queries
  • Uploaded files are stored in Google Cloud Storage with uniform bucket-level access; no public access
  • Export your records at any time for portability and regulatory recordkeeping
  • Payment card data is handled by Stripe and never stored on our systems
  • A current list of subprocessors and our written information security program are available on request

Security Contact

We welcome security inquiries from customers, prospects, and researchers. Every report is reviewed by our security lead (our founder serves as acting CISO) and acknowledged within one business day.

Report a Vulnerability

Found a security issue? Please report it responsibly by email. Include steps to reproduce and any proof-of-concept details.

security@complianceapproved.com →

Vendor Security Questionnaire

Evaluating Compliance Approved for your firm? We can provide our security documentation under a mutual NDA.

Request documentation →

Responsible Disclosure

  • Give us reasonable time to investigate and remediate before public disclosure
  • Do not access, modify, or destroy data belonging to other customers
  • Do not perform testing that could degrade service availability for others
  • We will acknowledge your report within one business day and keep you updated on remediation

Our published security contact information follows RFC 9116 and is available at /.well-known/security.txt.

Ready to transform your compliance workflow?

Be among the first to experience AI-powered compliance technology.