Trust Center

Your data stays in your tenant.

ComposIQ is private AI that runs entirely inside your own Azure subscription โ€” single-tenant, zero-egress, and customer-owned. This is where we document how we protect your data, the architecture that enforces it, and the privacy and compliance commitments behind it.

Security architecture

Built so your data never leaves your control

๐Ÿ 

Single-tenant & customer-owned

ComposIQ deploys as an Azure Managed Application into your own subscription. There is no shared multi-tenant backend โ€” your instance is yours alone.

๐Ÿšซ

Zero-egress by design

The deployment is locked down with private endpoints and network controls so your documents and prompts are not sent out to third-party services.

๐Ÿ”

Encryption in transit & at rest

Data is encrypted in transit (TLS) and at rest using Azure platform encryption across storage, database, and key management.

๐Ÿ“œ

Immutable audit ledger

Interactions are recorded to a tamper-evident, WORM-style audit ledger with hash chaining, so activity can be independently verified.

๐Ÿ‘ค

Identity & access control

Access is governed through your organization's identity provider with role-based access control, keeping authorization inside your boundary.

๐Ÿงญ

Private networking

Resources communicate over private networking within your tenant, minimizing public exposure of the platform's data plane.

Compliance

Frameworks we design and operate toward

SOC 2 (Security, Availability, Confidentiality)
Trust Services Criteria alignment.
STATUS โ€” UPDATE
HIPAA
Architecture supports safeguards for PHI in healthcare deployments.
SUPPORTED
GDPR / UK GDPR
Data-residency-in-tenant and DPA available for EU/UK customers.
SUPPORTED
NIST 800-53 / CSF
Control alignment for zero-trust, audit, and access.
ALIGNED
FedRAMP / StateRAMP
Government deployment posture.
STATUS โ€” UPDATE
FERPA
Education-record handling for K-12 and higher-ed deployments.
SUPPORTED

Privacy

Privacy by design

๐Ÿงพ

Data minimization

Because processing happens in your tenant, ComposIQ does not aggregate your content into an external corpus or use it to train shared models.

โฑ๏ธ

Retention & deletion

Data lifecycle is controlled within your environment, supporting your retention and deletion obligations.

๐Ÿค

Transparent subprocessors

Our subprocessor list documents the limited services involved in operating the platform.

Documents

Policies & legal

Security or compliance question?

Request our security package, a DPA, or a completed questionnaire (CAIQ / SIG / HECVAT).

Contact the security team