Single-tenant & customer-owned
ComposIQ deploys as an Azure Managed Application into your own subscription. There is no shared multi-tenant backend — your instance is yours alone.
Trust Center
ComposIQ is private AI that runs entirely inside your own Azure subscription — single-tenant, zero-egress, and customer-owned. This is where we document how we protect your data, the architecture that enforces it, and the privacy and compliance commitments behind it.
Security architecture
The controls below are properties of the deployment model, not policies we ask you to take on faith.
ComposIQ deploys as an Azure Managed Application into your own subscription. There is no shared multi-tenant backend — your instance is yours alone.
The deployment is locked down with private endpoints and network controls, so your documents and prompts are not sent out to third-party services.
Data is encrypted in transit with TLS and at rest using Azure platform encryption across storage, database, and key management.
Interactions are recorded to a tamper-evident, WORM-style audit ledger with hash chaining, so activity can be independently verified.
Access is governed through your organization's identity provider with role-based access control, keeping authorization inside your boundary.
Resources communicate over private networking within your tenant, minimizing public exposure of the platform's data plane.
Subprocessors
ComposIQ runs inside your own Azure tenant, so we do not receive, store, or process your content. Every service below is a Microsoft Azure resource deployed into your own subscription as part of the ComposIQ application.
| Sub-processor | Azure service | Role in ComposIQ |
|---|---|---|
| Microsoft | Azure Cosmos DB | Application data, audit index, payload key material (per deployment architecture) |
| Microsoft | Azure Blob Storage | Documents, tamper-evident audit ledger, payloads, manifests |
| Microsoft | Azure OpenAI Service | Chat completions, embeddings (inference only; no training on customer data per Microsoft and Publisher terms) |
| Microsoft | Azure Key Vault | Secrets, certificates, cryptographic key management |
| Microsoft | Azure Container Apps | Application runtime and scaling |
| Microsoft | Azure Container Registry | Container images for the application |
| Microsoft | Azure Virtual Network, NSG, Route Table | Networking isolation and egress controls |
| Microsoft | Azure Application Gateway | HTTPS ingress and WAF when the Public Access plan is selected |
| Microsoft | Azure Private Link / Private DNS | Private connectivity to PaaS endpoints |
| Microsoft | Azure Log Analytics | Operational logs and diagnostics within the tenant (workspace deployed with the application) |
| Microsoft | Azure Monitor (diagnostic settings) | Resource metrics and logs routed to Log Analytics within the tenant |
| Microsoft | Microsoft Entra ID | Authentication and directory integration (customer-controlled) |
We notify customers of changes to this list in advance of a new subprocessor being engaged. To be notified, contact support@sparkshare.io.
Privacy
We are a software vendor, not a data processor — there is nothing for us to collect, retain, or transfer.
Because processing happens in your tenant, ComposIQ does not aggregate your content into an external corpus or use it to train shared models.
The data lifecycle is controlled within your environment, supporting your own retention and deletion obligations.
Our subprocessor list documents the limited services involved in operating the platform.
Documents