Trust Center

Your data stays in your tenant.

ComposIQ is private AI that runs entirely inside your own Azure subscription — single-tenant, zero-egress, and customer-owned. This is where we document how we protect your data, the architecture that enforces it, and the privacy and compliance commitments behind it.

Security architecture

Built so your data never leaves your control

The controls below are properties of the deployment model, not policies we ask you to take on faith.

Single-tenant & customer-owned

ComposIQ deploys as an Azure Managed Application into your own subscription. There is no shared multi-tenant backend — your instance is yours alone.

Zero-egress by design

The deployment is locked down with private endpoints and network controls, so your documents and prompts are not sent out to third-party services.

Encryption in transit & at rest

Data is encrypted in transit with TLS and at rest using Azure platform encryption across storage, database, and key management.

Immutable audit ledger

Interactions are recorded to a tamper-evident, WORM-style audit ledger with hash chaining, so activity can be independently verified.

Identity & access control

Access is governed through your organization's identity provider with role-based access control, keeping authorization inside your boundary.

Private networking

Resources communicate over private networking within your tenant, minimizing public exposure of the platform's data plane.

Subprocessors

Who we work with

ComposIQ runs inside your own Azure tenant, so we do not receive, store, or process your content. Every service below is a Microsoft Azure resource deployed into your own subscription as part of the ComposIQ application.

Sub-processor Azure service Role in ComposIQ
Microsoft Azure Cosmos DB Application data, audit index, payload key material (per deployment architecture)
Microsoft Azure Blob Storage Documents, tamper-evident audit ledger, payloads, manifests
Microsoft Azure OpenAI Service Chat completions, embeddings (inference only; no training on customer data per Microsoft and Publisher terms)
Microsoft Azure Key Vault Secrets, certificates, cryptographic key management
Microsoft Azure Container Apps Application runtime and scaling
Microsoft Azure Container Registry Container images for the application
Microsoft Azure Virtual Network, NSG, Route Table Networking isolation and egress controls
Microsoft Azure Application Gateway HTTPS ingress and WAF when the Public Access plan is selected
Microsoft Azure Private Link / Private DNS Private connectivity to PaaS endpoints
Microsoft Azure Log Analytics Operational logs and diagnostics within the tenant (workspace deployed with the application)
Microsoft Azure Monitor (diagnostic settings) Resource metrics and logs routed to Log Analytics within the tenant
Microsoft Microsoft Entra ID Authentication and directory integration (customer-controlled)

We notify customers of changes to this list in advance of a new subprocessor being engaged. To be notified, contact support@sparkshare.io.

Privacy

Privacy by design

We are a software vendor, not a data processor — there is nothing for us to collect, retain, or transfer.

Data minimization

Because processing happens in your tenant, ComposIQ does not aggregate your content into an external corpus or use it to train shared models.

Retention & deletion

The data lifecycle is controlled within your environment, supporting your own retention and deletion obligations.

Transparent subprocessors

Our subprocessor list documents the limited services involved in operating the platform.

Documents

Policies & legal