Single-tenant & customer-owned
ComposIQ deploys as an Azure Managed Application into your own subscription. There is no shared multi-tenant backend — your instance is yours alone.
ComposIQ is private AI that runs entirely inside your own Azure subscription — single-tenant, zero-egress, and customer-owned. This is where we document how we protect your data, the architecture that enforces it, and the privacy and compliance commitments behind it.
Security architecture
The controls below are properties of the deployment model, not policies we ask you to take on faith.
ComposIQ deploys as an Azure Managed Application into your own subscription. There is no shared multi-tenant backend — your instance is yours alone.
The deployment is locked down with private endpoints and network controls, so your documents and prompts are not sent out to third-party services.1
Data is encrypted in transit with TLS and at rest using Azure platform encryption across storage, database, and key management.
Interactions are recorded to a hash-chained audit ledger, so gaps, reordering, or alteration of records are detectable and activity can be independently verified.
Access is governed through your organization's identity provider with role-based access control, keeping authorization inside your boundary.
Resources communicate over private networking within your tenant, minimizing public exposure of the platform's data plane.
1 Zero-egress describes the deployment boundary: ComposIQ makes no calls to sparkshare.io Corp servers, external analytics services, or third-party APIs, and your documents and prompts are not sent to any non-Microsoft service. Model inference is performed by Azure OpenAI Service, which is deployed into your subscription and reached over a private endpoint. The Azure Marketplace default is a GlobalStandard model deployment, under which Microsoft may process prompts and responses in any geography where Microsoft has deployed the model, subject to Microsoft's Azure OpenAI data, privacy, and security commitments — including that customer data is not used to train models. See our App Privacy Policy for the full disclosure, and contact us to discuss deployment options with narrower processing geography.
Subprocessors
ComposIQ runs inside your own Azure tenant, so we do not receive, store, or process your content. Every service below is a Microsoft Azure resource deployed into your own subscription as part of the ComposIQ application.
| Subprocessor | Azure service | Role in ComposIQ |
|---|---|---|
| Microsoft | Azure Cosmos DB | Application data, audit index, payload key material (per deployment architecture) |
| Microsoft | Azure Blob Storage | Documents, tamper-evident audit ledger, payloads, manifests |
| Microsoft | Azure OpenAI Service | Chat completions, embeddings (inference only; no training on customer data per Microsoft and Publisher terms). See the note on model deployment geography. |
| Microsoft | Azure Key Vault | Secrets, certificates, cryptographic key management |
| Microsoft | Azure Container Apps | Application runtime and scaling |
| Microsoft | Azure Container Registry | Container images for the application |
| Microsoft | Azure Virtual Network, NSG, Route Table | Networking isolation and egress controls |
| Microsoft | Azure Application Gateway | HTTPS ingress and WAF when the Public Access plan is selected |
| Microsoft | Azure Private Link / Private DNS | Private connectivity to PaaS endpoints |
| Microsoft | Azure Log Analytics | Operational logs and diagnostics within the tenant (workspace deployed with the application) |
| Microsoft | Azure Monitor (diagnostic settings) | Resource metrics and logs routed to Log Analytics within the tenant |
| Microsoft | Microsoft Entra ID | Authentication and directory integration (customer-controlled) |
Microsoft is our only subprocessor. The table above lists the Azure services that store, process, or transport your content; the deployment also creates supporting identity, monitoring, and networking resources that are not listed individually. All of them are Microsoft services running in your own subscription, where you can enumerate them directly, and the complete resource inventory is included in the security package available on request.
We notify customers of changes to this list in advance of a new subprocessor being engaged. To be notified, contact support@sparkshare.io.
Documents