Your data stays in your tenant.

ComposIQ is private AI that runs entirely inside your own Azure subscription — single-tenant, zero-egress, and customer-owned. This is where we document how we protect your data, the architecture that enforces it, and the privacy and compliance commitments behind it.

Effective

Security architecture

Built so your data never leaves your control

The controls below are properties of the deployment model, not policies we ask you to take on faith.

Single-tenant & customer-owned

ComposIQ deploys as an Azure Managed Application into your own subscription. There is no shared multi-tenant backend — your instance is yours alone.

Zero-egress by design

The deployment is locked down with private endpoints and network controls, so your documents and prompts are not sent out to third-party services.1

Encryption in transit & at rest

Data is encrypted in transit with TLS and at rest using Azure platform encryption across storage, database, and key management.

Tamper-evident audit logging

Interactions are recorded to a hash-chained audit ledger, so gaps, reordering, or alteration of records are detectable and activity can be independently verified.

Identity & access control

Access is governed through your organization's identity provider with role-based access control, keeping authorization inside your boundary.

Private networking

Resources communicate over private networking within your tenant, minimizing public exposure of the platform's data plane.

1 Zero-egress describes the deployment boundary: ComposIQ makes no calls to sparkshare.io Corp servers, external analytics services, or third-party APIs, and your documents and prompts are not sent to any non-Microsoft service. Model inference is performed by Azure OpenAI Service, which is deployed into your subscription and reached over a private endpoint. The Azure Marketplace default is a GlobalStandard model deployment, under which Microsoft may process prompts and responses in any geography where Microsoft has deployed the model, subject to Microsoft's Azure OpenAI data, privacy, and security commitments — including that customer data is not used to train models. See our App Privacy Policy for the full disclosure, and contact us to discuss deployment options with narrower processing geography.

Subprocessors

Who we work with

ComposIQ runs inside your own Azure tenant, so we do not receive, store, or process your content. Every service below is a Microsoft Azure resource deployed into your own subscription as part of the ComposIQ application.

Subprocessor Azure service Role in ComposIQ
Microsoft Azure Cosmos DB Application data, audit index, payload key material (per deployment architecture)
Microsoft Azure Blob Storage Documents, tamper-evident audit ledger, payloads, manifests
Microsoft Azure OpenAI Service Chat completions, embeddings (inference only; no training on customer data per Microsoft and Publisher terms). See the note on model deployment geography.
Microsoft Azure Key Vault Secrets, certificates, cryptographic key management
Microsoft Azure Container Apps Application runtime and scaling
Microsoft Azure Container Registry Container images for the application
Microsoft Azure Virtual Network, NSG, Route Table Networking isolation and egress controls
Microsoft Azure Application Gateway HTTPS ingress and WAF when the Public Access plan is selected
Microsoft Azure Private Link / Private DNS Private connectivity to PaaS endpoints
Microsoft Azure Log Analytics Operational logs and diagnostics within the tenant (workspace deployed with the application)
Microsoft Azure Monitor (diagnostic settings) Resource metrics and logs routed to Log Analytics within the tenant
Microsoft Microsoft Entra ID Authentication and directory integration (customer-controlled)

Microsoft is our only subprocessor. The table above lists the Azure services that store, process, or transport your content; the deployment also creates supporting identity, monitoring, and networking resources that are not listed individually. All of them are Microsoft services running in your own subscription, where you can enumerate them directly, and the complete resource inventory is included in the security package available on request.

We notify customers of changes to this list in advance of a new subprocessor being engaged. To be notified, contact support@sparkshare.io.

Documents

Policies & legal