HomeSecurity & Trust
Security & Trust Center

We hold ourselves to the
standards we help you achieve.

Complify is a GRC platform. That means our own security posture is held to the highest standard — certified, tested, and transparent. Everything you need to complete your vendor due diligence is on this page.

ISO 27001
Certified · 2022
SOC 2
Type II · Annual
ISO 27701
Certified · 2025
99.98%
Uptime SLA
Certifications & Attestations

Independently verified.
Every year.

ISO 27001 : 2022
Auditor: BSI Group
Scope: Development, operation, and support of the Complify GRC platform
Last renewed: March 2025
Request certificate copy →
SOC 2 Type II
Auditor: Deloitte & Touche LLP
Scope: Security, Availability, and Confidentiality Trust Services Criteria
Last renewed: December 2024
Request certificate copy →
ISO 27701 : 2025
Auditor: Bureau Veritas
Scope: Privacy Information Management System for EU customer data processing
Last renewed: January 2026
Request certificate copy →
Security Controls

How we protect your data.

🔐Encryption & Data Protection
  • AES-256 encryption at rest for all customer data
  • TLS 1.3 in transit — no older protocols accepted
  • Separate encryption keys per customer tenant
  • Hardware Security Module (HSM) for key management
  • Database-level field encryption for sensitive fields
👤Access Control & Identity
  • SSO with SAML 2.0 and OIDC (Okta, Azure AD, Google)
  • MFA enforced for all Complify staff — no exceptions
  • Zero-trust network access for internal systems
  • Quarterly access reviews with automatic deprovisioning
  • Privileged access management (PAM) for production systems
🌐Network & Infrastructure Security
  • AWS VPC with private subnets — no public-facing databases
  • WAF (Web Application Firewall) on all ingress points
  • DDoS protection via AWS Shield Advanced
  • Network segmentation between tenant environments
  • Automated intrusion detection (GuardDuty + custom SIEM rules)
💾Backup, Recovery & BCP
  • Automated daily backups with 90-day retention
  • Point-in-time recovery for the last 35 days
  • Cross-region backup replication (EU-West → EU-Central)
  • RTO: 4 hours / RPO: 1 hour for full platform restoration
  • BCP tested quarterly — last test: January 2026
Availability & SLA

99.98% uptime.
Not a target — a record.

99.98%
Uptime — last 12 months
< 90ms
Average API response time
3
Minor incidents — last 12 months
0
Major outages — last 12 months
Service Availability — Last 12 Months
Platform (Web App)99.98%
API99.99%
Evidence Collection99.95%
Report Generation99.97%
Notifications100%
Incident History — Last 12 Months
2025-11-14
23 minResolved

Elevated latency on Evidence Collection service — database query optimization required. All data integrity maintained.

2025-08-03
41 minResolved

Partial disruption to email notifications due to upstream Mailgun degradation. No data loss; notifications re-queued.

2025-04-19
18 minPlanned

Scheduled maintenance window — database version upgrade. Customer notified 14 days in advance.

Customer-Side Controls

Security controls you control.

🔒
SSO & MFA Enforcement

Enforce SSO via your corporate IdP and mandate MFA for all users. Complify supports SAML 2.0 and OIDC — integrate with Okta, Azure AD, Google Workspace, or any compliant provider.

👥
Role-Based Access Control

Granular RBAC with custom roles. Define who can view, edit, approve, and export — at the platform level, module level, and individual document level. Full audit trail of every access decision.

📋
Audit Logs & SIEM Export

Complete, immutable audit logs of all user actions, system events, and data access. Export to your SIEM in real time via webhook or API — Splunk, Datadog, Elastic, Microsoft Sentinel supported.

🌍
Data Residency Selection

SaaS customers choose their primary data residency region at onboarding — EU (Ireland + Frankfurt), US (Virginia + Oregon), or APAC (Singapore + Sydney). Region cannot be changed post-onboarding without migration.

📤
Data Export & Portability

Export all your compliance data at any time in structured JSON or PDF format. No lock-in — your evidence, policies, risk registers, and audit logs are yours and always exportable on request.

🗑️
Data Deletion & Retention

Configure data retention policies per module. On contract termination, all customer data is securely deleted within 30 days with a deletion certificate provided. Compliant with GDPR Art. 17 right to erasure.

Security Contacts

Talk to our security team.

For security questionnaires, penetration test reports, or due diligence reviews, contact our security team directly. We respond to all security inquiries within one business day.

🔒
Vulnerability Disclosure
security@complify.io
📋
Security Questionnaires
trust@complify.io
⚖️
Data Protection / DPA
privacy@complify.io
Security Review

Request a security review.

Our security team will walk you through Complify's controls, answer your questionnaire, and provide any documentation needed for your vendor due diligence process.