These are the questions a security or certification team asks a new supplier. Every answer is read from the application's code, from the running application or from the pages it links to, on the date below. Where we have not read something, the answer says so instead of guessing.
2026-10-06 · read from the application's code (commit b1597e4) and the running application
These are the companies that process something on our behalf, and what reaches each one. The field-by-field list, with the file in the code each row was read from, is on the subprocessors page.
Your workspace — the database and the files you upload — is stored in Frankfurt, in Supabase's eu-central-1 region. The application's server functions run in Frankfurt, in Vercel's fra1 region, as read from the application's configuration on 2026-10-06. Email is sent through Resend from Ireland.
You cannot choose another region today.
Anthropic's Data Processing Addendum, the version effective 2025-02-24, read on 2026-10-06, says: “Anthropic utilizes industry standard encryption methods for protection of Customer Data, including a minimum of AES-256 for data at rest, and TLS1.2+ for data in transit over public networks.”
We have not read where Vercel stores its own platform log, or where Anthropic, Perplexity and Stripe process what reaches them.
How each region was readAnthropic's Data Processing Addendum
Complipath does not train or fine-tune any model. The application uses a language model only to read and write text. Its code contains no training or fine-tuning call.
No language model decides a classification. The risk level comes from rules in code, so the same answers always give the same result.
Anthropic's Commercial Terms of Service, the version effective 2025-06-17, read on 2026-10-06, say: “Anthropic may not train models on Customer Content from Services.” In those terms, Customer Content is what is submitted to Anthropic's services and the responses they generate.
We have not read Perplexity's terms on training, so this page claims nothing about Perplexity either way.
What reaches Anthropic and Perplexity, path by pathAnthropic's Commercial Terms of Service
Everything in your workspace is kept for as long as the workspace exists. There is no expiry, and it is deleted with the workspace.
Settings → Data & privacy → Download everything gives you every table your workspace holds as one JSON file, at any time and on every plan. The register also exports as CSV, JSON or PDF, each assessment as a file, the technical documentation as a PDF, and your evidence files as a ZIP.
The workspace owner can delete the workspace in Settings → Data & privacy. The app first shows what will be removed, then removes the workspace, everything in it and the files you uploaded. Nothing in the app can bring it back. You can also ask us at hello@complipath.io, and we delete your workspace within 30 days.
Deleting the workspace does not remove the sign-in identity of each person — their email address in the sign-in system. Cancelling a plan deletes nothing.
We have not read how long our database and hosting providers keep their own logs and backups.
As of 2026-10-06, read on the served sign-in and sign-up pages: you sign in with Google, with your email address and a password of at least 10 characters, or with a one-time link sent to your email address. The link works once and expires after one hour. Sign-in is handled by Supabase.
Two-step sign-in is available on every plan, in Settings → Security: after you sign in, a code from an authenticator app on your phone. Each person gets ten one-time recovery codes, and we store only their hashes. It is optional unless the workspace owner requires it for everyone.
A workspace has two roles, Owner and Member. Every person in a workspace sees every system; there are no per-system permissions yet. Members can add, change and delete systems. Only the owner can change the workspace, invite people and delete the workspace.
Each workspace's rows are separated in the database by row-level security policies tied to the signed-in person's own organisation.
The application keeps an activity log of who did what, and when. On Starter and in the trial, the workspace reads it in Settings → Audit log, filters it and exports it as CSV. No member can edit or delete a line, an owner included: the log grants reading and adding, nothing else, as read in the production database on 8 October 2026. Deleting the workspace removes it with everything else. For a customer's security review, you can share a read-only link to your whole register; you can revoke it, and every view is logged.
Write to hello@complipath.io. It is read by the founder, Yobel Tzegai.
There is no separate security address and no security.txt file today.
Complipath is not SOC 2 certified and not ISO 27001 certified.
We do not offer a signed data processing agreement yet. A draft exists and is being reviewed before we offer it.