Security review

What your security team will ask us, answered

These are the questions a security or certification team asks a new supplier. Every answer is read from the application's code, from the running application or from the pages it links to, on the date below. Where we have not read something, the answer says so instead of guessing.

2026-10-06 · read from the application's code (commit b1597e4) and the running application

Download this page as a PDF

Which companies see your data, which fields and where do they run?

These are the companies that process something on our behalf, and what reaches each one. The field-by-field list, with the file in the code each row was read from, is on the subprocessors page.

CompanyWhat we use it forWhat reaches itWhere it runs
SupabaseDatabase, sign-in and file storageEvery table of your workspace, the sign-in identity of each person, and the files you upload as evidence or documentationFrankfurt (eu-central-1)
VercelHosting and the application's server functionsThe address of each page you open, your IP address and browser, and what you submit in formsServer functions in Frankfurt (fra1). Where Vercel keeps its own platform log: not read
AnthropicA language model that reads and writes text: reading a website in the free check, suggesting answers and system names, drafting documentation, the writing aid, the assistant, reading files you upload and comparing a system's own texts for contradictionsDepending on the feature: the domain you type and the text of your public pages; descriptions you type; a system's fields, your stored answers and documentation sections; the text of files you upload as documentation or evidence; your questions to the assistant with a summary of your registerNot read
PerplexityOne web search in the free check, before any account existsThe domain you typeNot read
ResendSending emailYour email address; workspace and system names in the letters; feedback and requests you write to usIreland (eu-west-1)
StripeTaking paymentYour workspace's identifier and the plan you choose; the billing details you type on Stripe's own page. Nothing from your registerNot read
CalendlyBooking a call from this website, not from the productYour name, email address, time zone and the answers in the booking formNot read

Where is your data stored?

Your workspace — the database and the files you upload — is stored in Frankfurt, in Supabase's eu-central-1 region. The application's server functions run in Frankfurt, in Vercel's fra1 region, as read from the application's configuration on 2026-10-06. Email is sent through Resend from Ireland.

You cannot choose another region today.

Anthropic's Data Processing Addendum, the version effective 2025-02-24, read on 2026-10-06, says: “Anthropic utilizes industry standard encryption methods for protection of Customer Data, including a minimum of AES-256 for data at rest, and TLS1.2+ for data in transit over public networks.”

We have not read where Vercel stores its own platform log, or where Anthropic, Perplexity and Stripe process what reaches them.

Is your data used to train AI models?

Complipath does not train or fine-tune any model. The application uses a language model only to read and write text. Its code contains no training or fine-tuning call.

No language model decides a classification. The risk level comes from rules in code, so the same answers always give the same result.

Anthropic's Commercial Terms of Service, the version effective 2025-06-17, read on 2026-10-06, say: “Anthropic may not train models on Customer Content from Services.” In those terms, Customer Content is what is submitted to Anthropic's services and the responses they generate.

We have not read Perplexity's terms on training, so this page claims nothing about Perplexity either way.

How long do you keep data, and how do you take it out and delete it?

Everything in your workspace is kept for as long as the workspace exists. There is no expiry, and it is deleted with the workspace.

Settings → Data & privacy → Download everything gives you every table your workspace holds as one JSON file, at any time and on every plan. The register also exports as CSV, JSON or PDF, each assessment as a file, the technical documentation as a PDF, and your evidence files as a ZIP.

The workspace owner can delete the workspace in Settings → Data & privacy. The app first shows what will be removed, then removes the workspace, everything in it and the files you uploaded. Nothing in the app can bring it back. You can also ask us at hello@complipath.io, and we delete your workspace within 30 days.

Deleting the workspace does not remove the sign-in identity of each person — their email address in the sign-in system. Cancelling a plan deletes nothing.

We have not read how long our database and hosting providers keep their own logs and backups.

How do people sign in, and who can see what?

As of 2026-10-06, read on the served sign-in and sign-up pages: you sign in with Google, with your email address and a password of at least 10 characters, or with a one-time link sent to your email address. The link works once and expires after one hour. Sign-in is handled by Supabase.

Two-step sign-in is available on every plan, in Settings → Security: after you sign in, a code from an authenticator app on your phone. Each person gets ten one-time recovery codes, and we store only their hashes. It is optional unless the workspace owner requires it for everyone.

A workspace has two roles, Owner and Member. Every person in a workspace sees every system; there are no per-system permissions yet. Members can add, change and delete systems. Only the owner can change the workspace, invite people and delete the workspace.

Each workspace's rows are separated in the database by row-level security policies tied to the signed-in person's own organisation.

The application keeps an activity log of who did what, and when. On Starter and in the trial, the workspace reads it in Settings → Audit log, filters it and exports it as CSV. No member can edit or delete a line, an owner included: the log grants reading and adding, nothing else, as read in the production database on 8 October 2026. Deleting the workspace removes it with everything else. For a customer's security review, you can share a read-only link to your whole register; you can revoke it, and every view is logged.

Who do you contact about a security incident?

Write to hello@complipath.io. It is read by the founder, Yobel Tzegai.

There is no separate security address and no security.txt file today.

What is Complipath not?

Complipath is not SOC 2 certified and not ISO 27001 certified.

We do not offer a signed data processing agreement yet. A draft exists and is being reviewed before we offer it.