Your compliance data, protected by design
ComplyLayer helps companies prove their governance, so we hold ourselves to the same standard. Here is exactly how we protect your data, in plain terms.
Hosted in the EU
AWS Frankfurt (eu-central-1)
Encrypted end to end
At rest (AES-256) & in transit (TLS 1.2+)
Backed up daily
Automated snapshots + database dumps
GDPR-aligned
DPA available on request
Hosting & data residency
·All customer data is hosted on Amazon Web Services in the EU (Frankfurt, Germany, eu-central-1) region.
·ComplyLayer is a US company; where personal data is accessed from outside the EEA, transfers rely on the EU Standard Contractual Clauses. See our Privacy Policy.
Encryption
·In transit: all connections use TLS 1.2 or higher.
·At rest: all data volumes are encrypted with AES-256 via AWS KMS.
·Passwords are never stored in plain text, only as salted, iterated PBKDF2-SHA256 hashes.
Backups & recovery
·Automated daily encrypted volume snapshots with rolling retention.
·Separate logical database backups kept off the primary host.
·If you cancel, your data stays recoverable for 30 days before deletion.
Access & authentication
·Access to production systems is restricted to authorised personnel using key-based authentication.
·Each organisation's data is logically isolated; users only ever see their own organisation.
·Sessions use short-lived tokens delivered in httpOnly cookies, so they can't be read by page scripts.
Data ownership & deletion
·You own the data you put into ComplyLayer. We process it only to provide the service and never use it to train AI models.
·You can permanently delete your organisation and all its data yourself, at any time, from your account Settings, no email required. Need an export instead? Email [email protected].
Subprocessors
·We share data only with vetted processors under data processing agreements: AWS (hosting), Stripe (billing), Resend (email), and OpenAI (document generation & risk classification, under terms that prohibit training on your data).
·A Data Processing Agreement with the current subprocessor list is available on request.
Browser extension: privacy by design
·The optional monitoring extension runs only on a maintained list of known AI-tool domains, never your general browsing.
·It captures at most a 240-character prompt preview and file names only, never full prompts, AI responses, file contents, passwords, or form inputs.
·The code scanner reads dependency manifests only, never your source code.
Compliance & certifications
·ComplyLayer is built to support GDPR and EU AI Act obligations, and we operate as a data processor for the content you manage in the platform.
·On our roadmap: SOC 2 Type II and ISO/IEC 27001. We'll publish reports here once completed, and we won't claim a certification before we hold it.
Reporting a vulnerability
·Found a security issue? Please report it responsibly to [email protected] and we'll respond promptly.
Questions about security or a vendor review? Email [email protected].