Security & trust
The strongest guarantee is structural, not contractual. Compiled's protection is a consequence of where it runs, not of what we promise.
Zero data egress
Communications and agent actions are inspected inside your tenant — by your own in-tenant AI resource, or a fully local model when you require an air-gap. They are never transmitted to, processed by, or stored by Compiled, OpenAI, or any third party. Inspection happens where the data already lives: your network, your compute, your boundary.
In-tenant inspection AI (and the default)
Inspection embeds text using your own in-tenant Azure OpenAI resource by default — the same model and vector space as the shipped detectors, so no recompile is needed, and content stays within your Microsoft/Azure boundary under your existing agreements. For the strictest deployments, a fully local model runs on-box with no external call of any kind (at some accuracy cost). External OpenAI is never used unless you explicitly opt in.
Nothing to exfiltrate from us
We do not hold your data, so a breach of Compiled infrastructure cannot expose it. This is not a policy promise about what we would do — it is a structural statement about what an attacker could find. The answer is: nothing.
Update integrity
Detector updates are the only inbound flow. They are signed, version-pinned, customer-staged, and rollback-able, and they carry no executable code — only detector data. You control when an update is applied.
Auditability
Every decision — allow, flag, or block — is logged in your environment, time-stamped, scored, and tied to the specific policy it matched, producing a complete evidentiary trail without assembling records from a vendor system.
Documentation under NDA
A SOC 2 report (in progress), a pre-filled security questionnaire (SIG / CAIQ), and a BAA are available under NDA — contact your Compiled representative.