Legal
Privacy Policy
Last updated: June 2026
The short version
Compiled is architecturally privacy-preserving. The scanner runs inside your own environment (your Azure tenant or on-prem). Document and message content is embedded and scored locally and is not transmitted to Compiled. We ship a small (~7 KB) mathematical model to you; your data does not flow to us.
What we process
Content you scan (communications, documents, AI-agent actions) is processed only within your environment to compute embeddings and detection scores. It is not stored by Compiled and, by default, is not retained after scoring. Audit logs of detections live in your environment under your control.
Account & billing data (company, contact, subscription) is processed to operate your account and is handled per the Microsoft commercial marketplace agreement when you transact through Azure Marketplace.
Data residency & egress
When deployed as an Azure Managed Application or on-prem, all embedding and scoring occur in your tenant/region. In the recommended configuration the embedding model is your own Azure OpenAI resource, so content never leaves your Azure boundary. A fully air-gapped mode runs a local model with zero network egress.
Privacy-preserving federation (opt-in)
Compiled can strengthen detection across customers by sharing only aggregated, differentially-private geometry — never content and never per-document vectors. A built-in privacy gate refuses to emit any aggregate that could be tied to an individual record. Federation is opt-in; you can decline with no loss of local functionality.
Sub-processors
For hosted components and marketplace transactions we rely on Microsoft Azure. When you deploy into your own tenant, the infrastructure is yours. A current sub-processor list is available on request.
Security
Encryption in transit (TLS 1.3) and at rest (AES-256), role-based access control, and SSO are supported. Our security posture and available compliance documentation are described on our Security & Trust page.
Your rights & contact
For data-protection requests or questions about this policy, contact privacy@compiledco.com. We respond within one business day.