Security

Secured by where it runs — not just by what it promises.

Compiled is private by construction: it runs inside your environment, so your most sensitive data is protected by your own controls, not a vendor's. There is nothing to exfiltrate from us because we never hold your data.

Zero data egressIn-tenant deploymentSOC 2 Type II — in progressGDPR-alignedHIPAA BAA availableAES-256 / TLS 1.3SSO — SAML 2.0 / OIDCFull audit logCoordinated disclosure
Data security

The strongest guarantee is structural, not contractual.

Most vendors protect your data with policies, encryption, and access controls — all of which can fail. Compiled's protection is different: it is a consequence of where the product runs, not of what we promise.

Zero data egress

Communications and agent actions are inspected inside your tenant — by your own in-tenant AI resource, or a fully local model when you require an air-gap. They are never transmitted to, processed by, or stored by Compiled, OpenAI, or any third party. The inspection happens where the data already lives — your network, your compute, your boundary.

Your perimeter, your keys

Compiled inherits your existing network controls, identity stack, and encryption configuration. It does not create a new place your data has to live, a new key-management surface to audit, or a new boundary to defend. Your controls protect Compiled; Compiled does not ask you to trust ours instead.

Nothing to exfiltrate from us

We do not hold your data, so a breach of Compiled infrastructure cannot expose it. This is not a policy promise about what we would do if breached. It is a structural guarantee about what an attacker could find. The answer is: nothing. Your communications and agent actions do not exist outside your environment.

Auditable by design

Every decision — allow, flag, or block — is logged in your environment, time-stamped, scored, and tied to the specific policy it matched. You produce a complete evidentiary trail for your team and your regulators without assembling records from a vendor system. Findings route to the SIEM or SOAR you already run.

Architecture and trust boundary

What runs where. What crosses the boundary.

Compiled operates inside a single, well-defined trust boundary. Understanding what is inside and what crosses it answers most InfoSec review questions before they are asked.

Inside your environment
The Compiled core — inspection logic and your antibody library
The inspection AI — your own in-tenant Azure OpenAI resource, or a fully local model for air-gapped deployments. Your choice at deploy time
All communication content and agent action payloads
Scored findings and audit logs
Your configuration and policy definitions
All outbound findings to your SIEM, SOAR, and case-management tools
What crosses the boundary
Inbound — from Compiled

Signed antibody updates only. No sensitive content, no configuration data, no findings. Updates are versioned and verified before they are applied to your deployment.

Outbound — to your SOC

Structured findings: timestamp, channel, verdict, score, policy attribution. Your routing rules determine where findings go — SIEM, SOAR, case management. No raw communication content leaves your environment.

Never crosses

Communication content, agent action payloads, findings in raw form, configuration data, or any sensitive business information.

Architecture and data-flow documentation is available under NDA. Contact sales@compiled.co.

Compliance and assurance

Where we are. Stated plainly.

We report our compliance posture honestly. SOC 2 Type II is in progress — we will not claim it before it is complete. The controls below are in place today; the roadmap items are committed and dated internally.

SOC 2 Type IIIn progress

Audit in progress. Report available under NDA upon completion. Controls mapped and operating.

GDPR-aligned data processingAvailable

Data Processing Agreement available. In-tenant architecture means personal data does not leave your jurisdiction.

HIPAA BAAAvailable

Business Associate Agreement available for healthcare deployments. PHI is inspected inside your environment and never transmitted to Compiled.

Data residencyAvailable

Deploys into your Azure tenant in your chosen region. No data store is created outside your environment.

ISO 27001 / ISO 42001Roadmap

ISO 27001 (information security management) and ISO 42001 (AI management system) on the roadmap.

Architecture documentationAvailable

Architecture brief, data-handling documentation, and sub-processor list available under NDA on request.

Security controls

What is in place today.

Encryption at restAES-256. Applies to all data stored in your environment as part of the Compiled deployment.
Encryption in transitTLS 1.3 for all connections between Compiled components and between the management plane and your deployment. TLS 1.2 minimum; older protocols rejected.
Access controlRole-based access control (RBAC) enforced at the application layer. Roles are scoped to the minimum privileges required for each function.
Multi-factor authenticationMFA required for all access to the management plane. Phishing-resistant methods (hardware key, passkey) recommended and supported.
Single sign-onSAML 2.0 and OIDC supported. Compiled integrates with your existing identity provider — Entra ID, Okta, Ping, and others. SSO is available on all plans.
JIT publisher accessAny Compiled engineer access into your deployment environment is least-privilege, time-boxed (just-in-time), and logged. No standing access. Every session is auditable.
Audit loggingAll decisions, administrative actions, access events, and configuration changes are logged in your environment in a tamper-evident format. Logs remain under your control.
Sub-processors

Minimal by design.

Compiled's sub-processor list is intentionally short. The in-tenant architecture means most infrastructure is yours, not ours.

Microsoft Azure
Management plane

Hosts the Compiled management plane and the signed antibody distribution infrastructure. Does not process your communications or agent action data.

Your Azure tenant
Inspection and data

When deployed in your tenant, all inspection infrastructure, data storage, and audit logging run on your infrastructure — not ours. This is not a sub-processor in the conventional sense; it is your environment.

A current sub-processor list is available on request. Contact sales@compiled.co.

Update integrity

Antibody updates are recognizer definitions, not executable code.

The architecture diagram states that antibody updates are the only thing that crosses the boundary inbound. A natural question follows: what are they, how are they controlled, and what is the blast radius if one is flawed? Here is the complete answer.

Recognizer definitions, not executable code

Antibody updates are sealed behavioral recognizer definitions — compact mathematical descriptions of a pattern or policy. They are not software binaries, not scripts, and carry no remote code execution capability. An update changes what Compiled looks for; it does not change how the Compiled runtime itself operates. The distinction matters: a malicious or defective update cannot alter the execution environment inside your tenant.

Cryptographically signed and verified

Every update is signed with a Compiled signing key before it leaves our infrastructure. Your deployment verifies the signature before applying the update. An unsigned or tampered package is rejected. The signing chain is documented in the architecture brief available under NDA.

Version-pinned and customer-staged

Updates carry a version identifier and a human-readable description of what changed and which policy or risk category it addresses. You control when updates are applied — your deployment can be configured to stage updates for review and approval before they take effect. Nothing is pushed silently or applied without a versioned artifact you can inspect.

Rollback-able at any point

Your environment maintains a full version history of your antibody library. If a new update produces unexpected behavior — higher false-positive rate, policy mismatch — you can revert to any prior version. Rollback is an operational operation, not an emergency procedure.

Limited blast radius by construction

Because updates are recognizer definitions only, a defective one degrades recognition accuracy for the affected behavior category. It does not affect the Compiled runtime, your other antibodies, your data, or your environment. Scope is bounded and recovery is immediate.

The signing infrastructure, update staging configuration, and rollback procedure are documented in full in the architecture brief. Available under NDA — contact sales@compiled.co.

Responsible AI

Your data is not our training data.

Compiled's approach to AI development is governed by clear rules about what your data can and cannot be used for.

No use of customer data without consent

Your communications and agent action data are never used to improve antibodies or any other part of the Compiled system without your explicit, documented consent. Improvement reaches you; your data stays put.

Versioned and auditable antibodies

Every antibody in your library has a version identifier, a description, and a policy attribution. You can see what changed, when it changed, and what policy or risk category it addresses — at any point in time.

Policy-attributable decisions

Every verdict is linked to a named policy, not a black-box score. When a regulator or internal reviewer asks why a communication was flagged, the answer is immediate, specific, and documented.

Signed updates only

Antibody updates that cross into your environment are cryptographically signed and verified before they are applied. No unsigned content enters your deployment.

Incident response

Notification commitments and SLAs.

In the event of a security incident affecting Compiled infrastructure, we are committed to the following notification timelines. Because your data lives in your environment, a Compiled infrastructure incident does not expose your communications or agent action data — but we notify promptly regardless.

24h
Notification SLA
From discovery of any confirmed P0/P1 incident
72h
GDPR notification
Article 33 supervisory-authority notification supported
P0
Critical — active exploitation
Immediate response; customer notification ≤ 4h
P0 — CriticalActive exploitation of Compiled infrastructure; confirmed data exposure; service-wide outage
Notification
≤ 4 hours from discovery
Resolution target
Continuous updates until resolved
P1 — HighPotential exploitation; significant degradation of inspection capability; vulnerability with active proof-of-concept
Notification
≤ 24 hours from discovery
Resolution target
Updates every 4 hours until resolved
P2 — MediumVulnerability without active exploitation; degradation of non-critical components; hardening findings
Notification
≤ 72 hours from discovery
Resolution target
Patch in next scheduled release cycle
Vulnerability disclosure

Coordinated disclosure.

We welcome reports from security researchers. If you have identified a potential vulnerability in Compiled, please report it to us before public disclosure. We commit to acknowledging receipt within one business day and to keeping you informed as we investigate and remediate.

Disclosure channel
security@compiled.co
Acknowledgement
Within one business day of receipt

Please include a description of the vulnerability, reproduction steps, and your assessment of impact. We will coordinate remediation and discuss public disclosure timelines with you directly. We do not pursue legal action against researchers who report in good faith and follow coordinated disclosure practice.

FAQ

Questions from InfoSec reviewers

Vendor security review

Pre-answered. So your InfoSec review can move faster.

InfoSec teams run through a standard set of questions on every vendor evaluation. The answers below cover the categories in common questionnaire frameworks (SIG, CAIQ). Download a pre-filled version to share with your team directly.

Data residency
Where is our data processed and stored?

Inside your own environment — your Azure tenant or on-prem. Compiled does not create an external data store. Your communications and agent action data are never transmitted to or stored by Compiled. The only infrastructure Compiled operates outside your tenant is the management plane, which holds deployment configuration and signed antibody updates — not your business data.

Data retention
How long does Compiled retain our data?

Compiled retains no customer communication or agent action data. Because inspection happens inside your environment, retention of findings and audit logs is governed by your own policies and storage configuration — not ours.

Sub-processors
Who are your sub-processors and what do they handle?

Compiled's sub-processor footprint is intentionally minimal. Microsoft Azure hosts the Compiled management plane and signed antibody distribution infrastructure. It does not process your communications or agent action data. A current sub-processor list is available on request.

Access controls
What access does Compiled have to our environment?

No standing access. Any Compiled engineer session into your deployment is just-in-time, least-privilege, and time-boxed. Every session requires explicit authorization and is scoped to the specific task. All sessions are logged in your environment and reviewable by your team. RBAC is enforced at the application layer. SSO (SAML 2.0 / OIDC) integrates with your existing identity provider.

Encryption
How is data encrypted at rest and in transit?

Data at rest is encrypted using AES-256. All connections between Compiled components and between the management plane and your deployment use TLS 1.3; TLS 1.2 is the minimum accepted. Compiled inherits your tenant's key management configuration and does not introduce a separate key-management surface.

Incident response
What are your incident notification commitments?

For a P0 (critical, active exploitation) incident affecting Compiled infrastructure, customer notification is within 4 hours of discovery. For P1 (significant), within 24 hours. GDPR Article 33 supervisory-authority notification is supported within 72 hours. Because your data lives in your environment, a Compiled infrastructure incident does not expose your communications or agent data.

SDLC and security testing
What does your secure development lifecycle include?

Compiled's SDLC includes code review, static analysis, dependency scanning, and a regular penetration testing cycle by a third-party firm. An executive summary of the most recent pen test is available under NDA. A vulnerability disclosure channel is maintained at security@compiled.co.

Certifications
What certifications do you hold?

SOC 2 Type II is in progress — we will not claim it before the audit is complete. Current controls documentation is available now. GDPR-aligned DPA is available. HIPAA BAA is available for healthcare deployments. ISO 27001 and ISO 42001 are on the roadmap.

Business continuity
What happens to our protection if Compiled has an outage?

Because Compiled runs inside your environment, an outage of Compiled's management plane does not affect the inspection capability already deployed in your tenant. Your antibody library and the inspection runtime operate independently of the Compiled management plane. Updates pause until connectivity is restored; existing protections remain active.

Download the pre-filled security questionnaire

SIG / CAIQ-style. Share it with your InfoSec team to run the review in parallel.

Request questionnaire — sales@compiled.co
Request documentation

Everything your InfoSec review needs.

We can turn around a vendor review package quickly. The following are available under NDA on request.

SOC 2 Type II report

Available upon audit completion. Current controls documentation available now.

Architecture brief

Deployment topology, data-flow diagram, and trust-boundary description.

Data Processing Agreement

GDPR-compliant DPA covering the Compiled management plane sub-processing.

HIPAA Business Associate Agreement

For healthcare deployments where PHI is in scope.

Sub-processor list

Current list of Compiled sub-processors and the data each processes.

Penetration testing summary

Executive summary of the most recent third-party pen test, under NDA.

Ready to start a vendor review?

Email us with the documents you need and we will respond within one business day. For a live walkthrough of the architecture, book a 30-minute session with our security team.

Request documentationChat with usBook a 30-minute walkthrough

Security disclosures: security@compiled.co