Most vendors protect your data with policies, encryption, and access controls — all of which can fail. Compiled's protection is different: it is a consequence of where the product runs, not of what we promise.
Communications and agent actions are inspected inside your tenant — by your own in-tenant AI resource, or a fully local model when you require an air-gap. They are never transmitted to, processed by, or stored by Compiled, OpenAI, or any third party. The inspection happens where the data already lives — your network, your compute, your boundary.
Compiled inherits your existing network controls, identity stack, and encryption configuration. It does not create a new place your data has to live, a new key-management surface to audit, or a new boundary to defend. Your controls protect Compiled; Compiled does not ask you to trust ours instead.
We do not hold your data, so a breach of Compiled infrastructure cannot expose it. This is not a policy promise about what we would do if breached. It is a structural guarantee about what an attacker could find. The answer is: nothing. Your communications and agent actions do not exist outside your environment.
Every decision — allow, flag, or block — is logged in your environment, time-stamped, scored, and tied to the specific policy it matched. You produce a complete evidentiary trail for your team and your regulators without assembling records from a vendor system. Findings route to the SIEM or SOAR you already run.
Compiled operates inside a single, well-defined trust boundary. Understanding what is inside and what crosses it answers most InfoSec review questions before they are asked.
Architecture and data-flow documentation is available under NDA. Contact sales@compiled.co.
We report our compliance posture honestly. SOC 2 Type II is in progress — we will not claim it before it is complete. The controls below are in place today; the roadmap items are committed and dated internally.
Compiled's sub-processor list is intentionally short. The in-tenant architecture means most infrastructure is yours, not ours.
Hosts the Compiled management plane and the signed antibody distribution infrastructure. Does not process your communications or agent action data.
When deployed in your tenant, all inspection infrastructure, data storage, and audit logging run on your infrastructure — not ours. This is not a sub-processor in the conventional sense; it is your environment.
A current sub-processor list is available on request. Contact sales@compiled.co.
The architecture diagram states that antibody updates are the only thing that crosses the boundary inbound. A natural question follows: what are they, how are they controlled, and what is the blast radius if one is flawed? Here is the complete answer.
Antibody updates are sealed behavioral recognizer definitions — compact mathematical descriptions of a pattern or policy. They are not software binaries, not scripts, and carry no remote code execution capability. An update changes what Compiled looks for; it does not change how the Compiled runtime itself operates. The distinction matters: a malicious or defective update cannot alter the execution environment inside your tenant.
Every update is signed with a Compiled signing key before it leaves our infrastructure. Your deployment verifies the signature before applying the update. An unsigned or tampered package is rejected. The signing chain is documented in the architecture brief available under NDA.
Updates carry a version identifier and a human-readable description of what changed and which policy or risk category it addresses. You control when updates are applied — your deployment can be configured to stage updates for review and approval before they take effect. Nothing is pushed silently or applied without a versioned artifact you can inspect.
Your environment maintains a full version history of your antibody library. If a new update produces unexpected behavior — higher false-positive rate, policy mismatch — you can revert to any prior version. Rollback is an operational operation, not an emergency procedure.
Because updates are recognizer definitions only, a defective one degrades recognition accuracy for the affected behavior category. It does not affect the Compiled runtime, your other antibodies, your data, or your environment. Scope is bounded and recovery is immediate.
The signing infrastructure, update staging configuration, and rollback procedure are documented in full in the architecture brief. Available under NDA — contact sales@compiled.co.
Compiled's approach to AI development is governed by clear rules about what your data can and cannot be used for.
In the event of a security incident affecting Compiled infrastructure, we are committed to the following notification timelines. Because your data lives in your environment, a Compiled infrastructure incident does not expose your communications or agent action data — but we notify promptly regardless.
We welcome reports from security researchers. If you have identified a potential vulnerability in Compiled, please report it to us before public disclosure. We commit to acknowledging receipt within one business day and to keeping you informed as we investigate and remediate.
InfoSec teams run through a standard set of questions on every vendor evaluation. The answers below cover the categories in common questionnaire frameworks (SIG, CAIQ). Download a pre-filled version to share with your team directly.
Inside your own environment — your Azure tenant or on-prem. Compiled does not create an external data store. Your communications and agent action data are never transmitted to or stored by Compiled. The only infrastructure Compiled operates outside your tenant is the management plane, which holds deployment configuration and signed antibody updates — not your business data.
Compiled retains no customer communication or agent action data. Because inspection happens inside your environment, retention of findings and audit logs is governed by your own policies and storage configuration — not ours.
Compiled's sub-processor footprint is intentionally minimal. Microsoft Azure hosts the Compiled management plane and signed antibody distribution infrastructure. It does not process your communications or agent action data. A current sub-processor list is available on request.
No standing access. Any Compiled engineer session into your deployment is just-in-time, least-privilege, and time-boxed. Every session requires explicit authorization and is scoped to the specific task. All sessions are logged in your environment and reviewable by your team. RBAC is enforced at the application layer. SSO (SAML 2.0 / OIDC) integrates with your existing identity provider.
Data at rest is encrypted using AES-256. All connections between Compiled components and between the management plane and your deployment use TLS 1.3; TLS 1.2 is the minimum accepted. Compiled inherits your tenant's key management configuration and does not introduce a separate key-management surface.
For a P0 (critical, active exploitation) incident affecting Compiled infrastructure, customer notification is within 4 hours of discovery. For P1 (significant), within 24 hours. GDPR Article 33 supervisory-authority notification is supported within 72 hours. Because your data lives in your environment, a Compiled infrastructure incident does not expose your communications or agent data.
Compiled's SDLC includes code review, static analysis, dependency scanning, and a regular penetration testing cycle by a third-party firm. An executive summary of the most recent pen test is available under NDA. A vulnerability disclosure channel is maintained at security@compiled.co.
SOC 2 Type II is in progress — we will not claim it before the audit is complete. Current controls documentation is available now. GDPR-aligned DPA is available. HIPAA BAA is available for healthcare deployments. ISO 27001 and ISO 42001 are on the roadmap.
Because Compiled runs inside your environment, an outage of Compiled's management plane does not affect the inspection capability already deployed in your tenant. Your antibody library and the inspection runtime operate independently of the Compiled management plane. Updates pause until connectivity is restored; existing protections remain active.
SIG / CAIQ-style. Share it with your InfoSec team to run the review in parallel.
We can turn around a vendor review package quickly. The following are available under NDA on request.
Email us with the documents you need and we will respond within one business day. For a live walkthrough of the architecture, book a 30-minute session with our security team.
Security disclosures: security@compiled.co