Our security posture, data handling practices, subprocessors, and compliance status, all in one place.
Assessment answers, compliance scores, generated policies, integration OAuth tokens (encrypted), and evidence artifacts. We never store raw source code.
All customer data is stored in Supabase (PostgreSQL) hosted on AWS US-East-1. Vercel Edge Functions may process requests globally.
Your data is retained for the duration of your subscription plus 90 days. You can request deletion at any time by emailing privacy@mycomplai.com.
Assessment data is sent to Anthropic Claude API to generate gap reports and policies. Anthropic does not use API data to train models.
We use the following third-party services to deliver OneStepWise. All subprocessors are bound by data processing agreements.
If you discover a security vulnerability in OneStepWise, please report it responsibly. We commit to acknowledging reports within 48 hours and providing a fix timeline within 5 business days.
Found a vulnerability? Email our security team directly.
security@mycomplai.com