Skip to content

Trust

Security & data handling.

This page is maintained by Complarity to answer common security and privacy questions about our compliance platform. It is not an independent certification.

Hosting & data residency

The application is hosted on infrastructure located within the European Union. Customer data — including AI system inventories, classification records, uploaded evidence, and generated documents — remains stored in the EU.

Access & authentication

Sign-in supports email/password and Google SSO. All sessions are protected by server-verified bearer tokens. Application access is scoped per company; row-level security enforces separation between tenants at the database layer.

Encryption

Data is encrypted in transit via TLS 1.2+. At-rest encryption is handled by the underlying platform (AES-256). Application-level encryption is used for stored third-party connection secrets.

Audit trail

Every classification confirmation, obligation status change, document approval, and evidence upload writes to an append-only audit log. Records include actor, timestamp, and a content hash for tamper detection.

Subprocessors

Complarity uses a small set of subprocessors for hosting, database, payment processing (Stripe), and outbound email. The current list is available in the Data Processing Addendum, and material changes are notified at least 30 days in advance.

Retention & deletion

Customer data is retained for the duration of the subscription plus a 30-day grace period. Deletion is available on written request and can be scheduled for the end of the billing period. Audit-trail records may be retained longer where required by law.

Incident response

Security incidents affecting customer data are notified without undue delay in line with GDPR Art. 33. Contact: security@fractionalit.co.

Vulnerability reporting

Please disclose responsibly at security@fractionalit.co. We aim to acknowledge within two business days.

Shared responsibility

Complarity provides the platform, controls listed above, and documentation templates. You remain the controller of the personal data you upload, the accountable party for AI Act obligations attached to your systems, and the signer of your Declaration of Conformity. We do not sign compliance artefacts on your behalf.

Not a certification

This page describes current app-visible controls and practices. It is not an independent audit report and does not constitute a SOC 2, ISO 27001, or equivalent certification claim.