Trust
Security & data handling.
This page is maintained by Complarity to answer common security and privacy questions about our compliance platform. It is not an independent certification.
Hosting & data residency
The application is hosted on infrastructure located within the European Union. Customer data — including AI system inventories, classification records, uploaded evidence, and generated documents — remains stored in the EU.
Access & authentication
Sign-in supports email/password and Google SSO. All sessions are protected by server-verified bearer tokens. Application access is scoped per company; row-level security enforces separation between tenants at the database layer.
Encryption
Data is encrypted in transit via TLS 1.2+. At-rest encryption is handled by the underlying platform (AES-256). Application-level encryption is used for stored third-party connection secrets.
Audit trail
Every classification confirmation, obligation status change, document approval, and evidence upload writes to an append-only audit log. Records include actor, timestamp, and a content hash for tamper detection.
Subprocessors
Complarity uses a small set of subprocessors for hosting, database, payment processing (Stripe), and outbound email. The current list is available in the Data Processing Addendum, and material changes are notified at least 30 days in advance.
Retention & deletion
Customer data is retained for the duration of the subscription plus a 30-day grace period. Deletion is available on written request and can be scheduled for the end of the billing period. Audit-trail records may be retained longer where required by law.
Incident response
Security incidents affecting customer data are notified without undue delay in line with GDPR Art. 33. Contact: security@fractionalit.co.
Vulnerability reporting
Please disclose responsibly at security@fractionalit.co. We aim to acknowledge within two business days.
Shared responsibility
Complarity provides the platform, controls listed above, and documentation templates. You remain the controller of the personal data you upload, the accountable party for AI Act obligations attached to your systems, and the signer of your Declaration of Conformity. We do not sign compliance artefacts on your behalf.
Not a certification
This page describes current app-visible controls and practices. It is not an independent audit report and does not constitute a SOC 2, ISO 27001, or equivalent certification claim.