Trust Center
How we protect your compliance data.
Complaix handles regulatory data. You deserve to know exactly how. This page lists every control we enforce, every attestation we hold (or are working toward), and every contract we sign.
Platform security
Encryption everywhere
Multi-tenant isolation via RLS
Strict Content Security Policy
Append-only audit log
Append-only evidence vault
Rate-limited sensitive endpoints
Authentication & access
Strong password + optional MFA
Role model
Privileged-column protection
Session lifecycle
Data protection & GDPR
EU-first data residency
Self-service data rights
DPA + DPIA
Backup + restore
Compliance posture
| Framework | Status | Notes |
|---|---|---|
| GDPR | In force | EU-based processing. DPIA, DPA, subprocessor register all published. |
| EU AI Act (self) | Applied to ourselves | Our own AI components classified and published at /ai-policy (Annex IV-style). |
| European Accessibility Act | Automated WCAG 2.2 AA regression live | Manual audit planned before GA. |
| NIS2 | Prepared as processor | SIEM-ready audit export, incident response runbook, 24h notification path. |
| SOC 2 Type I | Readiness in progress | GRC tooling engaged; audit scheduled. |
| ISO/IEC 42001 | Gap assessment complete | 38 controls mapped; Stage-1 audit after Type I. |
| ISO/IEC 27001 | Roadmapped | Sits under SOC 2 + ISO 42001 parent system. |
Liability & insurance
Complaix carries insurance appropriate to the scale and scope of the platform today. Our standard contractual commitments include:
Professional indemnity (E&O)
Cyber liability
Commercial general liability
DPA + MSA
Observability & incident response
Operational monitoring
Incident response
Breach notification
SIEM-ready audit export
Responsible disclosure
If you think you found a security issue, write to security@complaix.eu with a reproducer. We acknowledge within 3 business days and aim to remediate high-severity issues within 14 days.
Machine-readable details: /.well-known/security.txt. Full disclosure policy: /security.
Contacts
Last reviewed 2026-05-07 · Reviewed quarterly · Source-of-truth: /subprocessors · /privacy · /dpa · /status