How GetComply handles customer data

GetComply helps teams organize sensitive compliance records, so our own handling practices matter. This page explains the current approach in plain language. It is not a SOC 2 report, audit opinion, certification, or substitute for contractual due diligence.

Authentication and Access

Access to customer workspaces and evidence is limited to people who need it to support the engagement. Administrative access is protected with strong authentication, and access practices are reviewed as the company and customer base grow.

Customers use authenticated sessions to access the workspace. Any advisor access to customer records is limited to the engagement and the work being performed.

Evidence Handling

Customers should share only the records needed for the work in scope. GetComply uses the workspace to organize evidence, ownership, gaps, decisions, and next steps.

GetComply does not ask for production secrets, source code, personal data, or other sensitive materials merely because they may be available. When a less-sensitive record can support the work, that is preferred.

Evidence is accessed for review, organization, and program support within the engagement.

Customer Separation

Customer workspaces are designed around customer-specific access boundaries. Customer information is not intentionally shared across unrelated customer workspaces, demo environments, or other engagements.

Detailed technical information about the current separation model can be provided during due diligence when appropriate.

Vendors and Infrastructure

GetComply relies on third-party cloud infrastructure and SaaS tools to operate the website, workspace, email, scheduling, and internal workflows.

Vendors are selected based on the service they provide, the information they handle, security and reliability considerations, contractual fit, and operational need. The vendor-review process will become more formal as the program matures.

GetComply does not recommend a client tool merely because GetComply receives a commission. Any commercial relationship that could affect a recommendation should be disclosed.

Logging and Traceability

GetComply maintains operational records appropriate to supporting the service, investigating issues, and preserving accountability. The exact events recorded may change as the platform and internal program mature.

Where the workspace records approvals, governance decisions, evidence actions, or access changes, this page describes only the events that are currently captured and verified.

Backups and Recovery

GetComply uses managed cloud infrastructure and maintains backup and recovery measures appropriate to the service and the importance of the data.

More detailed recovery information can be provided during due diligence when relevant. Formal recovery-time and recovery-point objectives will be published only after they are defined, approved, tested, and supported by the current architecture.

Customer Control of Systems

GetComply does not require unrestricted access to a customer's production environment, source code, or databases as a standard condition of service.

The customer retains control of its systems and authorizes any access needed for the engagement. GetComply generally works from approved records, exports, reports, screenshots, and workspace access. Any direct access must be specifically approved, limited, and appropriate to the work.

Responsible Disclosure

If you believe you have found a security issue involving GetComply, please contact:

[email protected]

GetComply will acknowledge good-faith reports and investigate confirmed issues. GetComply does not currently operate a formal bug-bounty program.

Do not include sensitive customer information in the initial report. Provide enough detail to reproduce or understand the issue, and GetComply will coordinate a safer method for additional information when needed.

Due Diligence

Customers with a legitimate due-diligence need may request additional information about GetComply's current security practices, relevant vendors, data handling, and contractual terms.

The information provided will reflect the company's current state. GetComply will not present planned controls as completed controls.

This page is a plain-language overview of GetComply's current approach. It is not a SOC 2 report, audit opinion, certification, warranty, or contractual security schedule.

GetComply is an early-stage company and will update this page as the security program, platform, vendors, and operating practices mature. Claims will be added only when the supporting implementation and record exist.