How we handle your data.
This page describes plainly where data is processed and how it is protected. CompylotAI is built for regulated environments — clarity over certification logos we don't (yet) hold.
Hosting & data residency
EU-only hosting on Microsoft Azure, primarily in the Germany West Central region. Customer data does not leave the EU.
AI processing
Models are selected through an internal testing methodology based on review performance. The models used provide EU processing; model access is routed via OpenRouter. Non-public customer content is not used to train models.
Encryption
All customer data is encrypted in transit and at rest.
Human authority
CompylotAI supports first-pass review and remediation. Final approval stays with designated reviewers; accountability toward the regulator remains with the institution.
Retention & audit record
Data is retained in line with applicable retention requirements. For audit records, the application supports the ten-year retention required by BaFin.
Sub-processors
Microsoft Azure (hosting, EU), Resend (delivery of contact requests), and OpenRouter (AI model access).
Aligned to the regulation
CompylotAI supports teams operating under BaFin/MaRisk, DORA, and MiFID II. The product does not replace a compliance decision or guarantee conformity — it strengthens the quality and traceability of review.
- BaFin / MaRisk
- DORA
- MiFID II
- GDPR
Certifications
We do not currently hold formal security certifications (e.g. ISO 27001), and we don't claim any. For a data processing agreement (DPA) and detailed security questions, please reach out.
Questions about data handling or a DPA?
We're happy to answer security and data-handling questions directly.
Request a demo