Security

How we handle your data.

This page describes plainly where data is processed and how it is protected. CompylotAI is built for regulated environments — clarity over certification logos we don't (yet) hold.

  • Hosting & data residency

    EU-only hosting on Microsoft Azure, primarily in the Germany West Central region. Customer data does not leave the EU.

  • AI processing

    Models are selected through an internal testing methodology based on review performance. The models used provide EU processing; model access is routed via OpenRouter. Non-public customer content is not used to train models.

  • Encryption

    All customer data is encrypted in transit and at rest.

  • Human authority

    CompylotAI supports first-pass review and remediation. Final approval stays with designated reviewers; accountability toward the regulator remains with the institution.

  • Retention & audit record

    Data is retained in line with applicable retention requirements. For audit records, the application supports the ten-year retention required by BaFin.

  • Sub-processors

    Microsoft Azure (hosting, EU), Resend (delivery of contact requests), and OpenRouter (AI model access).

Aligned to the regulation

CompylotAI supports teams operating under BaFin/MaRisk, DORA, and MiFID II. The product does not replace a compliance decision or guarantee conformity — it strengthens the quality and traceability of review.

  • BaFin / MaRisk
  • DORA
  • MiFID II
  • GDPR

Certifications

We do not currently hold formal security certifications (e.g. ISO 27001), and we don't claim any. For a data processing agreement (DPA) and detailed security questions, please reach out.

Questions about data handling or a DPA?

We're happy to answer security and data-handling questions directly.

Request a demo