Introducing Complead. One AI-native platform for financial crime compliance. Read the story
New Ready Integrations available Check the new integrations
Security

Security and trust

Every claim below is something we can show, not just tell. Run your own diligence, or ask and we will walk you through it.

Controls

How the platform is controlled

01

Encryption

TLS 1.2+ in transit, AES-256 at rest. Keys rotate on a fixed schedule and are held in a managed KMS, separate from the data.

02

Access control

Role-based access, SSO and SCIM on request, MFA enforced internally. Production access is time-boxed, approved and logged per session.

03

Data residency

You choose the region at contract. Customer data stays in it, including backups. Screening can run against hashed identifiers where policy forbids sending names.

04

Retention and deletion

Retention is set per jurisdiction, five to ten years where required. Deletion requests are honoured within 30 days, subject to statutory holds.

05

Logging and monitoring

Every read of a customer record is logged with actor and time. Alerting runs on anomalous access; logs are retained independently of the platform.

06

Resilience

99.9% availability target, multi-zone deployment, tested restores. RTO 4 hours, RPO 15 minutes, exercised twice a year.

Residency

Where your data sits

01

European Union

Frankfurt and Dublin.

02

United Kingdom

London.

03

Turkiye

Istanbul, under KVKK.

Subprocessors

Who else touches the data

01

Cloud infrastructure

Hosting and storage. Contracted region: EU.

02

Email delivery

Alerts and notifications. Contracted region: EU.

03

Error monitoring

Diagnostics, no customer records. Contracted region: EU.

04

Support desk

Ticketing, on request only. Contracted region: EU.