Diligence us the way we diligence the world.
Certifications, audit reports, subprocessors, data residency and the controls behind them. Complead sells compliance, so the evidence sits on the page rather than behind a form. Documents that need an NDA are marked, and they arrive within one business day.
Certified, and checked again every year
Certification is the part your team actually diligences, so every line here carries its status instead of a logo. Where an audit is still open, it says so.
Documents
Public documents download directly. Anything marked NDA is released within one business day of a signed mutual NDA, through the same request. One request covers the whole list.
Tell us which documents you need and who signs the NDA. We will not route you to a portal that emails us on your behalf.
How the platform is protected
A checklist on a vendor directory tells you that a control exists. It does not tell you what the control is. Here is the second part.
Where your data lives, and what we never do with it
Five answers that belong in a contract, not in a sales call. They are in ours.
Subprocessors
Every change is published here and notified before the new subprocessor starts processing. The register attached to the DPA names each entity; this is the shape of it.
Named entities, their processing purpose and their region. Changes are announced 30 days before they take effect.
AI you can put in front of an auditor
Complead is AI-native, which makes governance the first question a regulator asks about us and the second one they ask about you. These answers are contractual, not aspirational.
Availability
Status and incident history are public and are not pruned. During an incident the first update goes out within 30 minutes and the updates keep coming until it closes, whether or not anyone has asked.
All systems operational
Subscribe there for incident mail, or pull the same feed into your own monitoring.
Found something? Tell us.
A vulnerability report is a favor, and it is treated like one. Researchers who act in good faith and stay inside the policy will not hear from our lawyers.
[email protected]
Reaches the engineers who own these controls, not a shared inbox that forwards to sales.
Security review questions
The seven that arrive in almost every review, answered before you have to ask them.
How long does a security review with Complead take?
Most close inside a week. Public documents are on this page, NDA documents arrive within one business day, and a security engineer joins the call if your team wants to walk the architecture rather than read it.
Can we send our own questionnaire instead of yours?
Yes, in whatever format your process requires. We keep CAIQ and SIG current, which usually answers most of a custom questionnaire, and we complete the rest ourselves rather than pointing you at a portal.
Can we run our own penetration test?
Yes, against a dedicated environment and scheduled with our security team. We share the rules of engagement in advance, and your findings enter the same remediation queue as the ones our own testers raise.
Do you support SSO and SCIM?
Single sign-on through SAML and OIDC. Role-based access is configurable per user, and every access change is written to the audit trail your own auditors can export.
Who inside Complead can see our data?
Support and engineering staff, and only through a request that is logged, time-boxed and tied to a ticket you can see. Nobody holds standing access to production data, including the people who built it.
What happens to our data when the contract ends?
You export it in a machine readable format on your own schedule. We then delete it, confirm the deletion in writing, and keep the record of that deletion available to you afterwards.
Do you have a status page and an incident history?
Both, both public, and the history is not pruned. An incident that embarrassed us two years ago is still there, with what we changed because of it.
Lead on compliance.
Join 800+ companies that trust Complead to detect risk, prevent fraud and stay compliant.