Introducing Complead. One AI-native platform for financial crime compliance. Read the story
New Ready Integrations available Check the new integrations

Diligence us the way we diligence the world.

Certifications, audit reports, subprocessors, data residency and the controls behind them. Complead sells compliance, so the evidence sits on the page rather than behind a form. Documents that need an NDA are marked, and they arrive within one business day.

99.95% Uptime, last 12 months
1 business day NDA document turnaround
Annual Third-party penetration test
ISO 27001 Certified and surveilled

Certified, and checked again every year

Certification is the part your team actually diligences, so every line here carries its status instead of a logo. Where an audit is still open, it says so.

Documents

Public documents download directly. Anything marked NDA is released within one business day of a signed mutual NDA, through the same request. One request covers the whole list.

Security whitepaper Architecture, control environment, and the reasoning behind both. Public · PDF
ISO 27001 certificate Certificate and scope statement, issued by the certification body. Public · PDF
ISO 9001 certificate Certificate and the processes inside its scope. Public · PDF
Data processing agreement Standard DPA, including the standard contractual clauses we rely on. Public · PDF
Subprocessor register Named entities, purpose, region, and the notice period before a change takes effect. Public · PDF
Penetration test summary Executive summary of the most recent third-party test, with remediation status per finding. NDA
SOC 2 Type II report Released when the first observation window closes. NDA
Business continuity and disaster recovery Recovery objectives, backup regime, and the date of the last restore test. NDA
Cyber insurance certificate Carrier, limits and policy period. NDA
Completed security questionnaire CAIQ and SIG, kept current so your review does not wait on ours. NDA
Request access

Tell us which documents you need and who signs the NDA. We will not route you to a portal that emails us on your behalf.

How the platform is protected

A checklist on a vendor directory tells you that a control exists. It does not tell you what the control is. Here is the second part.

Encryption TLS 1.2 and above in transit, AES-256 at rest. Keys live in a dedicated key service and rotate on a fixed schedule, separately from the data they protect.
Access control Single sign-on and multi-factor authentication for every employee. Least privilege by default, reviewed every quarter, and revoked the day somebody leaves.
Infrastructure Production is isolated from every other environment and defined as code. Nobody holds standing access to it; access is requested, logged and time-boxed.
Monitoring Centralized logging with alerting around the clock. Audit trails are retained and exportable, so your regulator reads the same record we do.
Secure development Every change is peer reviewed. Static analysis and dependency scanning run in the pipeline, and an independent firm tests the platform once a year.
People Background checks before the first day, security training at onboarding and every year after, confidentiality agreements for anyone who works near customer data.

Where your data lives, and what we never do with it

Five answers that belong in a contract, not in a sales call. They are in ours.

Residency You choose the region your data stays in. It does not leave the region you selected, for processing or for backup. EU · UK · Türkiye
Separation Every customer runs against logically separated data. Nothing is pooled across tenants, including for benchmarking. by design
Retention You set retention on screening records to match your own regulatory obligation, not ours. customer controlled
Deletion On exit you export everything in a machine readable format, then we delete it and confirm the deletion in writing. within 30 days
Transfers Where a transfer cannot be avoided it runs on standard contractual clauses, named in the DPA. SCCs
Model training Your data is never used to train a model that serves anyone else. There is no shared learning layer between customers. never

Subprocessors

Every change is published here and notified before the new subprocessor starts processing. The register attached to the DPA names each entity; this is the shape of it.

Cloud infrastructure Hosting, storage and backup inside the region you selected. EU · UK · Türkiye
Email delivery Transactional mail only: alerts, scheduled reports and system notices. EU
Customer support Ticket content and the contact details attached to it. EU
Product analytics Pseudonymized usage events. No customer records, no screening results. EU
Error monitoring Stack traces and request metadata, scrubbed of payload before they leave the platform. EU
Business systems Contract and billing contacts. No screening data reaches them. EU
Download the register

Named entities, their processing purpose and their region. Changes are announced 30 days before they take effect.

AI you can put in front of an auditor

Complead is AI-native, which makes governance the first question a regulator asks about us and the second one they ask about you. These answers are contractual, not aspirational.

Attribution Every agent action is logged with its inputs, its output, and the policy or person that authorized it. logged
Human sign-off Decisions that change a customer relationship stay with a person. The agent prepares the file, a human signs it. by design
Versioning Models are versioned. A change is testable against your own historical cases before it reaches production. testable
Explainability The reasoning travels with the decision, so the file reads the same to an examiner six months later as it did to your analyst. on the record
Isolation No customer data crosses into a model that serves another customer. enforced
EU AI Act Our classification, and the obligations we take on regardless of where the classification lands. documented

Availability

Status and incident history are public and are not pruned. During an incident the first update goes out within 30 minutes and the updates keep coming until it closes, whether or not anyone has asked.

All systems operational

99.95% Uptime, last 12 months
<200 ms Median screening response
4 h Recovery time objective
1 h Recovery point objective
Status page

Subscribe there for incident mail, or pull the same feed into your own monitoring.

Found something? Tell us.

A vulnerability report is a favor, and it is treated like one. Researchers who act in good faith and stay inside the policy will not hear from our lawyers.

Acknowledgment A human replies, not an autoresponder, and stays on the thread until the finding is closed. 1 business day
Scope The production platform, the public API and our own domains. Denial of service and social engineering are out of scope. see policy
Encrypted reports Use our PGP key if the finding includes anything you would rather not put in mail. PGP available

[email protected]

Reaches the engineers who own these controls, not a shared inbox that forwards to sales.

Report a vulnerability

Security review questions

The seven that arrive in almost every review, answered before you have to ask them.

How long does a security review with Complead take?

Most close inside a week. Public documents are on this page, NDA documents arrive within one business day, and a security engineer joins the call if your team wants to walk the architecture rather than read it.

Can we send our own questionnaire instead of yours?

Yes, in whatever format your process requires. We keep CAIQ and SIG current, which usually answers most of a custom questionnaire, and we complete the rest ourselves rather than pointing you at a portal.

Can we run our own penetration test?

Yes, against a dedicated environment and scheduled with our security team. We share the rules of engagement in advance, and your findings enter the same remediation queue as the ones our own testers raise.

Do you support SSO and SCIM?

Single sign-on through SAML and OIDC. Role-based access is configurable per user, and every access change is written to the audit trail your own auditors can export.

Who inside Complead can see our data?

Support and engineering staff, and only through a request that is logged, time-boxed and tied to a ticket you can see. Nobody holds standing access to production data, including the people who built it.

What happens to our data when the contract ends?

You export it in a machine readable format on your own schedule. We then delete it, confirm the deletion in writing, and keep the record of that deletion available to you afterwards.

Do you have a status page and an incident history?

Both, both public, and the history is not pruned. An incident that embarrassed us two years ago is still there, with what we changed because of it.

Lead on compliance.

Join 800+ companies that trust Complead to detect risk, prevent fraud and stay compliant.