We Hold Ourselves to the Standards We Help You Meet
Compeas is a European compliance company, hosted in the EU. Security and privacy are built into our platform, our processes, and our culture.
Hosting & Data Residency
European infrastructure for European compliance data
Hosted in Sweden on Ploi Cloud
The Compeas platform — application, database, and backups — runs on Ploi Cloud in a Swedish datacenter. Customer data never leaves the EU.
No Third-Country Transfers
We do not transfer personal data outside the EEA. If a future subprocessor ever requires it, our subprocessor list is updated first and GDPR Chapter V safeguards are put in place.
Your Data Stays Yours
You can export your compliance data at any time — no lock-in. After termination, data is deleted within 30 days on request, with earlier deletion available under the Data Processing Addendum.
How We Protect Your Data
Defence in depth across every layer of the platform
Encryption Everywhere
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are managed and rotated following industry best practice.
Strict Access Controls
Role-based access control, mandatory multi-factor authentication, and least-privilege principles govern all access to production systems and customer data.
Continuous Monitoring
We monitor our own infrastructure around the clock — 24/7 alerting on security events and configuration drift across the Compeas platform.
Secure Development
Code review, systematic security scanning, and dependency auditing are required steps in our development lifecycle before anything reaches production.
Backup & Resilience
Customer data is backed up regularly with documented recovery objectives and tested restore procedures, and our infrastructure is designed for high availability across failure domains.
Vendor & Subprocessor Review
Every vendor and subprocessor that touches customer data undergoes a security review before engagement and periodic reassessment thereafter. See our published subprocessor list.
Single Sign-On
Sign in with Microsoft Entra or Google Workspace. SSO is available to every customer on request — centralised access control, instant offboarding, and your own MFA policies.
Incident Response & Notification
A documented incident response process governs how we detect, triage, and resolve security incidents. If a personal-data breach affects your data, we notify you without undue delay — and where Compeas is controller, we notify the supervisory authority within 72 hours as GDPR requires.
People & Security Culture
Everyone at Compeas signs confidentiality undertakings, completes security onboarding and annual awareness training, and gets access only to what their role requires. Background checks are performed where permitted by Swedish law.
Our Own Compliance Roadmap
We drink our own champagne — Compeas runs its compliance programme on Compeas. Status as of July 2026.
GDPR
We process personal data in line with the GDPR. Our Privacy Policy and Data Processing Addendum describe how we handle data on behalf of customers.
ISO 27001
Our information security management system is being built on the Compeas platform itself, towards ISO 27001 certification.
Penetration Testing
Independent third-party penetration tests are performed on the platform annually. Last test: [TODO-OWNER: add month/year and testing firm]. Executive summaries are available under NDA.
Uptime & Status
We target 99.7% monthly uptime, measured per calendar month and excluding scheduled maintenance announced in advance — backed by service credits under our Terms of Service. Current and historical availability is published at status.compeas.com.
Subprocessors
Every vendor that touches customer data is security-reviewed and listed publicly. See the current list at Subprocessors.
Responsible Disclosure
We operate a responsible disclosure programme with a 48-hour acknowledgement commitment and a safe-harbour pledge for good-faith research. See Report a Vulnerability below.
Security White Paper
An in-depth look at our security architecture, data handling, and compliance posture
Report a Vulnerability
We take all security reports seriously. If you believe you have found a vulnerability in Compeas, please email security@compeas.com. We commit to acknowledging reports within 48 hours and ask that you give us reasonable time to respond before any public disclosure. In return, we will not pursue legal action against good-faith research conducted within the scope of our systems — see our machine-readable policy at /.well-known/security.txt.
Questions about our security?
Our team is happy to walk you through our security practices and documentation