Security and trust
Security and Trust
What is in place today to protect your data, how AI processing works, and how to report a security issue. We describe only what is true now and mark what is planned.
Last updated: July 27, 2026
How your data is handled
Complied AI is a research product. Reading updates, opening official sources, and browsing Acts needs no account. When you sign in, ask a section question, contact us, subscribe, or report an issue, we handle only the information needed for that action. We do not sell your data.
Encryption in transit
The site is served over HTTPS, so traffic between your browser and Complied AI is encrypted in transit. Data at rest is stored with our infrastructure providers described below.
Where data is stored
Application data, including account records and anything you submit through a form, is stored in Supabase (managed PostgreSQL). Access to those tables is restricted to the server, and the tables that hold form submissions are not readable by the public.
AI processing
Section Q&A sends your question, recent chat messages, and the statutory section context to the AI provider that answers it. The current chat endpoint uses Google Gemini through the AI SDK. Do not paste confidential client files, personal data, privileged material, passwords, one-time passwords, API keys, or financial account details into the chat.
Product analytics and marketing cookies
We use PostHog product analytics in its EU cloud region to understand usage of the site and product. We do not run advertising cookies or third-party marketing widgets, and we do not sell analytics data. Our sign-in, interface-preference, and analytics cookies are listed in the Cookie Policy.
Authentication
Sign-in is handled by a dedicated authentication layer with server-side sessions. Passwords are never stored in plain text. You can sign in with email and password, or with a supported social provider.
Responsible disclosure
If you find a security issue, please tell us before disclosing it publicly. Email hello@complied.ai with steps to reproduce it, and allow us reasonable time to investigate and fix it. We appreciate reports made in good faith.
What is planned
We are an early-stage product and are still maturing our security program. Formal certifications such as SOC 2 or ISO 27001 are not in place yet. As paid plans, saved history, and team features arrive, this page will be updated with the controls that go with them.