Independent verification of how Compliova protects your data, maintains security controls, and upholds our compliance commitments.
Compliance Posture
Information Security Management System — actively implementing all Annex A controls.
Trust Services Criteria for Security, Availability, and Confidentiality.
Data processing agreements, privacy notices, and subject-access request procedures in place.
How We Protect Your Data
All customer data is encrypted using AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed via KMS.
Every user action is scoped by their tenant, role, and permission set. Database-level Row Level Security (RLS) enforces tenant isolation independently of the application layer.
Continuous dependency scanning, quarterly penetration testing by external assessors, and 24-hour SLA for critical CVEs.
Documented IR plan with defined severity tiers, escalation paths, and a customer communication commitment of < 72 hours for confirmed data incidents.
Hosted on AWS in eu-west-1 with multi-AZ redundancy. Real-time uptime monitoring with a 99.9% SLA target.
All sub-processors are contractually bound by DPAs and undergo annual security assessments. See sub-processor list below.
Third-Party Vendors
All sub-processors are bound by data processing agreements and subject to annual security review.
Legal & Privacy
Common Questions
If your organisation uses Compliova, your dedicated Trust Center is available at/trust-center/your-company-slug
or on your configured custom domain.
Security questions or concerns? Contact us at security@compliova.com · Last reviewed: July 2026