Identity
- SSO via OIDC / SAML 2.0
- Mandatory MFA for admins
- Session expiry & idle timeout
- Service account scoping
Compliance teams know what good controls look like. We built CompStack to the same bar, because the platform itself sits inside our customers' audit scope.
The non-negotiables. Same on day one as on day a thousand.
Per-organization row-level isolation across requirements, documents, evidence, audits, CAPA, risk, and AI context. Verified at every query.
Admin · manager · auditor · viewer. Plus site-level access boundaries, useful when one tenant runs many sites under different leadership.
Authors cannot approve their own documents. CAPA verifiers cannot be the CAPA owner. Enforced at the database level, not advisory.
Every scope change, approval, evidence acceptance, and AI action is recorded with actor, timestamp, and prior state. Append-only.
TLS 1.3 in transit. AES-256 at rest. Time-limited signed URLs for evidence, no public file links, ever.
Choose a region for your tenant: EU, US, or Africa. Cross-region replication is opt-in, not default.
A condensed view of the SOC 2 / ISO 27001-style controls we operate. Full evidence pack available under NDA.
Our IR plan, in five sentences.
Each sub-processor has a contract that prohibits using your data for anything outside the stated purpose.
We respond within one business day. Coordinated disclosure preferred. We credit researchers in our disclosure log.
PGP key on /pgp.txt. Encrypt anything sensitive.
We pay for impactful findings on a per-case basis. Hall of fame list maintained.
Social engineering, physical attacks, denial-of-service, and findings against staging without prior coordination.
Available under NDA in 24 hours. We have a vendor security questionnaire pre-filled in CSV, saves your team a week.