Trust Center

We sell trust tooling, so we hold ourselves to the standard we preach: say exactly what we do, claim nothing we don't. Here's how your data is protected today — and what's on our certification roadmap.

Verifiable by design

Proof you can check — not a dashboard you take on faith

Most trust centers ask you to believe a status page. Ours is backed by cryptography: evidence is hash-chained and tamper-evident, and posture can be verified independently — the computation below runs entirely in your browser, with no call to our servers. Flip the tamper switch and watch the math reject it.

Trust Proof — loading… · /acme-corp
signed attestation
· / controls
Fetch published Ed25519 key
Recompute posture hash in your browser
Evidence Merkle root anchored in signature
Verify attestation signature (offline)

A real Ed25519-signed attestation from Compriska's trust protocol. Verify it yourself — the computation runs entirely on your machine.

Security practices

Encryption in transit

All traffic to compriska.com and app.compriska.com is served exclusively over TLS. Plain HTTP is permanently redirected.

Password security

Account passwords are hashed with bcrypt (cost 12) and never stored or logged in plaintext. Password resets use single-use, one-hour tokens and invalidate all active sessions.

Tenant isolation

Every customer workspace is isolated at the data layer — all queries are scoped to your organization, and isolation is covered by our automated tests.

Access control & audit

Role-based access within workspaces, httpOnly session cookies, and an append-only audit log recording security-relevant actions.

AI with guardrails

AI drafting is grounded in your documents with citations, and answers it cannot support are flagged as gaps — never invented. Your content is not used to train models.

Infrastructure

Production runs on hardened Linux infrastructure with automated certificate management, service supervision, and off-machine backups.

Certification roadmap

We publish our roadmap instead of badges we haven't earned. When these are complete, the reports will be available here.

SOC 2 Type II

On our certification roadmap — we run our own program on Compriska itself.

ISO 27001

Planned to follow SOC 2, on the same cross-mapped control base.

ISO 42001

Our AI management system is built to the standard we help customers certify against.

Security questions, disclosure reports, or documentation requests: hello@compriska.com — we respond within one business day.

Want a trust center like this for your company?

Compriska's questionnaire module includes a customer-facing trust portal — publish your posture once, answer fewer questionnaires forever.

Book a demo