Skip to main content
ComplyLoop
How it worksFeaturesPrinciples
Sign in with GitHub

Privacy Policy

How ComplyLoop handles account, repository, and compliance data during early access.

Last updated: 2026-09-10

What we store

  • GitHub account identity (user id, login) when you sign in
  • Encrypted GitHub tokens (user OAuth or App installation tokens) for clone, PR, and Checks
  • Ephemeral clones of connected repositories during assessment, remediation, and PR jobs (deleted after each job)
  • Assessments, findings, remediations, exceptions, and append-only evidence for connected projects

Retention

Evidence is append-only and retained for audit history. Disconnecting a GitHub project removes project-scoped mutable records (requirements, assessments, findings, remediations, alerts) while its evidence rows remain. Deleting an organization erases everything, including its evidence history.

Export and deletion

Organization owners can download a machine-readable JSON export of org-scoped product data and delete the organization from the Organization page. Sign-out clears stored encrypted GitHub tokens for that user. Support-assisted deletion requests are handled within 30 days for early-access pilots — contact your pilot operator.

Subprocessors

Optional AI features send finding context to the configured AI gateway when AI_GATEWAY_API_KEY is set. Error reporting may send diagnostics to Sentry when a Sentry DSN is configured (SENTRY_DSN on the server, optionally NEXT_PUBLIC_SENTRY_DSN in the browser). Hosting and Postgres providers hold application data when you deploy with those services.

ComplyLoop

Compliance engineering for React and Next.js — from requirement to verified evidence.

RGAA / WCAG accessibility

How it worksFeaturesPrinciples
TermsPrivacy