Trust
Trust
Plain facts about where data goes, who processes it, and how to get it out or have it removed.
Data flow
| Setup | What happens to your data |
|---|---|
| CLI on its own | Nothing leaves your environment. The CLI runs in your CI or on your machine. |
| CLI connected to the hosted service | A closed list of metadata fields, documented in the docs. No source code. The hosted service accepts a push only with a project API key. |
| Hosted service | Hosted on Vercel in Frankfurt, data stored on Neon in Frankfurt, and transactional email sent through Brevo in the EU. |
Sub-processors
| Name | Service | Location |
|---|---|---|
| Vercel | Hosting of the web application and APIs, including the ingestion API | Frankfurt, Germany (fra1 region); requests pass through Vercel's global edge network |
| Neon | Managed Postgres database that stores Service data | Frankfurt, Germany (AWS eu-central-1) |
| Brevo | Transactional email: sign-in links, invitations, welcome emails and support-ticket notifications | European Union |
Changes are published in two places: the sub-processor change feed and the email notice described in the DPA. The full list is in DPA Annex 3, and the notice terms are in section 6 of the DPA.
Deletion and export
- Export. An organisation admin can download an export of the organisation's data as a zip file: one NDJSON file per tenant table plus a manifest.
- Close. An organisation admin can close the organisation. API keys stop working at once and ingest answers 401. A platform operator can restore a closed organisation.
- Purge. A platform operator purges a closed organisation after a typed confirmation, which deletes the organisation's rows. The 30-day purge due date shown to operators is informational: no purge runs on a schedule.
- Audit records. Audit records are kept after a purge. They are append-only and carry the organisation id and the operator's typed reason, not names or emails.
- User erasure and retention. User erasure and a retention purge are run by an operator on request, dry run first.
To request any of these, write to hello@opencomplai.com.
Security contact
Report a vulnerability as described in our security.txt. Our general security practices are on the security page.
Support
What to expect from support is on the support policy page.