Portal workspaces and assessments
Trust information covers MSP portal access, customer workspaces, assessments, evidence handling, generated artifacts, and related services.
Trust & Safety Portal
ComplianceAide protects customer evidence, assessments, generated artifacts, and portal workspaces with a security program built around clear data boundaries, Azure-hosted infrastructure, and evidence-cited AI controls.
Overview
Use this page to understand ComplianceAide's operating boundaries, framework alignment, customer data handling, and security-response practices before procurement or vendor review.
Trust information covers MSP portal access, customer workspaces, assessments, evidence handling, generated artifacts, and related services.
Customer content is used to provide requested services and is not shared across customers or used to train public foundation models.
The program is reviewed against recognized frameworks and updated as the platform, AI workflows, and customer obligations evolve.
FedRAMP 2026 / Machine-readable
ComplianceAide publishes a machine-readable overview using the current official FedRAMP Certification Package Overview JSON schema. It describes readiness, evidence-organization, control-mapping, and package-preparation support.
ComplianceAide is not a FedRAMP-authorized offering, is not represented as FedRAMP certified, and does not make authorization decisions. Schema validation confirms the JSON structure only; it is not an authorization, assessment, or FedRAMP approval.
Framework & Readiness References
These are the public alignment and readiness areas ComplianceAide is tracking for buyers. Formal third-party certification or assessment status is called out only when applicable.
Security-program alignment and buyer-facing control posture mapped to Govern, Identify, Protect, Detect, Respond, and Recover.
Readiness referenceOperational alignment around practical protections for access, devices, network exposure, malware defense, and secure configuration.
Readiness referenceControl-mapping reference for enterprise security, privacy, and assessment narratives across customer-facing trust materials.
Readiness referenceAI risk-management reference for governed, measured, transparent, and human-approved AI compliance workflows.
Readiness referenceReadiness support is available for CMMC Level 2 workflows. Formal third-party assessment status is pending.
PendingData Use
ComplianceAide limits retention and use of submitted prompts, responses, policies, assessments, evidence, and generated work product.
Security Program
ComplianceAide combines platform isolation, secure provider configuration, internal access controls, and monitored infrastructure for customer-facing compliance operations.
Services and data are primarily hosted on Microsoft Azure, with selected external providers used for specialized platform tasks.
ComplianceAide uses TLS for data in transit, performs regular backups, and limits customer-content retention based on operational and legal needs.
Internal privileges follow least-privilege principles, critical security events are logged, and credentials are protected with strong policies and MFA.
Employee endpoints and cloud infrastructure instances use disk encryption. Corporate devices run endpoint detection and response tooling, and centralized management helps enforce consistent policies.
Firewalls and network policies help regulate traffic. Network activity is centrally logged, with detection logic used to identify anomalies and potential threats.
Incident Response & Continuity
ComplianceAide maintains incident-response, vulnerability-management, and business-continuity practices for platform resilience.
Security events are identified, contained, escalated, and remediated through a documented incident-response process.
Infrastructure and applications are continuously scanned, independent testing is used where appropriate, and critical patches are handled on an expedited schedule.
Recovery objectives are reviewed as platform capabilities and customer obligations evolve, with periodic disaster recovery exercises.
Responsible Disclosure
ComplianceAide welcomes responsible reports from the security community and investigates valid submissions for appropriate remediation.