Portal workspaces and assessments
Trust information covers MSP portal access, customer workspaces, assessments, evidence handling, generated artifacts, and related services.
Trust & Safety Portal
ComplianceAide protects customer evidence, assessments, generated artifacts, and portal workspaces with a security program built around clear data boundaries, Azure-hosted infrastructure, and evidence-cited AI controls.
Overview
Use this page to understand ComplianceAide's operating boundaries, framework alignment, customer data handling, and security-response practices before procurement or vendor review.
Trust information covers MSP portal access, customer workspaces, assessments, evidence handling, generated artifacts, and related services.
Customer content is used to provide requested services and is not shared across customers or used to train public foundation models.
The program is reviewed against recognized frameworks and updated as the platform, AI workflows, and customer obligations evolve.
Certifications & Framework Readiness
These are the public alignment and readiness areas ComplianceAide is tracking for buyers. Formal third-party certification or assessment status is called out only when applicable.
Security-program alignment and buyer-facing control posture mapped to Govern, Identify, Protect, Detect, Respond, and Recover.
AlignedOperational alignment around practical protections for access, devices, network exposure, malware defense, and secure configuration.
TrackedControl-mapping reference for enterprise security, privacy, and assessment narratives across customer-facing trust materials.
MappedAI management-system readiness paired with NIST AI RMF thinking for governed, human-approved AI compliance workflows.
TrackedReadiness support is available for CMMC Level 2 workflows. Formal assessment or authorization status is pending.
PendingData Use
ComplianceAide limits retention and use of submitted prompts, responses, policies, assessments, evidence, and generated work product.
Security Program
ComplianceAide combines platform isolation, secure provider configuration, internal access controls, and monitored infrastructure for customer-facing compliance operations.
Services and data are primarily hosted on Microsoft Azure, with selected external providers used for specialized platform tasks.
ComplianceAide uses TLS for data in transit, performs regular backups, and limits customer-content retention based on operational and legal needs.
Internal privileges follow least-privilege principles, critical security events are logged, and credentials are protected with strong policies and MFA.
Employee endpoints and cloud infrastructure instances use disk encryption. Corporate devices run endpoint detection and response tooling, and centralized management helps enforce consistent policies.
Firewalls and network policies help regulate traffic. Network activity is centrally logged, with detection logic used to identify anomalies and potential threats.
Incident Response & Continuity
ComplianceAide maintains incident-response, vulnerability-management, and business-continuity practices for platform resilience.
Security events are identified, contained, escalated, and remediated through a documented incident-response process.
Infrastructure and applications are continuously scanned, independent testing is used where appropriate, and critical patches are handled on an expedited schedule.
Recovery objectives are reviewed as platform capabilities and customer obligations evolve, with periodic disaster recovery exercises.
Responsible Disclosure
ComplianceAide welcomes responsible reports from the security community and investigates valid submissions for appropriate remediation.