ComplianceCheck is built for compliance teams, so it is designed around a simple principle: your documents are processed, not stored. This page describes exactly what happens to an uploaded file, which subprocessors are involved, and how the service maps to the regulatory frameworks your vendor assessment will ask about.
The analysis works on product documentation (policy terms and IPID/KID summaries). It needs no personal data, no policyholder records, and no access to your systems. Most customers analyze documents that are already published on their own websites.
Your PDFs are uploaded over TLS to transient storage (Vercel Blob) used only to hand the files to the analysis engine. The analysis runs entirely server-side — API keys and documents never pass through third-party browser code.
The documents are sent to the Claude API (Anthropic) for gap analysis. Anthropic is contractually barred from training models on this data and retains API inputs for a limited operational period (up to ~30 days) before deletion.
As soon as the analysis completes, the uploaded files are deleted from transient storage. The gap report is returned to your browser session and is not persisted on our servers.
Documents and analysis results are never used to train AI models — excluded under Anthropic's commercial API terms, which we rely on contractually.
Uploaded files are deleted from transient storage immediately after the analysis completes. Reports exist only in your browser session and the exports you download.
No person reads your documents. The analysis is fully automated; access to the tool itself is restricted and authenticated.
Documents and findings are never shared with third parties beyond the subprocessors listed below, and never used for any purpose other than producing your report.
A Data Processing Agreement is available on request. Transfers to Anthropic (US) are covered by Standard Contractual Clauses under Anthropic's DPA. Product documents typically contain no personal data at all.
Zero-data-retention processing and EEA in-region inference (AWS Frankfurt / Google Cloud Warsaw) are available for enterprise agreements where policy requires them.
Three subprocessors touch your data, each under its own security certifications:
UKNF cloud communiqué (23 Jan 2020):in our assessment, analyzing published product documents does not involve information protected by law (statutory insurance secrecy) and does not constitute special cloud-based outsourcing, so the communiqué's mandatory regime does not apply to typical use. The classification is always yours to make — if your internal policy requires a UKNF notification, we provide a pre-filled Annex 1 with all provider, service, and data-centre details.
DORA (Regulation 2022/2554): ComplianceCheck is an ICT service supporting a non-critical function — compliance document review assistance, with all regulatory judgment remaining with your team. We offer a contract addendum covering every Art. 30(2) requirement (service description, processing locations, data security, incident assistance, termination rights) and the data points for your register of information.
This page describes our current architecture and terms for vendor assessment purposes. It is not legal advice; classification of outsourcing arrangements remains the responsibility of the supervised entity.
Vendor assessment questionnaire? DPA request? We answer security questions within one business day — jakub@getcompliancecheck.com.