Where your documents go — and where they don't

ComplianceCheck is built for compliance teams, so it is designed around a simple principle: your documents are processed, not stored. This page describes exactly what happens to an uploaded file, which subprocessors are involved, and how the service maps to the regulatory frameworks your vendor assessment will ask about.

The analysis works on product documentation (policy terms and IPID/KID summaries). It needs no personal data, no policyholder records, and no access to your systems. Most customers analyze documents that are already published on their own websites.

Three steps, zero retention

01
🔒

Encrypted upload

Your PDFs are uploaded over TLS to transient storage (Vercel Blob) used only to hand the files to the analysis engine. The analysis runs entirely server-side — API keys and documents never pass through third-party browser code.

02

AI analysis

The documents are sent to the Claude API (Anthropic) for gap analysis. Anthropic is contractually barred from training models on this data and retains API inputs for a limited operational period (up to ~30 days) before deletion.

03
🗑

Immediate deletion

As soon as the analysis completes, the uploaded files are deleted from transient storage. The gap report is returned to your browser session and is not persisted on our servers.

What we never do with your documents

🚫

No model training

Documents and analysis results are never used to train AI models — excluded under Anthropic's commercial API terms, which we rely on contractually.

No storage beyond the analysis

Uploaded files are deleted from transient storage immediately after the analysis completes. Reports exist only in your browser session and the exports you download.

👥

No human review

No person reads your documents. The analysis is fully automated; access to the tool itself is restricted and authenticated.

📤

No resale or sharing

Documents and findings are never shared with third parties beyond the subprocessors listed below, and never used for any purpose other than producing your report.

🇪🇺

GDPR-ready

A Data Processing Agreement is available on request. Transfers to Anthropic (US) are covered by Standard Contractual Clauses under Anthropic's DPA. Product documents typically contain no personal data at all.

🔐

Stronger options for enterprise

Zero-data-retention processing and EEA in-region inference (AWS Frankfurt / Google Cloud Warsaw) are available for enterprise agreements where policy requires them.

A short, certified chain

Three subprocessors touch your data, each under its own security certifications:

Vercel — hosting & transient storage
Serves the application and holds uploaded files only for the duration of the analysis. ISO 27001 and SOC 2 Type 2 certified.
Anthropic — AI analysis (Claude API)
Performs the document analysis. SOC 2 Type 2 certified; DPA with Standard Contractual Clauses; no training on customer data; limited operational retention with zero-data-retention available for enterprise agreements.
Zoho (EU) — email
Handles our correspondence with you. Hosted in EU data centres. Your analyzed documents never pass through email unless you send them to us yourself.

Built with KNF and DORA in mind

UKNF cloud communiqué (23 Jan 2020):in our assessment, analyzing published product documents does not involve information protected by law (statutory insurance secrecy) and does not constitute special cloud-based outsourcing, so the communiqué's mandatory regime does not apply to typical use. The classification is always yours to make — if your internal policy requires a UKNF notification, we provide a pre-filled Annex 1 with all provider, service, and data-centre details.

DORA (Regulation 2022/2554): ComplianceCheck is an ICT service supporting a non-critical function — compliance document review assistance, with all regulatory judgment remaining with your team. We offer a contract addendum covering every Art. 30(2) requirement (service description, processing locations, data security, incident assistance, termination rights) and the data points for your register of information.

This page describes our current architecture and terms for vendor assessment purposes. It is not legal advice; classification of outsourcing arrangements remains the responsibility of the supervised entity.

Ask us anything about data handling

Vendor assessment questionnaire? DPA request? We answer security questions within one business day — jakub@getcompliancecheck.com.