Trust & security
The security design behind your compliance software
ComplyTrain holds the documents, approvals and records that prove your organisation is in control - so the platform is built to protect them. Every customer is isolated at the database, identity and storage layers, your data is encrypted, and everything runs in the EU by default. This is the security story your auditors will ask about, answered plainly.
Security is built in, not bolted on
ComplyTrain is where your organisation keeps the evidence that proves it is doing what it says it does. That evidence is only as trustworthy as the platform that holds it, so cyber-security runs through the product rather than sitting around the edge of it.
Four things hold that promise together: your data is kept apart from every other customer, it is encrypted, it stays in the EU by default, and every change to it leaves a verifiable trail. Each is covered below - and each is the default for every customer, not an upgrade you have to ask for.
Per-tenant isolation - the silo model
We do not put every customer in one shared database, one pool of identities and one storage bucket and separate them with a filter. Each organisation is a silo of its own, isolated at every layer that matters.
A separate database schema
Your organisation’s data lives in its own database schema - not a shared table filtered by a customer id. One customer cannot see, or accidentally reach, another customer’s records.
A separate identity pool
Sign-in and user identities are held in an identity pool dedicated to your organisation. Credentials from one customer’s pool cannot be used against another.
A separate storage bucket
Uploaded files and documents are kept in a storage bucket of your own, encrypted and held apart from every other customer’s files.
Encryption and cryptographic identity
Every customer’s data is stored securely and encrypted. The signing keys behind an electronic signature are protected with AES-256-GCM encryption, and each organisation has its own certificate authority inside ComplyTrain that issues the certificates those signatures are backed by - so a signature is tied to a specific person and to the exact content they signed.
Signing an approval takes two things together: a biometric check - a fingerprint or face scan on the signer’s own device - and a separate signing password used for nothing else. A shared or stolen login cannot produce a signature, and neither can any automated process.
Hosted in the EU - with a deployment choice
By default, ComplyTrain runs in the European Union, on AWS in the eu-central-1 region. Running the platform does not move your data out of the EU.
Where an organisation needs more control over where the platform runs, there is a choice of deployment:
- In the EU by default - managed by us on AWS eu-central-1.
- On a pure EU-based cloud provider - for organisations with a specific sovereign-cloud requirement (Enterprise tier).
- On-premise, inside your own environment - for organisations that keep everything in-house (Enterprise tier).
Your data, your control, your evidence
Isolation and encryption protect the data. These three principles govern how it is handled.
Your data is yours
The records, documents and evidence you put into ComplyTrain belong to your organisation. We hold them to run the service for you - we do not treat them as ours.
A human is always in control
Approvals and signatures are made by people, never by an automated process. AI can draft and suggest, but a person decides - and a document cannot be approved while any AI suggestion is still waiting for a human to accept or reject it.
A tamper-evident audit trail
Every significant change is recorded in an audit trail that is cryptographically hash-chained. If any record were altered or removed, the chain would break and ComplyTrain would show exactly where - so the evidence an external auditor reviews is verifiable, not merely asserted.
Leaving is a clean exit
If you leave, you get a full export of your data first, and the deletion afterwards is complete. Your schema, your storage and your identity pool are yours alone, so there is nothing of yours entangled in another customer's records to be left behind.
Built for organisations that are audited on how they handle information
ComplyTrain is built by Skylen for organisations that are themselves audited on how they handle information. We design the platform knowing your auditors will ask how their data is held - and knowing the answer has to stand up. That is why the isolation, encryption and audit-trail decisions on this page are the defaults for every customer, and not something reserved for the largest.
