Start a free trial
Menu

Trust & security

The security design behind your compliance software

ComplyTrain holds the documents, approvals and records that prove your organisation is in control - so the platform is built to protect them. Every customer is isolated at the database, identity and storage layers, your data is encrypted, and everything runs in the EU by default. This is the security story your auditors will ask about, answered plainly.

Security is built in, not bolted on

ComplyTrain is where your organisation keeps the evidence that proves it is doing what it says it does. That evidence is only as trustworthy as the platform that holds it, so cyber-security runs through the product rather than sitting around the edge of it.

Four things hold that promise together: your data is kept apart from every other customer, it is encrypted, it stays in the EU by default, and every change to it leaves a verifiable trail. Each is covered below - and each is the default for every customer, not an upgrade you have to ask for.

Per-tenant isolation - the silo model

We do not put every customer in one shared database, one pool of identities and one storage bucket and separate them with a filter. Each organisation is a silo of its own, isolated at every layer that matters.

  • A separate database schema

    Your organisation’s data lives in its own database schema - not a shared table filtered by a customer id. One customer cannot see, or accidentally reach, another customer’s records.

  • A separate identity pool

    Sign-in and user identities are held in an identity pool dedicated to your organisation. Credentials from one customer’s pool cannot be used against another.

  • A separate storage bucket

    Uploaded files and documents are kept in a storage bucket of your own, encrypted and held apart from every other customer’s files.

Encryption and cryptographic identity

Every customer’s data is stored securely and encrypted. The signing keys behind an electronic signature are protected with AES-256-GCM encryption, and each organisation has its own certificate authority inside ComplyTrain that issues the certificates those signatures are backed by - so a signature is tied to a specific person and to the exact content they signed.

Signing an approval takes two things together: a biometric check - a fingerprint or face scan on the signer’s own device - and a separate signing password used for nothing else. A shared or stolen login cannot produce a signature, and neither can any automated process.

Hosted in the EU - with a deployment choice

By default, ComplyTrain runs in the European Union, on AWS in the eu-central-1 region. Running the platform does not move your data out of the EU.

Where an organisation needs more control over where the platform runs, there is a choice of deployment:

  • In the EU by default - managed by us on AWS eu-central-1.
  • On a pure EU-based cloud provider - for organisations with a specific sovereign-cloud requirement (Enterprise tier).
  • On-premise, inside your own environment - for organisations that keep everything in-house (Enterprise tier).

Your data, your control, your evidence

Isolation and encryption protect the data. These three principles govern how it is handled.

  • Your data is yours

    The records, documents and evidence you put into ComplyTrain belong to your organisation. We hold them to run the service for you - we do not treat them as ours.

  • A human is always in control

    Approvals and signatures are made by people, never by an automated process. AI can draft and suggest, but a person decides - and a document cannot be approved while any AI suggestion is still waiting for a human to accept or reject it.

  • A tamper-evident audit trail

    Every significant change is recorded in an audit trail that is cryptographically hash-chained. If any record were altered or removed, the chain would break and ComplyTrain would show exactly where - so the evidence an external auditor reviews is verifiable, not merely asserted.

  • Leaving is a clean exit

    If you leave, you get a full export of your data first, and the deletion afterwards is complete. Your schema, your storage and your identity pool are yours alone, so there is nothing of yours entangled in another customer's records to be left behind.

Built for organisations that are audited on how they handle information

ComplyTrain is built by Skylen for organisations that are themselves audited on how they handle information. We design the platform knowing your auditors will ask how their data is held - and knowing the answer has to stand up. That is why the isolation, encryption and audit-trail decisions on this page are the defaults for every customer, and not something reserved for the largest.

Bring your security team - we’ll answer the hard questions

Send us your security questionnaire, or put your security lead in front of the person who built ComplyTrain’s security. We would rather answer the difficult questions now than have them surface during your own audit.