Legal
Security
Access to your data
Comparisons, participants, evidence and notes belong to your workspace. Access is enforced in the database with row-level security and checked again on the server for every request. Admin access is verified on the server from a separate role record, never from settings in the browser.
Private notes
Notes you write on a participant stay private to your account. They are never sent to AI models, never used in external research and never included in a shared report.
Safe page fetching
Websites are fetched only on our servers. We accept http and https addresses only, refuse local, private and reserved network destinations, re-check every redirect, and cap redirects, size, time and the number of pages per analysis. Fetched text is treated as untrusted and instructions inside it are ignored by the analysis.
Share links
Share links use long random tokens that are stored only as a hash. Optional passwords are hashed with PBKDF2. You can add an expiry date or a recipient list, and revoke a link at any time.
Browser protections
The site sends a per-request Content Security Policy, blocks being embedded in other sites and uses HTTPS. Secret keys for AI and research services are kept on the server and never reach the browser.
Reporting a security issue
Found something? Please tell us through the contact form and choose "Support & account". See also our privacy page.
Responsible entity
The legal entity and contact address for CompComp have not been published yet. They will be added here before general availability; nothing is stated until it is confirmed.