Legal

Security

How CompComp protects your comparisons and reports. CompComp does not currently hold a SOC 2 or ISO 27001 certification of its own; this page describes the controls built into the product.

Access to your data

Comparisons, participants, evidence and notes belong to your workspace. Access is enforced in the database with row-level security and checked again on the server for every request. Admin access is verified on the server from a separate role record, never from settings in the browser.

Private notes

Notes you write on a participant stay private to your account. They are never sent to AI models, never used in external research and never included in a shared report.

Safe page fetching

Websites are fetched only on our servers. We accept http and https addresses only, refuse local, private and reserved network destinations, re-check every redirect, and cap redirects, size, time and the number of pages per analysis. Fetched text is treated as untrusted and instructions inside it are ignored by the analysis.

Share links

Share links use long random tokens that are stored only as a hash. Optional passwords are hashed with PBKDF2. You can add an expiry date or a recipient list, and revoke a link at any time.

Browser protections

The site sends a per-request Content Security Policy, blocks being embedded in other sites and uses HTTPS. Secret keys for AI and research services are kept on the server and never reach the browser.

Reporting a security issue

Found something? Please tell us through the contact form and choose "Support & account". See also our privacy page.

Responsible entity

The legal entity and contact address for CompComp have not been published yet. They will be added here before general availability; nothing is stated until it is confirmed.

CompComp v0.7 Alpha - see also Privacy, Terms and Cookies.