Skip to main content
ComplAI
Platform⌄
Platform

See how ComplAI connects controls, data, inventory, and work into one record.

Platform overview ↗
Compliance governanceControls, evidence & decisionsData & CUI contextDiscovery, classification & accessAsset & identity intelligenceBoundary and ownership contextRemediation workflowsFindings, tasks & review historySource integrationsDeployment-scoped ingestion pathsDeployment boundaryCustomer-hosted and cloud patterns
Solutions⌄
Solutions

Start with the program you have to support.

Solutions overview ↗
ATO & continuous ATOFederal authorization lifecycleCMMC Level 2CUI boundary and assessment evidenceMulti-framework assuranceReuse facts, preserve meaningPartner-led deliveryAdvisory, service and channel roles
Resources⌄
Resources

Product, program, and company pages in one place.

Resource center ↗
Framework catalogCoverage and maturity statesIntegrationsSources, paths and claim boundariesNews & mediaAttributable announcementsCommon questionsStable answers before scoping
Company⌄
Company

Who we are, how we work, and how to reach us.

About ComplAI ↗
Trust & responsibilityAccountability and data boundariesPartnersEcosystem and delivery rolesNews & mediaCompany announcementsContactStart a non-sensitive conversationPrivacy noticePublic-site data handlingTerms of usePublic website terms
Pricing
Request a working session ↗

Platform

Platform overviewCompliance governanceData & CUI contextAsset & identity intelligenceRemediation workflowsSource integrationsDeployment boundary

Solutions

Solutions overviewATO & continuous ATOCMMC Level 2Multi-framework assurancePartner-led delivery

Resources

Resource centerFramework catalogIntegrationsNews & mediaCommon questions

Company

About ComplAITrust & responsibilityPartnersNews & mediaContactPrivacy noticeTerms of use
PricingRequest a working session

PUBLIC WEBSITE PRIVACY

Privacy Notice

This notice explains the limited personal information ComplAI processes through the public marketing site and how visitors can ask questions or exercise applicable privacy rights.

Last updated
August 15, 2026
Applies to
ComplAI public website and business contact channels

On this page

Information you provideTechnical informationHow we use informationHow the contact form is deliveredWhen information may be sharedCookies and similar technologiesYour choices and privacy rightsSecurity and sensitive-data boundaryChildren and international visitorsChanges and contact
Contact ComplAI ↗

This notice covers complai.us public marketing pages and public business communications. Customer product environments, assessment records, and contracted services are governed by the applicable agreement, architecture, and customer notice—not this public-site notice.

1. Information you provide

When you request a working session, contact the team, or communicate with ComplAI, we process the information you choose to provide so we can respond and understand the business context.

  • Required contact-form fields: first name, last name, work email, organization, and program path.
  • Optional fields: role or title, phone, hosting environment, organization size, timing, referral source, non-sensitive context, and marketing preference.
  • Business correspondence, meeting details, and follow-up information you provide directly to the team.

2. Technical information

The site and its hosting, content-delivery, and security providers may process ordinary connection and diagnostic information needed to deliver and protect the site. Depending on the request, that can include IP address, browser and device information, requested page, referring page, timestamps, response status, and security events.

The current site does not include third-party advertising pixels, cross-site behavioral tracking, or a third-party analytics product. If that changes, ComplAI will update this notice and add any consent or choice controls the deployment requires.

3. How we use information

ComplAI uses public-site information for the business and operational purposes described below.

  • Respond to inquiries and prepare for requested working sessions.
  • Evaluate product, program, partner, procurement, architecture, and service fit.
  • Operate, secure, troubleshoot, and improve the public site and contact path.
  • Maintain business records, prevent abuse, and comply with applicable legal obligations.
  • Send occasional product or program updates only when the visitor has asked to receive them; the public form does not itself enroll a visitor in an automated campaign.

4. How the contact form is delivered

On the production public site, a validated contact request is sent through a same-origin endpoint and Amazon Simple Email Service to a ComplAI team inbox. The website implementation does not write the submission to a CRM, product environment, assessment system, or customer CUI boundary.

The resulting email is retained under the team mailbox’s operational settings and access controls. ComplAI keeps business correspondence only as long as reasonably needed for the inquiry, relationship, legal obligation, security need, or dispute, then deletes or de-identifies it when practical.

In static review environments, the form does not transmit data and instead offers a prepared email handoff. The page states that boundary before the visitor continues.

5. When information may be shared

ComplAI may disclose limited personal information only as reasonably necessary for the purposes in this notice.

  • To infrastructure and communication providers that host, deliver, secure, or support the public site and business email.
  • To professional advisers when legal, accounting, security, or transaction support requires it.
  • To authorities or other parties when required by law or reasonably necessary to protect rights, safety, systems, or users.
  • As part of a merger, financing, acquisition, reorganization, or transfer of relevant business assets, subject to appropriate confidentiality and legal safeguards.

6. Cookies and similar technologies

ComplAI does not currently use the public site for behavioral advertising or cross-site profiling. The application does not intentionally set advertising or analytics cookies. Hosting and security infrastructure may use technically necessary mechanisms or connection logs to route requests, maintain availability, and prevent abuse.

If optional analytics, scheduling, CRM, or marketing technology is added later, ComplAI will review its data flow, retention, ownership, and consent requirements before enabling it publicly.

7. Your choices and privacy rights

You may decline optional fields and marketing updates. You may also ask ComplAI to access, correct, delete, or restrict use of personal information associated with a public-site inquiry, or withdraw a marketing preference. Applicable rights vary by location and may be subject to identity verification and legal exceptions.

Send a request to cmmc@complai.us with the subject “Privacy request.” Do not include CUI, credentials, assessment evidence, system security plans, or other sensitive program records. ComplAI may ask for limited information needed to verify the request and locate the relevant correspondence.

8. Security and sensitive-data boundary

ComplAI uses reasonable administrative, technical, and organizational measures appropriate to the public-site information it handles. No internet transmission or storage method can be guaranteed completely secure.

Public website forms and ordinary email are not approved channels for CUI, credentials, security plans, evidence packages, detailed system diagrams, customer data, or other sensitive regulated records. If a later engagement requires those materials, ComplAI and the customer must first establish an approved channel and handling boundary.

9. Children and international visitors

The public site is intended for business and government audiences and is not directed to children under 13. ComplAI does not knowingly seek personal information from children through this site.

ComplAI is based in the United States. Public-site information may be processed in the United States and other locations where approved service providers operate, subject to applicable contractual and legal safeguards.

10. Changes and contact

ComplAI may update this notice when the public site, contact path, service-provider inventory, or applicable requirements change. The updated date at the top of the page identifies the current version. Material changes will be presented in a manner appropriate to the change.

Questions about this notice can be sent to cmmc@complai.us. For general product and program questions, use the public contact page and keep the initial description non-sensitive.

ComplAI

Continuous assurance for ATO, cATO, and CMMC. One place to see what is current and show why.

cmmc@complai.us
CAGE: 9RNQ9D&B: 026249007NAICS: 518210

Platform

Platform overviewCompliance governanceData & CUI contextAsset & identity intelligenceRemediation workflowsIntegrationsDeployment boundary

Solutions

Solutions overviewATO / continuous ATOCMMC Level 2Multi-framework assurancePartner-led deliveryPricing & scoping

Resources

Resource centerFramework catalogSource integrationsNews & mediaCommon questionsContact

Company

About ComplAITrust & responsibilityPartnersPrivacy noticeTerms of use

© 2026 ComplAI Inc. All rights reserved.

PrivacyTerms & conditions

Do not submit CUI or credentials through public channels.