Keep sensitive records out
Do not send CUI, credentials, SSPs, evidence packages, security findings, or detailed system diagrams through public forms or email.
TRUST & RESPONSIBILITY
The platform prepares the record. People make the call. Data stays inside the boundary you set.
HUMAN ACCOUNTABILITY
ComplAI can organize evidence, show relationships, prepare artifacts, route work, and keep history. It does not certify an organization, authorize a system, act as an assessor, or guarantee continued compliance.
System owners and customer leadership stay accountable for the program.
Assessors keep independent assessment responsibilities.
Authorizing officials and designated authorities keep authorization decisions.
Advisors, services, and vendors work inside an agreed scope.
DATA & DEPLOYMENT
Hosting, model use, integrations, and who owns what are confirmed for each deployment. Customer-hosted, commercial cloud, AWS GovCloud, and Azure Government are options — not assumptions.
Do not send CUI, credentials, SSPs, evidence packages, security findings, or detailed system diagrams through public forms or email.
Vendor marks show possible sources. Exact connectors are confirmed per deployment.
Catalog names keep active, registered, or portfolio states. They are not certifications or endorsements.
PUBLIC CLAIMS
We do not publish customer outcomes, certification or authorization status, government-approval language, or efficiency metrics without a source, a scope, and approval.
Prefer a named government or partner source.
Use customer outcomes only with permission, a baseline, and a scope.
Label product views so they cannot be mistaken for customer or assessment results.
Update or remove a claim when the source no longer holds.
NEXT DECISION
Start with a non-sensitive note. Detailed security review belongs in an approved customer channel.