Legal

Security

How Compass protects your organization's most sensitive information.

Last updated: March 1, 2026

Our Security Commitment

Security is not an afterthought at Directlink — it is a core design principle. Compass was built from the ground up for regulated industries where data governance, privacy, and auditability are non-negotiable. Below is an overview of the safeguards we have in place.

🔒 Private Cloud Architecture

Each customer's data is stored in a fully isolated environment. Your documents never touch shared infrastructure or third-party AI services.

🛡️ Encryption

All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Sensitive fields are encrypted at the database level.

📋 Audit Logging

Every query, document upload, and administrative action is logged with user, timestamp, and context — examiner-grade records for compliance reviews.

👥 Role-Based Access

Granular role-based access controls ensure users only see what they're authorized to see. Admins can configure permissions at the team and individual level.

🔐 Authentication

Support for SSO (SAML 2.0), multi-factor authentication, and session management with configurable timeout policies.

🚫 No Model Training

Your data is never used to train AI models — ours or anyone else's. Queries and documents remain exclusively within your private environment.

Compliance

Compass is designed to support compliance with:

Vulnerability Disclosure

If you believe you have discovered a security vulnerability in Compass, please report it responsibly to security@directlink.ai. We will acknowledge your report within 48 hours and work to address confirmed issues promptly. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to resolve it.

Data Breach Response

In the unlikely event of a data breach, we will notify affected customers within 72 hours of becoming aware of the incident, consistent with applicable regulations. We maintain an incident response plan that is reviewed and tested regularly.

Security Reviews

We conduct annual third-party penetration tests and ongoing vulnerability assessments. Customers on enterprise plans may request our most recent security documentation under NDA.

Contact Our Security Team

For security questions or to request our security documentation, contact us at security@directlink.ai.