Last updated: March 1, 2026
Our Security Commitment
Security is not an afterthought at Directlink — it is a core design principle. Compass was built from the ground up for regulated industries where data governance, privacy, and auditability are non-negotiable. Below is an overview of the safeguards we have in place.
🔒 Private Cloud Architecture
Each customer's data is stored in a fully isolated environment. Your documents never touch shared infrastructure or third-party AI services.
🛡️ Encryption
All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Sensitive fields are encrypted at the database level.
📋 Audit Logging
Every query, document upload, and administrative action is logged with user, timestamp, and context — examiner-grade records for compliance reviews.
👥 Role-Based Access
Granular role-based access controls ensure users only see what they're authorized to see. Admins can configure permissions at the team and individual level.
🔐 Authentication
Support for SSO (SAML 2.0), multi-factor authentication, and session management with configurable timeout policies.
🚫 No Model Training
Your data is never used to train AI models — ours or anyone else's. Queries and documents remain exclusively within your private environment.
Compliance
Compass is designed to support compliance with:
- SOC 2 Type II
- NCUA and FFIEC examination standards for credit unions and community banks
- GLBA (Gramm-Leach-Bliley Act) data protection requirements
- State privacy regulations including CCPA
Vulnerability Disclosure
If you believe you have discovered a security vulnerability in Compass, please report it responsibly to security@directlink.ai. We will acknowledge your report within 48 hours and work to address confirmed issues promptly. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to resolve it.
Data Breach Response
In the unlikely event of a data breach, we will notify affected customers within 72 hours of becoming aware of the incident, consistent with applicable regulations. We maintain an incident response plan that is reviewed and tested regularly.
Security Reviews
We conduct annual third-party penetration tests and ongoing vulnerability assessments. Customers on enterprise plans may request our most recent security documentation under NDA.
Contact Our Security Team
For security questions or to request our security documentation, contact us at security@directlink.ai.