CompatoolCompatool

Trust Center

Compatool's Trust Center provides compliance documentation, data-handling policies, and security information for procurement and legal review.

Compliance status

SOC 2 Type II
Planned
Planned — H2 2026
ISO 27001
On request
Not yet pursued
GDPR (data processor)
Live
Compliant — DPA available on Enterprise
UK GDPR
Live
Compliant — same basis as EU GDPR
CCPA
Live
Applicable — see Privacy Policy
Penetration testing
Planned
Planned — H2 2026

Data processing

Compatool acts as a data processor when evaluating submitted agents. We do not use submitted agent code, evaluation traces, or score data for training our own models. A Data Processing Agreement (DPA) is available to Enterprise customers.

  • We process submission data only to provide the evaluation service
  • We do not sell or share submission data with third parties
  • Aggregated, anonymised benchmark statistics may be published
  • You can request deletion of all your data at any time: privacy@compatool.com

Subprocessors

SubprocessorPurposeLocation
CloudflareCompute, storage, CDNUS / global
ClerkAuthenticationUS
StripeBilling (Enterprise/Pro)US

Responsible disclosure

We welcome security researchers. If you discover a vulnerability:

  1. Email security@compatool.com with a description and reproduction steps.
  2. We will acknowledge within 24 hours.
  3. Please allow us 90 days to resolve before public disclosure.
  4. We will credit researchers who follow coordinated disclosure.

We do not pursue legal action against good-faith researchers.

Documents available on request

Procurement teams can request the following documents by emailing hello@compatool.com.

Data Processing Agreement (DPA)

Enterprise plan customers

Request via email
Security overview PDF

All procurement teams

Request via email
Sample signed evaluation report

Prospects evaluating the platform

Request via email
Vendor due diligence questionnaire (completed)

Legal and procurement teams

Request via email
Subprocessor list (full)

Data protection officers

Request via email
SLA document

Enterprise and Pro customers

Request via email

Contact

Security issues
Privacy / data requests
Procurement / legal