Compliance PreCheck analyzes regulated policy and compliance documents on behalf of organizations — many in federal, healthcare, financial services, and defense contexts. Data stewardship is not a nice-to-have; it's the product. This page documents how we handle your data, what security controls are in place today, and what we're building next.
Last updated: April 20, 2026
Compliance PreCheck is hosted entirely on Amazon Web Services in the us-east-2 region (Ohio). No customer data leaves the continental United States during normal operation, except when sent to our analysis vendor as described in AI vendor posture.
All traffic to complianceprecheck.com and our subdomains is served over TLS 1.2 or higher, with TLS 1.0 and 1.1 explicitly disabled at our load balancer. Certificates are issued by AWS Certificate Manager and rotated automatically. HSTS is enforced.
All persistent storage is encrypted with AES-256:
Key material is managed by AWS KMS. We do not hold, export, or have direct access to private key bytes.
A compliance check takes your document and evaluates it claim-by-claim against the regulatory frameworks you select. Here is every place your document goes:
We do not use your documents to train AI models. Neither we nor Anthropic fine-tune or pre-train any model on your uploads. See Anthropic's Commercial Terms for their zero-retention commitment on API traffic.
Compliance PreCheck uses Anthropic's Claude API for document analysis. Two things matter about this relationship:
If your procurement policy requires AI vendor attestations, we're happy to share Anthropic's relevant documentation and a data flow diagram on request.
HttpOnly, Secure, and SameSite=LaxWe retain your documents and reports for as long as your account is active so that you can review them later. If you want something deleted sooner, we'll delete it — email support@ailaunchpods.com from the address on your account and we'll remove the specified report, document, and all associated findings within 30 days (typically within 48 hours).
If you close your account, we delete uploaded documents and generated findings within 30 days of account closure. We retain billing records (invoices, Stripe transaction IDs) for seven years to satisfy tax and financial audit obligations, as required by law.
Logs (application, access, error) are retained for 90 days and then rotated out.
Vendors that process customer data on our behalf, what they do, and where they are:
We will update this list whenever a subprocessor is added or changed. If your agreement requires advance notification of subprocessor changes, let us know during onboarding and we'll honor a 30-day notice.
We monitor application errors, authentication anomalies, and background-worker failures continuously. If we identify a security incident that affects customer data, we commit to:
Security researchers and customers who believe they've found a vulnerability should email support@ailaunchpods.com with details. We won't pursue legal action against good-faith researchers who follow responsible disclosure.
We're a young product and we're transparent about where we are. We do not currently hold third-party security certifications. Here's what's on the roadmap:
If your procurement process blocks on a specific certification, tell us — it helps us prioritize, and in some cases we can provide compensating documentation (security questionnaires, data flow diagrams, subprocessor lists, customized DPAs) that may unblock you.
Security questions, vulnerability reports, vendor assessment questionnaires, or custom DPA requests: support@ailaunchpods.com.
Privacy rights (access, correction, deletion, portability): see our Privacy Policy.