Legal
Privacy Policy
Last updated: August 4, 2026
1. Who We Are
ComplianceLayer, Inc. ("ComplianceLayer," "we," "us," or "our") operates the ComplianceLayer API and website at compliancelayer.net. We provide infrastructure security scoring services for MSPs and businesses.
If you have questions about this policy, contact us at: privacy@compliancelayer.net
2. Information We Collect
Account Information
When you create an account, we collect your email address, name (optional), and billing information (processed by Stripe — we never store full card numbers).
Usage Data
We collect logs of API requests including: domains scanned, timestamps, API key used, scan results, and IP address of the request origin. This data is used to provide the service, enforce rate limits, and detect abuse.
Payment Data
All payment processing is handled by Stripe, Inc. We receive confirmation of successful payments and subscription status, but never store raw card data. Stripe's privacy policy applies to payment data: stripe.com/privacy
Technical Data
When you visit our website, we collect browser type, referring URLs, and page interaction data using Google Analytics, which sets its own cookies. We do not use advertising networks or sell visitor data. You can block analytics cookies with standard browser tools without affecting the service.
3. How We Use Your Information
- Provide and operate the ComplianceLayer API service
- Process billing and send invoices
- Send service notifications (downtime alerts, scan completions, plan updates)
- Enforce our Terms of Service and Acceptable Use Policy
- Respond to support requests
- Improve the product based on aggregate usage patterns
We do not sell your data to third parties. We do not use your scan results for any purpose other than delivering results to you.
4. Scan Data
Domains you submit for scanning are processed to generate security scores. Scan results are stored in your account history for the duration of your subscription. We do not share individual scan results with other customers or third parties.
Aggregate, anonymized data (e.g., "X% of scanned domains have no DMARC record") may be used in published research or marketing materials. No individual domain results are included in aggregate reports.
5. Data Retention
- Account data: Retained while your account is active, and deleted on request (see Section 7)
- Scan results: Retained while your account is active so that your scan history and reports remain available; deleted with your account on request
- Billing records: Retained for 7 years as required by law
- API logs: Retained for abuse detection and debugging; we periodically review and prune operational logs, but do not currently commit to a fixed automatic expiration window
6. Data Sharing
We share data only with:
- Infrastructure providers — Vultr (hosting) and Cloudflare (DNS, CDN, TLS termination), which necessarily handle all traffic to the service
- Stripe — payment processing
- MXRoute — transactional email delivery
- Sentry — application error monitoring, configured to exclude personal data
- Google Analytics — website usage measurement on our marketing pages, only if you accept analytics cookies
- Scan data sources — when you run a scan, the domain name or server IP being assessed is sent to third-party lookup services (Shodan, ip-api.com, Have I Been Pwned, crt.sh, HackerTarget, Google Safe Browsing, VirusTotal) to retrieve public information about that host. Your account details are never sent to them.
- Integrations you connect — Slack, Microsoft Teams, or Zapier receive scan results only if you enable them
- Law enforcement — only when legally required by valid legal process
The complete, current list with each provider's role and location is maintained in Annex B of our Data Processing Addendum.
We will notify you of any government data requests where legally permitted to do so.
Business customers on whose behalf we process personal data are covered by our Data Processing Addendum, which lists our authorized subprocessors.
7. Your Rights
You may at any time:
- Export your scan history from your dashboard
- Delete your account and associated data (email privacy@compliancelayer.net)
- Request a copy of data we hold about you
- Correct inaccurate account information
Account deletion requests are processed within 30 days. Billing records required by law are retained per Section 5.
8. Security
We use industry-standard practices to protect your data: encryption in transit (TLS 1.2+), encryption at rest, API key hashing, and access controls. No system is perfectly secure — if you discover a vulnerability, please report it to security@compliancelayer.net.
9. Cookies
We use cookies necessary to operate the service (authentication sessions, CSRF protection). Google Analytics cookies for website usage measurement are on by default; you can turn them off at any time, either from the cookie notice shown on your first visit or from the Cookie preferences link in the site footer, and opting out does not affect the service. We do not use advertising cookies and we do not enable Google's advertising or cross-site reporting features. Disabling all cookies will prevent login from working.
10. Children
ComplianceLayer is not directed at children under 13. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, contact us immediately.
11. Visitors from the EEA, UK, and Switzerland
ComplianceLayer is a United States business. We offer our services to customers in the United States, price exclusively in US dollars, and do not target or market to individuals in the European Economic Area or the United Kingdom. We therefore do not treat the EU/UK General Data Protection Regulation as applying to our website visitors, and our website analytics operate on a notice-and-opt-out basis rather than prior consent.
Where we do process personal data on behalf of a business customer who is itself subject to the GDPR, that processing is governed by our Data Processing Addendum, which includes the Standard Contractual Clauses. In that arrangement the customer is the controller and determines the legal basis; we act on their documented instructions. The bases we rely on for our own processing are: performance of a contract (operating your account and delivering scan results), legitimate interests (service security, abuse prevention, product improvement, and measuring website usage), and legal obligation (billing records). Newsletter emails are sent only to people who subscribe, and every one carries a one-click unsubscribe link.
Regardless of where you are located, and as a matter of practice rather than because we are compelled to, we will honour a request to object to or restrict processing, to port your data, or to opt out of analytics. Email privacy@compliancelayer.net; we respond within 30 days.
Our infrastructure and all of our subprocessors are located in the United States, so any data you provide is stored and processed there. We maintain contractual data-protection terms with each of the service providers listed in Section 6.
12. California Residents
We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. The categories of personal information we collect are described in Section 2 (identifiers, commercial information, and internet activity), collected for the purposes in Section 3 and disclosed only to the service providers in Section 6.
California residents may exercise the rights to know, delete, and correct by emailing privacy@compliancelayer.net. We verify requests via the email address associated with your account, respond within 45 days, and do not discriminate against you for exercising your rights. You may designate an authorized agent to submit requests on your behalf.
13. Changes to This Policy
We may update this policy. Material changes will be communicated via email to active customers at least 30 days before taking effect. Continued use of the service constitutes acceptance of the updated policy.
14. Contact
For privacy-related questions or requests:
Email: privacy@compliancelayer.net
ComplianceLayer, Inc.
United States