CompScience Trust and Security

Safety is Job 1

Preventing workplace injuries is our mission. That work relies on data you entrust to us: data that represents your business and its most valuable resource, your people. Protecting them and protecting your data is the same promise. It guides everything CompScience does.

Our Commitment

Responsible AI that identifies hazards, not workers, to drive down serious injuries.

Our platform exists to prevent injuries, not to police people. It analyzes workplace environments for hazards and recommends controls to remove the risk. Responsible use is not something we added on top. It is how the product works.

We work with safety experts, regulators, and the workforce itself to get it right, and we hold ourselves to high standards:

Identify the hazards, not the workers

We analyze hazards and unsafe conditions. We do not use facial recognition, gait analysis, or biometrics, we do not identify or track individual workers, and we never install hidden surveillance tools.

Safety by design

The platform is built as a safety coaching tool. It declines to weigh in on individual behavior unless that behavior affects safety, and it is not built to monitor or discipline employees.

People make the call

Our risk intelligence platform surfaces hazards. Your team decides what to do about it.

Openness with your team

We encourage customers to tell their team how CompScience supports workplace safety, and we give workers and clients a direct channel to raise concerns, questions, or issues with our systems.

Your company data is never sold, and never used for advertising.

What Your Data Is For
  • Identifying risk, hazards, and unsafe conditions.
  • Reducing incidents and the total cost of risk.
  • Supporting insurance underwriting, when you bundle it.

Platform Security

Your data lives on secure cloud infrastructure, backed by policy best practices, verified by audit, safety by design.

SOC 2 Type II

Independently audited security

CompScience maintains a SOC 2 Type II report across key trust categories: Security, Confidentiality and Availability. Third-party audit confirms that our controls are not just designed correctly but keep working correctly over time.

Encryption and Infrastructure

  • Data encrypted in transit (TLS 1.2 or higher), and at rest (AES-256).
  • Auditable AWS infrastructure provisioned with Terraform.
  • Continuous monitoring and vulnerability scanning.

Policies and Governance

  • Endpoint protection on employee devices.
  • Internal access limits. Only authorized staff can reach customer data.
  • Annual SOC 2 audits.
  • Regular third-party penetration testing.
  • Over 30 documented information security policies, annual employee training.

Cloud AI and Data Protection

Certain features require advanced reasoning or visual processing. For these, CompScience may use frontier models from three leading AI providers: Anthropic, OpenAI, and Google. All three are governed by contracts and attestations that explicitly prevent indefinite retention and training on your data.

Do the AI providers used by CompScience train their models on our data?

CompScience only uses business tiers across all three providers. Each have explicit contractual commitments not to train their models on data sent through these APIs.

Could our data show up in another customer's AI response?

Because the providers don't train on CompScience's data, that data cannot influence what other customers see. Inputs are processed for the request, returned, and not retained for training.

How is the use of AI providers different from any other technology provider?

The contracts, audits, and encryption standards used by AI providers are the same ones already governing cloud infrastructure industry standards — SOC 2, ISO 27001, GDPR DPAs.

AI providers ensure your data is in safe hands

Paid business tiers only

CompScience never uses the free / consumer tier of any AI provider, where data may be used for training.

Encryption end to end

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256) by every provider.

SOC 2 reports on file

Independently audited security reports from each provider.

Data is not retained by 3rd parties

Providers keep inputs and outputs only for a limited period, solely for abuse monitoring and legal compliance, then delete them. None of it trains a model or goes to a third party, except where law requires longer retention. Each provider publishes its current retention window: AnthropicOpenAI, and Google.

What each provider commits to, in writing
Provider Training on business/API data Security standards Sources
Anthropic Claude API

Commercial Terms state Anthropic may not train on Customer Content from the Services.

SOC 2 Type 2, ISO 27001, ISO 42001
OpenAI OpenAI API

API data not used to train models since March 1, 2023 unless you opt in.

SOC 2 Type 2, ISO 27001, ISO 42001
Google Gemini API, paid

Gemini API, paid

Gemini API, paid
Anthropic Claude API
Training on business/API data

Commercial Terms state Anthropic may not train on Customer Content from the Services.

Security standards

SOC 2 Type 2, ISO 27001, ISO 42001

Sources
OpenAI OpenAI API
Training on business/API data

API data not used to train models since March 1, 2023 unless you opt in.

Security standards

SOC 2 Type 2, ISO 27001, ISO 42001

Sources
Google Gemini API, paid
Training on business/API data

Gemini API, paid

Security standards

Gemini API, paid

Sources

Download the security one-pager

A single printable page covering data handling, platform security, and subprocessors — built for security reviews and vendor questionnaires.

Download One-Pager (PDF)

Questions?

If you have questions, need clarification, or more detailed information, please don't hesitate to reach out.

privacy@compscience.com