Skip to content

Security and Data Protection at Comma Compliance

Platform Security Overview

Review Comma’s capture architecture, access controls, storage design and operating evidence with your security team. Use the Trust Center for available assessment material and an enterprise evaluation to establish the controls required for your deployment.

Encryption at Every Stage

  • All communications are encrypted in transit using TLS 1.2+ protocols and encrypted at rest with AES-256 encryption.
  • We use cloud-native key management through AWS KMS and Azure Key Vault to control encryption keys securely.

Authentication and Access Management

  • Review user roles, administrative access, multi-factor authentication and identity-provider requirements as part of setup. Identity features depend on deployment enablement.
  • Inspect the audit events available for your required workflows. Confirm event coverage, access and retention rather than assuming every action produces the same evidence.

Continuous Monitoring and Testing

Request the relevant vulnerability-management and penetration-test evidence for your evaluation. Confirm the assessment scope, remaining findings and remediation records with the security team.

External Certifications

  • Request the current SOC 2 audit status and available assessment evidence through our Trust Center. Confirm the scope and status during your security review.
  • Request the current Google OAuth CASA assessment evidence and its scope for Gmail and Workspace integrations.

Infrastructure and Data Storage

Comma uses Amazon Web Services and Microsoft Azure infrastructure. The deployment review should cover the application, archive storage, processing services and source-specific capture infrastructure.

Review these operating requirements:

  • Backup frequency, retention and replication locations
  • Recovery objectives and the procedures used to validate recovery
  • Availability commitments and support responsibilities in your agreement
  • Service history on our live status page

Ask to inspect the storage and retention configuration that applies to your records, along with the supporting evidence. A cloud provider’s storage durability figure is not an application availability commitment.

Data Residency

By default, client data is stored within the United States. Additional regional requirements are reviewed during enterprise deployment planning. Confirm the proposed region, available infrastructure and the locations of records, processing, backups and connector services before rollout. See data residency for the scope of that review.

Data Ownership and Privacy

You retain full ownership of your data.

Comma acts as a secure custodian of your communications, using your information strictly to deliver archiving, compliance, and risk analysis services.

We never sell, rent, or share client data outside of authorized sub-processors directly involved in service delivery.

Business and personal classification is configurable. Review the classification defaults, visibility and export behavior relevant to your sources. Classification settings do not by themselves change what a connector captures.

AI-Driven Compliance Monitoring

Comma’s configured policies analyze communications and route flags into review workflows. Coverage depends on the enabled sources and policy configuration. A flag is a prompt for human review, not a finding. See policy matching for the review workflow.

Key Principles:

  • AI assists but does not replace human oversight.
  • Review the source communication and associated policy when assessing a flag.
  • Clients can adjust, refine, and contribute feedback to improve detection models.
  • No client-specific data is used for system-wide training without explicit consent.

Our automation enhances compliance efficiency while maintaining full transparency.

Regulatory Alignment

Comma is designed against SEC 17a-4, FINRA 4511, CFTC 1.31, and MiFID II electronic-recordkeeping requirements. This is a design statement, not regulatory approval.

The archive connects search and case work with administrative configuration. Discuss retention requirements, preservation workflows and the output formats your recipients need as part of the deployment review. See configuration and controls and e-discovery for the available workflows and their boundaries.

Your organization remains responsible for establishing its obligations and reviewing the controls and evidence that support them.

Frequently Asked Questions

Frequently asked questions

Do you have a recent pen test?
Request the current penetration-test summary, assessment scope and remediation information from security@commacompliance.com. Available restricted assessment material is shared through the security review process.

Contact and Security Reporting

For questions or concerns related to security, or to report a potential vulnerability, please contact our security team directly:

Comma Compliance

Email: security@commacompliance.com

Phone: 888-884-3318

Address: 2261 Market Street STE 22253, San Francisco, CA 94114

For more information on specific key security terms, visit our compliance glossary, or visit our Trust Center for more information on certifications, policies, and controls.

Share this page

More