Policy Compass
Trust Centre

Your data stays yours.

Policy Compass is built for teams handling regulated, commercially sensitive work. Here's exactly how we store, protect, and never train on your data - and the controls you can check before you trust us with it.

Bold flat-vector illustration of a calm professional in an orange jumper safeguarding glowing documents in a secure vault, with a vault door, padlock, brass key and shield
EU-hosted AES-256 encrypted Zero Data Retention Cyber Essentials certified GDPR-ready DPA

Reflects our Security & Data Handling overview (v1.1, June 2026).

We never train on your data

Your prompts, answers, uploaded documents, and chat history are never used to train AI models - by us or by any provider we use. All model traffic runs under Zero Data Retention.

EU data residency

Customer data is stored and processed in EU regions. The database, file storage, and the AI runtime that handles your data all sit in the EU.

Encrypted in transit and at rest

AES-256 at rest and TLS 1.2+ in transit - on every connection, from your browser through to the model providers. Session cookies are HTTP-only and Secure.

Isolated per customer

Row-level security and a dedicated AI runtime for each customer. One customer has no database, network, or filesystem path into another's data - even with a valid session.

GDPR-aligned, DPA on offer

You're the data controller; we're your processor. A signed Data Processing Agreement with EU Standard Contractual Clauses and the UK ICO addendum is available with any contract.

Cyber Essentials certified

Meet George holds the UK government-backed Cyber Essentials certification, covering our technical security controls.

View the certificate

How your data flows

Encrypted end to end, with nothing watching on the side.

When you ask a research question, it travels a short, encrypted path - and there's no third-party analytics layer anywhere in it.

  1. 1

    Your browser sends your question to Policy Compass over HTTPS, where it's authenticated and saved to your account.

  2. 2

    Policy Compass passes it to your account's dedicated AI runtime over HTTPS, where the AI agent processes it.

  3. 3

    The agent calls the language model through a gateway under Zero Data Retention - the prompt is processed and not stored.

  4. 4

    The answer streams back to your browser and is saved to your account.

Every hop uses HTTPS. Your prompts and the AI's responses are never sent to error monitoring - AI content is stripped from every error report before it leaves our systems.

How we use AI

Built to be checked, not taken on faith.

Policy Compass is an AI research tool for specialists. It's designed so you can verify everything it tells you - and to assist your judgement, not replace it.

Grounded in authoritative sources

Research is restricted to authoritative regulatory sources - Ofgem, DESNZ, Elexon, the industry codes - not the open web. Every answer cites the source it drew from, so you can check it against the original.

Workflows tuned to the question

Different question types trigger different research methods - consultation analysis, code-modification impact, policy review - so the right sources are consulted in the right order, not one generic prompt.

Never trained on your data

Your prompts, answers, documents and history are never used to train models - by us or our providers. All model traffic runs under Zero Data Retention.

It can make mistakes - keep a human in the loop

Like any AI tool, Policy Compass can be wrong. It accelerates research; it does not give legal or compliance advice or replace professional judgement. Verify outputs against the cited sources before acting on them.

Sub-processors

A short list, shared in full when you need it.

A small set of sub-processors helps us run the service - cloud hosting and database, the AI runtime, model providers under Zero Data Retention, plus email, billing, and error monitoring. Each one has a Data Processing Agreement, executed as part of your contract.

We share the complete list - with every sub-processor's purpose and region - on request and as part of any contract, and we give active customers at least 30 days' notice before any material change.

Request the sub-processor list

GDPR & your rights

  • You own your data. You keep all rights to what you put in and what you get out - your questions, documents, and research. We claim no ownership of it.
  • Controller and processor. Under GDPR you're the controller and Meet George is your processor. A signed DPA is available with any contract.
  • International transfers. Where a sub-processor sits outside the EU/UK, transfers are covered by EU Standard Contractual Clauses and the UK ICO addendum.
  • Data-subject requests. Access, rectification, erasure, restriction, portability, and objection are actioned within 30 days.
  • Breach notification. We notify you of any confirmed personal-data breach affecting your tenant within 72 hours of becoming aware.
  • Retention and deletion. Data is kept for the contract term and a defined period after, then deleted - and within 30 days of your instruction on close.

On enterprise contract

Additional controls we can enable for your tenant before go-live.

  • Single Sign-On (SAML / OIDC) and MFA enforcement, by arrangement - talk to us about your identity provider
  • Signed DPA with EU SCCs and the UK ICO addendum
  • Customer-specific data-retention configuration
  • Customer-initiated data export and deletion
  • Named security contact and incident-notification commitments

Questions or a security questionnaire?

Our full Security & Data Handling overview and Cyber Essentials certificate are available on request.

privacy@policycompass.co.uk

Your expertise. Multiplied.

No card, no setup. Your whole team, signed in and ready.

14-day free trial, then £400/month per seat. See pricing

Cyber Essentials Certified
UK/EU data residency
GDPR compliant