Policy Compass is built for teams handling regulated, commercially sensitive work. Here's exactly how we store, protect, and never train on your data - and the controls you can check before you trust us with it.
Reflects our Security & Data Handling overview (v1.1, June 2026).
Reflects our Security & Data Handling overview (v1.1, June 2026).
Your prompts, answers, uploaded documents, and chat history are never used to train AI models - by us or by any provider we use. All model traffic runs under Zero Data Retention.
Customer data is stored and processed in EU regions. The database, file storage, and the AI runtime that handles your data all sit in the EU.
AES-256 at rest and TLS 1.2+ in transit - on every connection, from your browser through to the model providers. Session cookies are HTTP-only and Secure.
Row-level security and a dedicated AI runtime for each customer. One customer has no database, network, or filesystem path into another's data - even with a valid session.
You're the data controller; we're your processor. A signed Data Processing Agreement with EU Standard Contractual Clauses and the UK ICO addendum is available with any contract.
Meet George holds the UK government-backed Cyber Essentials certification, covering our technical security controls.
View the certificateHow your data flows
When you ask a research question, it travels a short, encrypted path - and there's no third-party analytics layer anywhere in it.
Your browser sends your question to Policy Compass over HTTPS, where it's authenticated and saved to your account.
Policy Compass passes it to your account's dedicated AI runtime over HTTPS, where the AI agent processes it.
The agent calls the language model through a gateway under Zero Data Retention - the prompt is processed and not stored.
The answer streams back to your browser and is saved to your account.
Every hop uses HTTPS. Your prompts and the AI's responses are never sent to error monitoring - AI content is stripped from every error report before it leaves our systems.
How we use AI
Policy Compass is an AI research tool for specialists. It's designed so you can verify everything it tells you - and to assist your judgement, not replace it.
Research is restricted to authoritative regulatory sources - Ofgem, DESNZ, Elexon, the industry codes - not the open web. Every answer cites the source it drew from, so you can check it against the original.
Different question types trigger different research methods - consultation analysis, code-modification impact, policy review - so the right sources are consulted in the right order, not one generic prompt.
Your prompts, answers, documents and history are never used to train models - by us or our providers. All model traffic runs under Zero Data Retention.
Like any AI tool, Policy Compass can be wrong. It accelerates research; it does not give legal or compliance advice or replace professional judgement. Verify outputs against the cited sources before acting on them.
Sub-processors
A small set of sub-processors helps us run the service - cloud hosting and database, the AI runtime, model providers under Zero Data Retention, plus email, billing, and error monitoring. Each one has a Data Processing Agreement, executed as part of your contract.
We share the complete list - with every sub-processor's purpose and region - on request and as part of any contract, and we give active customers at least 30 days' notice before any material change.
Request the sub-processor listAdditional controls we can enable for your tenant before go-live.
Our full Security & Data Handling overview and Cyber Essentials certificate are available on request.
privacy@policycompass.co.ukNo card, no setup. Your whole team, signed in and ready.
14-day free trial, then £400/month per seat. See pricing