Trust and privacy summary

Know what is retained, what is temporary, and where CMMC boundaries sit.

This page is the buyer-facing summary for the $4,800 USD ComplianceAide CMMC readiness package. It is intended to remove ambiguity before purchase. Contract terms, data-processing addenda, SOC 2 status, references, and counsel-reviewed privacy terms can be reviewed before payment.

Retention

  • Paid workspace artifacts such as readiness reports, SSP planning files, POA&M planning files, and uploaded evidence extracts are retained for the active license term unless the customer requests deletion or exports and closes the workspace.
  • Transient AI processing records, temporary upload files, troubleshooting traces, and short-lived operational buffers may be purged on a much shorter operational schedule.
  • A seven-day purge statement must not be read as deletion of all paid workspace deliverables every seven days.

Hosting

  • The commercial ComplianceAide portal and this checkout path are hosted on Microsoft Azure commercial services.
  • The commercial readiness package is operated from US Azure regions; as of June 19, 2026, the portal resource group is East US and the Function App reports East US 2.
  • The public checkout and commercial readiness workspace are not described as FedRAMP-authorized, Azure Government, GCC High, GovCloud, or a CUI enclave on this page.
  • Public marketing pages may use separate static hosting or content systems, but customer workspace processing for this package is not described as AWS-hosted on this page.
  • Customers who require tenant-specific architecture details should request a vendor review packet before purchase.

Privacy and legal review

  • ComplianceAide does not rely on invalidated legacy transfer frameworks as a current transfer basis.
  • Buyers who need SCCs, DPF status, a DPA, subprocessors, breach-notification terms, insurance details, MSA terms, BAA path, or references can review the Security, SOC 2, and References Packet before submitting payment.
  • Do not submit passwords, export-controlled technical data, CUI, or contract-sensitive files through the public checkout form.
  • Request written confirmation before sending regulated evidence to any AI-assisted workflow; do not assume public OpenAI, Azure OpenAI, or other model processing is approved for CUI without that written path.

Security and SOC 2 status

  • ComplianceAide aligns security practices with recognized security frameworks and reviews those practices as services and obligations evolve.
  • This page does not claim SOC 2 certification, ISO 27001 certification, assessor acceptance, or third-party audit completion.
  • Use the Security, SOC 2, and References Packet to review current buyer-safe posture and request supporting materials before purchase.

Resilience

  • Operational recovery targets are reviewed per customer and deployment path. Placeholder recovery values are not buyer commitments.
  • Readiness documents are designed to be exportable so customers can retain their own copy outside ComplianceAide.
  • For procurement review, request current RTO/RPO, backup, and incident-response commitments before purchase.

CUI, GCC High, FedRAMP, and government enclave boundary

The public checkout page is for starting a readiness engagement and should not receive CUI. The commercial portal is a non-CUI readiness planning workspace unless your contract or security officer approves a separate written handling path. ComplianceAide does not present this public checkout path as FedRAMP Moderate equivalent, Azure Government, GCC High, GovCloud, FIPS-validated, or DFARS 252.204-7012 CUI storage. If your requirement includes CUI, CDI, export-controlled data, FedRAMP equivalency, FIPS-validated cryptography, incident-reporting flow-downs, or a government enclave, contact info@thecomplianceaide.com before purchase so the correct hosting, onboarding, model-processing, and evidence-handling path can be confirmed in writing.

Request our security package before payment if you need current architecture, data-processing, subprocessors, incident-response, insurance, DPA, BAA, SOC 2 / ISO 27001 status, or CUI boundary materials. Start with the Security, SOC 2, and References Packet.