Skip to content
Security

Security you can reason about.

ComplyMo touches your visitors’ consent choices, so we treat that data carefully: encrypted, isolated per tenant, and never sold. Here is exactly how it works.

How we protect data

Encrypted, isolated, least-privilege.

Data is encrypted in transit and at rest. Internal access follows the principle of least privilege — people and services get only the access their job requires. And every customer’s data is isolated per tenant, so one account can never reach another’s. We follow industry-standard security practices rather than reinventing them.

How the widget is safe

It sits lightly on your page.

The script loads asynchronously, so it never blocks your content from rendering. It is built to live inside a strict Content-Security-Policy. Consent logs are pseudonymous — enough to prove a choice was recorded, without profiling anyone — and we never sell personal data or hand it to ad networks.

Loads async CSP-friendly Pseudonymous logs No PII sold
Our practices

The controls behind the promise.

Encryption everywhere

TLS for data in transit and encryption at rest. Traffic between your site, the widget, and our services stays encrypted end to end.

Least-privilege access

Internal access is scoped to what a role needs and nothing more, with access reviewed regularly and audit trails kept.

Per-tenant isolation

Each customer’s data is logically isolated. One tenant can never read another tenant’s consent records or settings.

Async, CSP-friendly widget

The script loads asynchronously and is designed to sit comfortably inside a strict Content-Security-Policy — it never blocks your page.

Pseudonymous consent logs

Consent records are stored pseudonymously — enough to prove a choice was made, without building a profile of the visitor.

No selling of PII

We do not sell personal data and we do not share it with ad networks. Your visitors’ data works for compliance, nothing else.

Reliability

The widget is served from a global edge and fails open — if it cannot reach us, your page still loads normally. We monitor uptime continuously and design for graceful degradation rather than hard failures.

Responsible disclosure

Found something? We want to hear about it. Email security@complymo.com and we will acknowledge your report, investigate, and keep you updated as we fix it.

Compliance, handled.

Passes WCAG 2.2 AA. No contract, no contact-sales wall.

ComplyMo

Compliance, handled
— in five minutes.

Accessibility, GDPR, and cookies. One script. One price. 14 days free.