Legal

Privacy Policy

What information ComplianceAnvil collects, how it is used, who it is shared with, and the choices you have.

Effective date
August 7, 2026
Last updated
August 7, 2026

This Privacy Policy explains how Forge Technology Solutions LLC, the veteran owned and operated United States company behind ComplianceAnvil™, handles information when you visit our website and use our platform. We describe only practices we actually implement.

This document is materially complete and ready for owner and professional review. It has not been reviewed or approved by an attorney.

Owner policy decision required

The following rules are intentionally left undecided rather than invented. They must be set by the business before this document is treated as final.

  • Final retention periods for closed accounts and for uploaded evidence after deletion.
  • Whether to publish a designated privacy contact mailbox separate from support@complianceanvil.com.

1. Scope of this policy

This policy covers www.complianceanvil.com and the ComplianceAnvil application.

We act in two different roles:

  • For information about our own customers — account holders and organization owners — we decide how the information is used.
  • For information you upload into your workspace about your employees, contractors, vendors, or customers, you decide how it is used and we process it on your instructions to provide the Service. You are responsible for having a lawful basis for that information and for informing the people it concerns.

This policy does not cover third-party websites we link to, or your own organization's internal privacy practices.

2. Account information we collect

When you create an account or sign in we collect:

  • your name, as you provide it;
  • your email address;
  • your authentication credentials — passwords are stored only as salted hashes by our authentication provider and are never visible to us;
  • if you sign in with Google, the basic profile information Google returns for that sign-in (name, email address, and account identifier); and
  • your role and membership status within an organization workspace.

We do not collect your password when you use Google sign-in.

3. Organization and business profile information

To generate a readiness program we collect the business details you provide, which typically include:

  • organization and legal entity name;
  • industry, business type, and size, including employee and contractor counts;
  • location and operating footprint;
  • contracting context, such as whether you hold or pursue government contracts and which frameworks apply to you;
  • your technology environment as you describe it;
  • assessment answers, readiness scores, and gap results;
  • control implementation status, notes, and remediation plans;
  • POA&M items, risks, vendors, and incident records you create; and
  • training assignments, course progress, knowledge-check results, and completion certificates for the members you enroll.

4. Payment information

Payments are processed by Stripe, Inc.

We never receive or store your full card number, card expiration, card security code, or bank account credentials. Those go directly to Stripe.

From Stripe we receive and store only what we need to run your account: a Stripe customer identifier, a subscription or purchase identifier, the plan and price purchased, the amount, currency, billing period dates, payment status, the billing email, and the billing environment. We use these to activate your entitlements, show your billing history, and support you.

Stripe processes your payment details under its own privacy policy and may collect information such as your billing address and device information for fraud prevention.

5. Uploaded documents and evidence

The Service lets you upload and generate compliance material: policies, procedures, System Security Plans, screenshots, configuration exports, training records, and other evidence.

  • We store this material to provide the Service to your organization.
  • We do not use it to train artificial intelligence models.
  • We do not sell it and we do not use it for advertising.
  • We do not review or validate it, except where we must investigate a security incident, respond to a support request you initiate, or comply with a legal obligation.
  • Files are stored in private storage with tenant-scoped paths, access rules enforced on the server, and time-limited download links.
  • Organization owners and administrators can access, export, and delete this material.

Please do not upload classified information, or controlled unclassified information beyond what your plan and your own authorization permit, and do not upload payment card or health information unless we have confirmed a suitable configuration with you in writing.

6. Technical and log information

When you use the Service, our infrastructure automatically records operational information, including:

  • IP address;
  • browser type, version, and general device information;
  • pages and features accessed, and the time of access;
  • referring page;
  • request and error logs from our application and database; and
  • authentication events, such as sign-in attempts and password resets.

We also record security and audit events inside the application — for example who changed a role, approved a document, activated a program pack, downloaded evidence, or changed billing state — together with the actor, timestamp, and relevant context. These records are append-only and cannot be edited or deleted through the application, because their integrity is what makes them useful for your own compliance program.

We use this information to operate the Service, investigate errors, detect and prevent abuse, enforce rate limits, and maintain security.

7. Cookies and local storage

We use cookies and browser storage that are necessary for the Service to function:

  • authentication and session storage, so you stay signed in;
  • security tokens that protect against cross-site request forgery;
  • preferences, such as interface settings; and
  • limited local storage that preserves in-progress work — for example a partially completed assessment or a program recommendation — so it survives a page reload or a sign-up step.

We do not use advertising cookies and we do not participate in cross-site advertising networks. See our Cookies notice for more detail.

8. Analytics

We use privacy-respecting product analytics provided through our hosting platform to understand aggregate usage — which pages are visited, which features are used, and where errors occur — so we can improve the Service.

We use this in aggregate. We do not use analytics to build advertising profiles, and we do not sell analytics data.

9. AI processing

Some features generate or assist output using artificial intelligence models accessed through our platform's AI gateway.

When you use such a feature:

  • the specific content needed for that request — for example your business profile summary, a control description, or a document prompt — is sent to the model provider to produce the response;
  • we do not send your uploaded evidence files to model providers as part of routine operation;
  • we do not authorize model providers to use your content to train their models; and
  • output is returned to your workspace and stored with your content.

AI output must be reviewed by a qualified person in your organization before you rely on it. It is not legal advice, a compliance determination, an assessor finding, or a certification. See our Disclaimer.

10. How we use information

We use information to:

  • create and administer your account and organization workspace;
  • provide the readiness assessment, scoring, program packs, control workspace, documents, training, and evidence features;
  • process payments, activate and enforce plan entitlements, and manage renewals, upgrades, downgrades, and cancellations;
  • send transactional email you would expect — sign-in and verification messages, password resets, receipts, billing notices, training assignments, approval requests, and support replies;
  • respond to your support requests;
  • maintain security, authenticate users, detect and prevent fraud and abuse, and enforce our Terms;
  • keep the audit and security records described above;
  • diagnose and fix problems, and improve the Service; and
  • comply with legal obligations.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

Marketing email, if we send any, is limited to customers and interested contacts and always includes a one-click unsubscribe. Unsubscribing does not stop transactional messages needed to operate your account.

11. Service providers we share information with

We share information only as needed with providers who process it on our behalf under contract:

ProviderPurposeWhat it receives
Stripe, Inc.Payment processing, subscription billing, tax calculationBilling email, purchase and subscription details, payment method data you enter directly with Stripe
Our cloud application and database platformHosting, database, authentication, file storageAccount, organization, workspace content, uploaded files, logs
Our managed email delivery providerSending transactional and authentication emailRecipient email address, message content, delivery outcome
Our AI gateway and model providersGenerating AI-assisted output you requestOnly the content included in the specific request

These providers are permitted to use the information only to provide their service to us.

We may also share information:

  • with other members of your own organization, according to the roles your organization assigns;
  • when you direct us to, such as sharing a document or a verification link;
  • with professional advisors, such as accountants and lawyers, under confidentiality;
  • to comply with law, a valid legal process, or a lawful government request, and to protect our rights, your safety, or the security of the Service; and
  • in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify you and the acquirer must honor this policy or give you notice before changing it.

Internal support notifications may be routed to a Forge Technology Solutions staff mailbox so a ticket is never lost. Customer-facing correspondence always comes from the ComplianceAnvil support identity.

12. Data retention

We retain information for as long as your account is active and for as long as needed to provide the Service.

  • Workspace content — assessments, documents, controls, POA&M items, training records, evidence — is retained while your organization exists so you can maintain a continuous compliance history.
  • Content you delete is removed from the application promptly and purged from routine backups within the backup rotation period.
  • Billing records are retained as long as required for tax, accounting, and dispute-resolution purposes.
  • Audit and security events are append-only and retained for the life of the account, because their integrity is the point of keeping them.
  • Closed accounts are retained for a limited grace period so you can export or reactivate, then deleted.

Exact retention periods for closed accounts and deleted evidence are an outstanding owner policy decision, noted at the top of this page. Until it is recorded, we retain closed-account data no longer than necessary and honor deletion requests as described below.

13. Security practices

We implement the following controls. We describe only what is actually in place.

  • Encryption in transit using TLS, and encryption at rest for our database and file storage.
  • Row-level security in the database so a request can only reach rows belonging to the requester's own organization.
  • Server-side enforcement of authorization and plan entitlements. Client-side checks are treated as presentation only and are never trusted.
  • Private file storage with tenant-scoped paths and time-limited, signed download links.
  • Separation between our test and live payment environments, so activity in one cannot alter the other.
  • Signature verification on incoming payment webhooks, with duplicate-delivery protection.
  • Passwords stored only as salted hashes, and a check against known-breached password lists at sign-up and password change.
  • Short administrative sessions and a requirement to re-authenticate recently before sensitive administrative actions.
  • Rate limiting and abuse controls on public forms and authentication endpoints.
  • Append-only audit and security event logging.
  • Least-privilege access for our own staff, limited to what is needed to operate and support the Service.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for safeguarding your credentials and managing access within your organization.

We do not claim any third-party security certification, attestation, or audit report — including SOC 2, ISO 27001, FedRAMP, or CMMC — for the ComplianceAnvil platform itself. If that changes, we will say so specifically and name the report.

If you believe you have found a vulnerability, email support@complianceanvil.com. Please do not test against other customers' data.

14. Your choices

You can:

  • view and correct your account and business profile information in the application;
  • export the documents and records your plan supports exporting;
  • unsubscribe from any marketing email using the link in the message;
  • decline optional AI features by not using them;
  • ask your organization owner about content that belongs to your organization rather than to you personally; and
  • close your account.

Depending on where you live, you may have additional rights — such as to access, correct, delete, or receive a copy of your personal information, or to object to certain processing. We honor these requests as required by applicable law and will not discriminate against you for making one.

15. Access and deletion requests

To request access to, correction of, or deletion of your personal information, email support@complianceanvil.com from the address on your account and describe what you need.

  • We will verify your identity before acting, usually by confirming control of the account email.
  • We will respond within 30 days, or sooner where the law requires it, and will tell you if we need more time.
  • If you are an employee or member within a customer's workspace, we will refer your request to the organization that controls that workspace and support them in fulfilling it.
  • We may retain information we are legally required to keep, such as billing records and append-only audit events, and will tell you when that applies.

Authorized agents may submit requests on your behalf with proof of authorization.

16. Children's privacy

The Service is a business tool intended for users 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18.

If you believe a child has provided us information, contact support@complianceanvil.com and we will delete it.

17. United States processing

We are a United States company and we store and process information in the United States.

If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your location. Where a cross-border transfer mechanism is required by your local law, contact us and we will discuss what is available.

Our transactional email is delivered through infrastructure that may route messages through providers operating in other regions; message content is limited to what the notification requires.

18. Changes to this policy

We may update this policy. When we do, we will change the "Last updated" date above.

For material changes — for example a new category of sharing or a materially different use of your information — we will provide reasonable advance notice by email to the address on your account or by a notice in the Service before the change takes effect.

Continuing to use the Service after the effective date means you accept the updated policy.

19. Contact us

Forge Technology Solutions LLC — veteran owned and operated in the United States, publisher of ComplianceAnvil™.

  • Privacy, access, and deletion requests: support@complianceanvil.com
  • Website: https://www.complianceanvil.com

Please include your organization name and account email so we can verify and respond accurately.

Questions about this document

Contact Forge Technology Solutions LLC at support@complianceanvil.com. ComplianceAnvil is a veteran owned and operated business in the United States.