Security Policy

Last Updated: July 6, 2026

LetsCompl.ai is committed to providing secure compliance middleware for B2B applications and autonomous AI agents. Security is built directly into our product architecture, operational controls, and coding guidelines.

1. Data Architecture & Zero Retention

Our gateway proxy uses a strict zero-retention policy for evaluated payloads:

  • In-Memory Processing: Payloads are analyzed in-memory and immediately destroyed. Raw transaction prompts or responses are never saved to persistent storage.
  • Local Redaction Option: For maximum security, developers can run our local SDK to scrub PII and PHI before they leave their private network.

2. Encryption Controls

  • In Transit: All API requests, dashboards, and webhook alerts are encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
  • At Rest: Sensitive database credentials, user accounts, and billing metadata are encrypted using industry-standard AES-256 encryption.

3. API Security & Key Scopes

We provide secure management of API credentials:

  • API keys can be scoped to specific tasks, ensuring that compromised keys have limited blast radiuses.
  • Key creation and deletion occur via atomic transactions.
  • Keys can be regenerated instantly in the developer dashboard if rotation is required.

4. Compliance & Isolation

  • Sandbox Isolations: Evaluating untrusted code or rulesets happens in sandboxed environments, isolating operations from the core gateway code.
  • Rate Limiting: Standard rate limits are enforced at the network edge to prevent denial-of-service (DoS) attempts against downstream LLM integrations.

5. Reporting Vulnerabilities

If you discover a security vulnerability, please report it directly to our security team. We take all reports seriously and will work to triage and resolve issues quickly.

  • Email: security@letscompl.ai
  • Mailing Address: letscomplai, inc., c/o AKVentures LLC, 1660 International Dr, Suite 600, McLean, VA 22102