Trust and privacy summary
Know what is retained, what is temporary, and where CMMC boundaries sit.
This page is the buyer-facing summary for the $4,800 USD ComplianceAide CMMC readiness package.
It is intended to remove ambiguity before purchase. Contract terms, data-processing addenda,
SOC 2 status, references, and counsel-reviewed privacy terms can be reviewed before payment.
Retention
- Paid workspace artifacts such as readiness reports, SSP planning files, POA&M planning files, and uploaded evidence extracts are retained for the active license term unless the customer requests deletion or exports and closes the workspace.
- Transient AI processing records, temporary upload files, troubleshooting traces, and short-lived operational buffers may be purged on a much shorter operational schedule.
- A seven-day purge statement must not be read as deletion of all paid workspace deliverables every seven days.
Hosting
- The commercial ComplianceAide portal and this checkout path are hosted on Microsoft Azure commercial services.
- The commercial readiness package is operated from US Azure regions; as of June 19, 2026, the portal resource group is East US and the Function App reports East US 2.
- The public checkout and commercial readiness workspace are not described as FedRAMP-authorized, Azure Government, GCC High, GovCloud, or a CUI enclave on this page.
- Public marketing pages may use separate static hosting or content systems, but customer workspace processing for this package is not described as AWS-hosted on this page.
- Customers who require tenant-specific architecture details should request a vendor review packet before purchase.
Privacy and legal review
- ComplianceAide does not rely on invalidated legacy transfer frameworks as a current transfer basis.
- Buyers who need SCCs, DPF status, a DPA, subprocessors, breach-notification terms, insurance details, MSA terms, BAA path, or references can review the Security, SOC 2, and References Packet before submitting payment.
- Do not submit passwords, export-controlled technical data, CUI, or contract-sensitive files through the public checkout form.
- Request written confirmation before sending regulated evidence to any AI-assisted workflow; do not assume public OpenAI, Azure OpenAI, or other model processing is approved for CUI without that written path.
Security and SOC 2 status
- ComplianceAide aligns security practices with recognized security frameworks and reviews those practices as services and obligations evolve.
- This page does not claim SOC 2 certification, ISO 27001 certification, assessor acceptance, or third-party audit completion.
- Use the Security, SOC 2, and References Packet to review current buyer-safe posture and request supporting materials before purchase.
Resilience
- Operational recovery targets are reviewed per customer and deployment path. Placeholder recovery values are not buyer commitments.
- Readiness documents are designed to be exportable so customers can retain their own copy outside ComplianceAide.
- For procurement review, request current RTO/RPO, backup, and incident-response commitments before purchase.
CUI, GCC High, FedRAMP, and government enclave boundary
The public checkout page is for starting a readiness engagement and should not receive CUI. The commercial
portal is a non-CUI readiness planning workspace unless your contract or security officer approves a
separate written handling path. ComplianceAide does not present this public checkout path as FedRAMP
Moderate equivalent, Azure Government, GCC High, GovCloud, FIPS-validated, or DFARS 252.204-7012 CUI
storage. If your requirement includes CUI, CDI, export-controlled data, FedRAMP equivalency, FIPS-validated
cryptography, incident-reporting flow-downs, or a government enclave, contact
info@thecomplianceaide.com before purchase so the correct
hosting, onboarding, model-processing, and evidence-handling path can be confirmed in writing.
Request our security package before payment if you need current architecture, data-processing, subprocessors,
incident-response, insurance, DPA, BAA, SOC 2 / ISO 27001 status, or CUI boundary materials.
Start with the Security, SOC 2, and References Packet.