Security & Trust

Everything your reviewer asks for, in one place.

Subprocessors, retention windows, security controls, transfer arrangements, incident response and the person who answers. Nothing here is a certification; controls that are not yet formalised are labelled as such.

Compass Performance Consulting, Inc. is the legal entity behind this site; Compass Performance, Inc. and Compass Performance are the names it trades under. They are the same organization. Data governance version 1.0.0, effective 19 August 2026. Privacy notice version 2026-08-03. This page consolidates practice already published in the privacy notice, the IT Security Policy, the Personal Data Notice and the System Use & Data Processing Agreement. Those documents remain the governing texts.

Built from the same register as the page, so it stays in step with updates.

Subprocessors

These providers may process personal data on Compass’s instruction under a data processing agreement. Each is engaged for the stated purpose only.

Subprocessors, purpose and location
SubprocessorPurposeLocation
HubSpotClient relationship records, meeting scheduling, and follow-up correspondence.United States / European Union
Supabase (Lovable Cloud)Application database, authentication, and encrypted file storage for the platform.United States
LovableHosting, delivery, and transactional email for this site and its instruments.United States / European Union
ScoreAppComplimentary Compass Profiles completed on the provider's own scorecard platform.United Kingdom
Positive IntelligenceLicensed PQ® Mental Fitness program delivery for enrolled participants.United States
YouTube (Google)Video playback, loaded only when you choose to play a video.United States / European Union
LinkedInPublishing Compass articles and recording share clicks you initiate.United States / European Union

EU transfer arrangements

Transfers of personal data outside the European Economic Area rely on EU Standard Contractual Clauses or an adequacy decision, as recorded per provider below.

No Article 27 representative in the European Union has been appointed; European enquiries are answered directly by the contact below.

Transfer safeguard by subprocessor
SubprocessorTransfer safeguard
HubSpotEU Standard Contractual Clauses under HubSpot's data processing agreement.
Supabase (Lovable Cloud)EU Standard Contractual Clauses under the provider's data processing agreement.
LovableEU Standard Contractual Clauses under the provider's data processing agreement.
ScoreAppUK adequacy decision; the provider's own notice applies to data entered there.
Positive IntelligenceEU Standard Contractual Clauses under the licensor's terms.
YouTube (Google)EU Standard Contractual Clauses under Google's terms.
LinkedInEU Standard Contractual Clauses under LinkedIn's terms.

Data subject requests are answered within 30 days. Use the data rights request form.

Retention

Retention is enforced nightly by an automated job. When a window closes, identifying fields are irreversibly redacted or the record is deleted. Client engagement records follow the engagement agreement.

Retention windows by data type
DataWindowWhat happens
Assessment and diagnostic submissions (Mental Fitness, FOUNDATION, and related instruments)24 months from submissionName, email, phone, and company are irreversibly redacted; anonymous scores remain for benchmarking.
Outreach and campaign responses24 months from responseContact detail redacted; the response itself is kept anonymously.
Forum fit profiles and uploaded resumes12 months from applicationContact detail redacted and the uploaded document reference deleted.
Measurement events (page views, CTA clicks, scroll depth, share clicks)24 months from the eventDeleted outright.
Access and security logs (hashed visitor fingerprints, gate attempts)12 months from the eventDeleted outright.
Compass 360° feedback and client engagement recordsPer the engagement agreement, then on requestReturned or destroyed at the client's instruction; individual ratings are never released by name outside Compass administration.

Security controls

The control register as it stands. “Being formalised” means the control operates but the written procedure and evidence schedule are still being documented — it is stated rather than implied. Full detail sits in the IT Security Policy.

Control register and status
DomainControlStatusDetail
EncryptionData encrypted in transit and at restIn placeTLS between browser, platform and providers; encryption at rest by the hosting and database platform.
Access controlNamed accounts, server-side roles, two-step administrator sign-inBeing formalisedImplemented in the platform; the written access-review procedure and evidence schedule are being documented for client review.
LoggingAudit record of access, refusals, report release, export and printBeing formalisedRecorded by the platform; the retention window and the client extract format are being documented.
RetentionClient-directed retention with a documented defaultBeing formalisedDefault of 24 months stated in Section 4.4; per-engagement schedules are being written into engagement agreements.
AI useDraft-only AI use with recorded human verificationBeing formalisedSection 4.5 states the operating rule; the provenance record and verification sign-off are being standardised across every AI-assisted artifact.
Incident response72-hour notification to the client system ownerBeing formalisedSection 8 states the commitment; the tested runbook is being written.
SubcontractorsWritten processing terms with each provider; notice before a new one is usedBeing formalisedProvider list published in the Personal Data Notice; the change-notice step is being formalised.
Business continuityProvider backup plus an independent document record of truthBeing formalisedBackups run at the provider; restore testing is being scheduled.

Incident response

Access to client material is restricted by role and logged. If a breach affecting personal data occurs, Compass notifies the relevant supervisory authority within 72 hours of becoming aware, notifies the client system owner within the same window, and informs affected people without undue delay where the risk to them is high.

Report a suspected vulnerability, exposure or misdirected record to skopecky@compassperformanceinc.com. Include what you observed and when; do not include the affected personal data in the message.

Terminology

The names used across this site and in the governing documents, in the order they sit: Compass Performance → Compass Enterprise Architecture™ → CompassOS™. Select a term for its definition.

Terminology changes

When a governed name changes, the change is recorded here with the date it was published. Entries are added, never rewritten.

  1. 29 August 2026Terminology glossary and change record published.

    • The three-level hierarchy — firm, methodology, technology layer — is now stated in one glossary rather than explained page by page.
    • The Security & Trust page carries the glossary, so an IT or legal reviewer can map the names used in the governing documents in one place.
    • Future naming changes are recorded on this list with the date they went live.
  2. 19 August 2026Naming hierarchy normalized across the public site.

    • Compass Enterprise Architecture™ is the methodology name on every public surface, spelled from one register.
    • CompassOS™ is named only as the AI-enabled technology layer beneath the work — never as a service, a nav item or a headline.
    • The eight components keep the three governed groupings: the Core Architecture, the Renewal Engine, and Enterprise Execution Disciplines.
    • The earlier operating-system spelling of the methodology was retired to avoid collision with an unrelated third-party framework.

Ask a governance question or report an incident

Every enquiry below reaches a named governance contact rather than a general inbox. If you would rather write directly, email skopecky@compassperformanceinc.com or call 224.307.0912.

Contact

Security questions, IT review requests, subprocessor queries and incident reports go to one address.

This document is Compass's standard operating position, not legal advice. Compass is not your counsel. Have your own legal and IT functions review it before execution, and where an executed master agreement exists, that agreement controls.

Not sure where to start?

Three questions, and we point you to the right instrument.

Under a minute. From this page, most leaders begin with The organization.