Security & Trust
Everything your reviewer asks for, in one place.
Subprocessors, retention windows, security controls, transfer arrangements, incident response and the person who answers. Nothing here is a certification; controls that are not yet formalised are labelled as such.
Compass Performance Consulting, Inc. is the legal entity behind this site; Compass Performance, Inc. and Compass Performance are the names it trades under. They are the same organization. Data governance version 1.0.0, effective 19 August 2026. Privacy notice version 2026-08-03. This page consolidates practice already published in the privacy notice, the IT Security Policy, the Personal Data Notice and the System Use & Data Processing Agreement. Those documents remain the governing texts.
Subprocessors
These providers may process personal data on Compass’s instruction under a data processing agreement. Each is engaged for the stated purpose only.
| Subprocessor | Purpose | Location |
|---|---|---|
| HubSpot | Client relationship records, meeting scheduling, and follow-up correspondence. | United States / European Union |
| Supabase (Lovable Cloud) | Application database, authentication, and encrypted file storage for the platform. | United States |
| Lovable | Hosting, delivery, and transactional email for this site and its instruments. | United States / European Union |
| ScoreApp | Complimentary Compass Profiles completed on the provider's own scorecard platform. | United Kingdom |
| Positive Intelligence | Licensed PQ® Mental Fitness program delivery for enrolled participants. | United States |
| YouTube (Google) | Video playback, loaded only when you choose to play a video. | United States / European Union |
| Publishing Compass articles and recording share clicks you initiate. | United States / European Union |
EU transfer arrangements
Transfers of personal data outside the European Economic Area rely on EU Standard Contractual Clauses or an adequacy decision, as recorded per provider below.
No Article 27 representative in the European Union has been appointed; European enquiries are answered directly by the contact below.
| Subprocessor | Transfer safeguard |
|---|---|
| HubSpot | EU Standard Contractual Clauses under HubSpot's data processing agreement. |
| Supabase (Lovable Cloud) | EU Standard Contractual Clauses under the provider's data processing agreement. |
| Lovable | EU Standard Contractual Clauses under the provider's data processing agreement. |
| ScoreApp | UK adequacy decision; the provider's own notice applies to data entered there. |
| Positive Intelligence | EU Standard Contractual Clauses under the licensor's terms. |
| YouTube (Google) | EU Standard Contractual Clauses under Google's terms. |
| EU Standard Contractual Clauses under LinkedIn's terms. |
Data subject requests are answered within 30 days. Use the data rights request form.
Retention
Retention is enforced nightly by an automated job. When a window closes, identifying fields are irreversibly redacted or the record is deleted. Client engagement records follow the engagement agreement.
| Data | Window | What happens |
|---|---|---|
| Assessment and diagnostic submissions (Mental Fitness, FOUNDATION, and related instruments) | 24 months from submission | Name, email, phone, and company are irreversibly redacted; anonymous scores remain for benchmarking. |
| Outreach and campaign responses | 24 months from response | Contact detail redacted; the response itself is kept anonymously. |
| Forum fit profiles and uploaded resumes | 12 months from application | Contact detail redacted and the uploaded document reference deleted. |
| Measurement events (page views, CTA clicks, scroll depth, share clicks) | 24 months from the event | Deleted outright. |
| Access and security logs (hashed visitor fingerprints, gate attempts) | 12 months from the event | Deleted outright. |
| Compass 360° feedback and client engagement records | Per the engagement agreement, then on request | Returned or destroyed at the client's instruction; individual ratings are never released by name outside Compass administration. |
Security controls
The control register as it stands. “Being formalised” means the control operates but the written procedure and evidence schedule are still being documented — it is stated rather than implied. Full detail sits in the IT Security Policy.
| Domain | Control | Status | Detail |
|---|---|---|---|
| Encryption | Data encrypted in transit and at rest | In place | TLS between browser, platform and providers; encryption at rest by the hosting and database platform. |
| Access control | Named accounts, server-side roles, two-step administrator sign-in | Being formalised | Implemented in the platform; the written access-review procedure and evidence schedule are being documented for client review. |
| Logging | Audit record of access, refusals, report release, export and print | Being formalised | Recorded by the platform; the retention window and the client extract format are being documented. |
| Retention | Client-directed retention with a documented default | Being formalised | Default of 24 months stated in Section 4.4; per-engagement schedules are being written into engagement agreements. |
| AI use | Draft-only AI use with recorded human verification | Being formalised | Section 4.5 states the operating rule; the provenance record and verification sign-off are being standardised across every AI-assisted artifact. |
| Incident response | 72-hour notification to the client system owner | Being formalised | Section 8 states the commitment; the tested runbook is being written. |
| Subcontractors | Written processing terms with each provider; notice before a new one is used | Being formalised | Provider list published in the Personal Data Notice; the change-notice step is being formalised. |
| Business continuity | Provider backup plus an independent document record of truth | Being formalised | Backups run at the provider; restore testing is being scheduled. |
Incident response
Access to client material is restricted by role and logged. If a breach affecting personal data occurs, Compass notifies the relevant supervisory authority within 72 hours of becoming aware, notifies the client system owner within the same window, and informs affected people without undue delay where the risk to them is high.
Report a suspected vulnerability, exposure or misdirected record to skopecky@compassperformanceinc.com. Include what you observed and when; do not include the affected personal data in the message.
Terminology
The names used across this site and in the governing documents, in the order they sit: Compass Performance → Compass Enterprise Architecture™ → CompassOS™. Select a term for its definition.
The firm.
Compass Performance is the firm you engage. It is not the name of the methodology or of the technology.
The methodology — how the enterprise is architected to operate, lead, execute and renew.
Compass Enterprise Architecture™ is the architecture — the thinking and structure. It is not software.
CompassOS™ is the AI-enabled technology layer beneath the work — it enables leaders to assess, execute, measure and renew the architecture.
CompassOS™ is not a service, an offering or something to understand before engaging. It carries the architecture; it does not replace it.
How the enterprise is built, focused, led and grown — the structural core of the architecture.
FOUNDATION™ · SIMPLIFY™ · LEAD™ · GROW™
How the enterprise analyzes, refines and commits again, so the architecture keeps working after installation.
ARC™
The disciplines that carry enterprise execution across the architecture rather than sitting inside one part of it.
Front-to-Back 80/20™ · Change & Transformation · Program & Project Management
Terminology changes
When a governed name changes, the change is recorded here with the date it was published. Entries are added, never rewritten.
29 August 2026 — Terminology glossary and change record published.
- The three-level hierarchy — firm, methodology, technology layer — is now stated in one glossary rather than explained page by page.
- The Security & Trust page carries the glossary, so an IT or legal reviewer can map the names used in the governing documents in one place.
- Future naming changes are recorded on this list with the date they went live.
19 August 2026 — Naming hierarchy normalized across the public site.
- Compass Enterprise Architecture™ is the methodology name on every public surface, spelled from one register.
- CompassOS™ is named only as the AI-enabled technology layer beneath the work — never as a service, a nav item or a headline.
- The eight components keep the three governed groupings: the Core Architecture, the Renewal Engine, and Enterprise Execution Disciplines.
- The earlier operating-system spelling of the methodology was retired to avoid collision with an unrelated third-party framework.
Ask a governance question or report an incident
Every enquiry below reaches a named governance contact rather than a general inbox. If you would rather write directly, email skopecky@compassperformanceinc.com or call 224.307.0912.
Contact
Security questions, IT review requests, subprocessor queries and incident reports go to one address.
- Email skopecky@compassperformanceinc.com
- Telephone 224.307.0912
- 500 West Silver Spring Drive, Suite K-200, Glendale, Wisconsin 53217, United States
This document is Compass's standard operating position, not legal advice. Compass is not your counsel. Have your own legal and IT functions review it before execution, and where an executed master agreement exists, that agreement controls.
Not sure where to start?
Three questions, and we point you to the right instrument.
Under a minute. From this page, most leaders begin with The organization.