Security & Trust
Clear access.
Traceable evidence.
Informed review.
Make a decision based on specific controls and operating requirements. This page describes the implemented service and the commitments that are agreed separately with each customer.
CONTROL AT EVERY HANDOFF01Access
Workspace roles and scoped API keys
02Evidence
Source snapshots and review history
03Connections
Credential handling and delivery controls
Explore the implemented controls ↓ Implemented controls
Access and activity stay connected to the workspace.
The production-equivalent release suite validates role enforcement, workspace isolation, signed delivery, MCP authorization and billing reconciliation before publication.
Site access
IMPLEMENTEDThe marketing website is public. Customer workspaces require WorkOS sign-in, and server-side membership checks restrict each workspace to its authorised members.
Customer configuration
Agree any customer-specific enterprise sign-in, domain or provisioning requirements during onboarding.
Workspace roles
IMPLEMENTEDOwner, admin, analyst and viewer checks restrict records and administrative operations.
Customer configuration
Confirm user provisioning, offboarding and the permission model for your team.
API credentials
IMPLEMENTEDAPI keys have scopes, expiry and revocation. Stored API keys are hashed, and generated secrets are shown once.
Customer configuration
Confirm permitted data use, minimum scopes and rotation responsibilities.
Source connections
IMPLEMENTEDProvider credentials are encrypted when stored, using deployment configuration kept outside the source repository.
Customer configuration
Confirm credential ownership, approved providers and permitted datasets.
Review evidence
IMPLEMENTEDSource snapshots, investigation references, prior decisions and an exportable workspace activity log support traceable review.
Customer configuration
Agree retention, export and deletion requirements for your records.
Event delivery
IMPLEMENTEDOutbound webhooks use signatures, bounded retries and delivery tracking. Duplicate source events are rejected by workspace-scoped identifiers.
Customer configuration
Confirm approved destinations, receiver validation and downstream replay handling.
Hosting and data handling
Review the whole service chain.
The site is published through OpenAI Sites using a Cloudflare Worker and D1 storage. Company lists, review records and enquiries are stored by the application. Configured registry and AI connections can send relevant requests and records to their respective providers.
Do not assume a particular data-residency region, backup commitment or AI-provider policy from the hosting platform alone. Request the applicable contractual documentation for your intended use.
Procurement
Bring your requirements into the assessment.
Security documentation
Ask for the applicable access model, hosting arrangements, provider list and incident contact.
Data processing
Agree the responsible entities, purpose, retention, deletion, data transfers and any required processing agreement.
Service operations
Confirm collection frequency, availability commitments, support and recovery requirements. Global Data Intelligence Limited maintains ISO 27001 certification; scope evidence and contractual service commitments are provided during procurement.
Your questions
What to know before you start
Is CompanyDelta SOC 2 or ISO 27001 certified?
CompanyDelta is operated within Global Data Intelligence Limited's ISO 27001-certified information security management framework. Request the certificate, scope and Statement of Applicability during procurement.
Can all workspace users see API keys?
The application restricts key administration to workspace owners and admins. A newly generated secret is shown once; the saved API-key record uses a hash.
Does this site send marketing emails?
The enquiry form stores the request, sends a service confirmation and does not automatically subscribe the sender to marketing.
Can we start with sensitive production data?
Agree your data-processing and security requirements first. Initial enquiries should describe requirements without uploading confidential company lists or personal identity documents.
Start with your company list
See how CompanyDelta fits your review process.
Discuss your countries, company volumes and the questions your team needs to answer.
Book a demo →