Frequently asked questions

ComplyEasy AI FAQ

Clear answers about the platform, its AI capabilities, supported compliance frameworks, security architecture, integrations, pricing, and support. Browse by topic below, or jump straight to the area you care about.

Getting started

What the platform is, who it serves, and how onboarding works.

What is ComplyEasy AI?

ComplyEasy AI is an AI-powered compliance automation platform that helps organizations achieve and maintain continuous readiness across global regulatory standards. It automates evidence collection, control monitoring, risk assessment, and audit preparation using autonomous AI agents and machine learning.

Who is ComplyEasy AI for?

It is built for startups preparing for a first certification such as SOC 2 or ISO 27001, scale-ups managing several frameworks at once, and enterprises that need advanced automation, custom frameworks, or on-premise deployment. It is a strong fit for regulated industries including FinTech, HealthTech, SaaS, and AI companies, as well as organizations subject to the EU AI Act, DMA, or DSA.

How quickly can I get started?

Signing up takes a couple of minutes, and AI-assisted framework setup typically takes 15 to 30 minutes. Automated evidence collection can begin within the first day, an initial compliance dashboard comes together within a few days, and audit-ready status generally follows over 30 to 90 days depending on the framework and your current maturity.

Do you offer a free trial?

Yes. A 3-day free trial is available with no credit card required. It includes Foundation-tier capabilities such as three compliance frameworks, up to 10 users, automated evidence collection, the AI Risk Analyzer, and basic reporting.

What happens after my trial ends?

The trial ends automatically after three days. You can upgrade to a paid tier to continue with all of your data preserved, or contact the sales team to request an extension for evaluation purposes.

Pricing and billing

Tiers, tier changes, payment methods, and refunds.

How does your pricing work?

Pricing is tier-based with flat annual rates. Foundation is $8,500/year for up to 10 users and three frameworks. Essentials is $17,000/year for up to 100 users and 10 frameworks. Growth ranges from $42,500 to $51,000/year for 100 to 1,000 users and up to 50 frameworks. Visionary ranges from $68,000 to $170,000/year with unlimited users and frameworks. Growth and Visionary are quoted by the sales team.

Can I switch tiers?

Yes, at any time. Upgrades take effect immediately with prorated billing. Downgrades take effect at the next billing cycle, and your current features remain active until then. There are no penalties for switching tiers.

What payment methods do you accept?

Major credit and debit cards (Visa, Mastercard, Amex, Discover) are accepted for all customers. ACH bank transfer is available for US-based organizations, and wire transfer, purchase orders with NET 30 terms, and invoice payment are available for enterprise, Growth, and Visionary customers.

What is your refund policy?

You can cancel during the trial period with no charges. On annual plans, a prorated refund for unused months is available after the first 30 days. Enterprise contracts follow their negotiated terms.

Platform and features

Core capabilities, autonomous operations, and evidence automation.

What compliance frameworks does the platform support?

The platform includes more than 50 built-in frameworks spanning security (SOC 2 Type I and II, ISO 27001, ISO 27701, NIST CSF, CIS Controls), privacy (GDPR, CCPA, HIPAA, PIPEDA, LGPD), cloud (FedRAMP, StateRAMP, TISAX), AI/ML (EU AI Act, NIST AI RMF, ISO 42001), and industry standards (PCI DSS, HITRUST, 21 CFR Part 11, ITAR), plus the EU Digital Markets Act and Digital Services Act. Custom frameworks are available as an add-on with the Growth tier and above.

What is aCOS (Autonomous Compliance Operations System)?

aCOS is the autonomous compliance engine. It monitors your infrastructure continuously with AI agents, detects compliance drift in real time, remediates issues automatically when it is safe to do so, learns from your environment to adapt policies, predicts emerging risks, and orchestrates remediation workflows. It is available in the Essentials tier and above, or as a separately billed add-on.

How does automated evidence collection work?

AI agents collect evidence from cloud infrastructure (AWS, Azure, GCP), SaaS tools (GitHub, Slack, Jira, Okta, Google Workspace), security tools, monitoring systems, and HR systems. You connect integrations through OAuth, API keys, personal access tokens, or read-only access; the AI maps evidence to controls automatically; evidence is collected on a daily, weekly, or monthly schedule; and a versioned, immutable audit trail is maintained for every item.

Can I customize frameworks and controls?

Yes, with customization scaling by tier. Foundation lets you add custom controls to existing frameworks, Essentials lets you modify control requirements and evidence mappings, Growth lets you build custom frameworks from scratch, and Visionary adds full Compliance-as-Code using OPA/Rego policies.

Can I export my data?

Yes. You own your data and can export it at any time, with unlimited exports, in JSON, CSV, PDF, or XML. Exports cover evidence and attachments, risk assessments, control mappings, audit history, policies and procedures, and reports. The platform also supports data portability to help you migrate elsewhere without vendor lock-in.

AI and automation

How the AI works, what it automates, and where humans stay in the loop.

What AI features are included?

Every tier includes core AI features: the AI Risk Analyzer for automated risk assessment and scoring, the AI Control Mapper for mapping evidence to controls, and a natural-language AI chatbot. Growth adds advanced AI such as predictive risk modeling, AI Red Team simulation, smart remediation, a compliance digital twin, and neuro-symbolic reasoning. Visionary adds federated learning, homomorphic encryption, multi-modal processing, and full AI governance.

Can AI replace my compliance team?

No, but it augments your team significantly. The AI handles routine work such as evidence collection, control monitoring, risk scoring, report generation, and anomaly detection, freeing people to focus on strategic decisions, auditor relationships, policy design, exception approvals, and program leadership.

What is AI Red Team?

AI Red Team simulates adversarial review of your compliance program. It identifies gaps an auditor would likely catch, models how controls could be bypassed, tests your posture under stress, and generates reports on what to fix. It is simulation only with no actual attacks performed, and it is available in the Growth tier and above.

How does the AI chatbot work?

The chatbot answers natural-language compliance questions against your own data, such as listing open access-control risks, identifying missing evidence for a specific SOC 2 control, or generating an executive risk report. It only accesses your organization’s data, which is never shared across organizations, and it is available in all tiers.

Do you use customer data to train AI models?

Customer data is never used for AI training without explicit opt-in. Where supported, zero-knowledge techniques allow compliance to be verified without exposing the underlying data, and you control data access permissions and encryption keys.

Compliance frameworks

Timelines, running multiple frameworks, and staying current with updates.

How long does SOC 2 certification take?

With ComplyEasy AI, setup and gap assessment usually take a few weeks, remediation runs roughly 4 to 12 weeks depending on the gaps found, and SOC 2 Type II requires a 3 to 6 month observation period before the audit itself. End to end this commonly lands in the 4 to 9 month range, compared with the longer timelines typical of fully manual programs.

Can I pursue multiple frameworks simultaneously?

Yes, and this is a core strength of the platform. Many frameworks share a large portion of their controls, so the AI maps shared controls automatically, reuses evidence across frameworks, flags the unique requirements of each, and generates framework-specific reports. The number of concurrent frameworks scales with your tier.

What is the difference between SOC 2 Type I and Type II?

SOC 2 Type I is a point-in-time assessment that evaluates whether controls are designed appropriately. SOC 2 Type II evaluates how effectively those controls operate over a 3 to 12 month observation period and is the report most enterprise buyers expect. The platform supports both Type I and Type II with continuous control monitoring.

How do you handle framework updates?

Framework changes are tracked centrally. When a standard is revised, new controls are added to your instance, you receive advance notice, and AI assists the transition while preserving and remapping existing evidence. This has covered updates such as the ISO 27001:2022 revision, NIST CSF 2.0, and the EU AI Act, so you stay current without manual framework maintenance.

EU regulations

EU AI Act, DMA, DSA, and GDPR coverage.

Do you support the EU AI Act?

Yes. The platform helps you classify AI system risk, generate technical documentation for high-risk systems, run conformity assessments, manage required transparency disclosures and labeling, operate human-oversight governance workflows, and monitor data quality and accuracy. It is included with the Visionary tier and available as an add-on for lower tiers.

What about the Digital Markets Act (DMA)?

The platform supports DMA obligations for digital gatekeepers, including gatekeeper assessment, mapping of the DMA obligations, documenting interoperability and data portability, monitoring self-preferencing and data-combination practices, and generating compliance reports. It is available in the Visionary tier or as a Growth-tier add-on.

And the Digital Services Act (DSA)?

The platform provides a DSA toolkit covering content-moderation tracking, notice-and-action workflows, automated transparency reporting, systemic-risk analysis for very large platforms, recommender-system documentation, advertising transparency, and user-rights request handling. It is available in the Visionary tier or as a Growth-tier add-on.

How does the platform help with GDPR?

The GDPR toolkit helps you track processing activities, manage consent, handle data-subject requests for access, deletion, and portability, generate a Record of Processing Activities, conduct Data Protection Impact Assessments, and document your legal basis for processing.

Security and privacy

Architecture, data residency, access controls, and customer-managed keys.

How is the platform secured?

The platform is built on a zero-trust architecture with device-trust verification, end-to-end encryption (AES-256 at rest and TLS 1.3 in transit), and support for zero-knowledge proofs to verify data without exposing it. Bring Your Own Key lets you control encryption keys, and continuous security monitoring backs the environment.

Where is my data stored?

By default, data is stored in multi-region cloud storage with geo-replication for disaster recovery. You can choose regional isolation to keep data in specific regions, deploy on-premise within your own infrastructure (Visionary tier with the on-premise add-on), or run a hybrid of cloud and on-premise to meet residency requirements for regulations such as GDPR and CCPA.

Do you have access to my data?

Access follows a minimal-access principle. Production data has zero standing access and requires breakglass approval, support access requires explicit customer permission and is logged and audited, and customer data is never used for AI training without opt-in. With zero-knowledge techniques, compliance can be verified without the platform seeing your underlying data.

Can I use my own encryption keys?

Yes. Bring Your Own Key is available in the Growth tier and above, with support for AWS KMS, Azure Key Vault, Google Cloud KMS, and HashiCorp Vault. Keys can be rotated automatically or manually, and revoking a key renders the associated data unreadable. BYOK can be combined with client-side encryption for a zero-knowledge posture.

Integrations

Supported tools, connection methods, and building your own.

What integrations do you support?

The platform offers more than 80 pre-built integrations across cloud providers (AWS, Azure, GCP, Oracle Cloud, IBM Cloud), security and compliance tools (Wiz, Vanta, Snyk, Crowdstrike, Qualys, Tenable), DevOps (GitHub, GitLab, Bitbucket, Jenkins, CircleCI, Terraform), communication (Slack, Microsoft Teams, PagerDuty, Opsgenie), HR and identity (Okta, Azure AD, Google Workspace, BambooHR, Workday), ticketing (Jira, ServiceNow, Linear, Asana), and monitoring (Datadog, Splunk, Elasticsearch, Prometheus, Grafana).

How do integrations work?

Integrations connect through one-click OAuth where available, read-only API keys or personal access tokens, or webhooks for real-time events, and they are agentless with no software to install. The platform requests the minimum permissions needed, preferring read-only access.

Can I build custom integrations?

Yes. A Webhook API is available on every tier for sending evidence, triggering workflows, and querying compliance data. The no-code Integration Builder (Growth tier and above) connects any REST API with visual field mapping, and full programmatic access via REST and GraphQL is available on the Visionary tier. Professional services can also build integrations for you.

What if you don’t support my tool?

You can use generic options such as the Webhook API, CSV import, or email forwarding, request the integration on the public roadmap, build it yourself with the Integration Builder or SDK, or have the professional services team build it. New integrations are added regularly based on customer demand.

Technical questions

Uptime, deployment, rate limits, and developer interfaces.

What is your uptime SLA?

Uptime commitments scale by tier: 99.5% for Foundation and Essentials, 99.9% with SLA credits for Growth, and 99.95% with SLA credits for Visionary. When an uptime target is missed, monthly service credits apply, and a public status page is available.

Can I deploy on-premise?

Yes. On-premise deployment is available on the Visionary tier with an on-premise add-on. It runs on a Kubernetes cluster with PostgreSQL, Redis, and S3-compatible storage, ships as Docker containers with Helm charts, and is supported by a dedicated on-premise team. A hybrid mode keeps sensitive data on-premise while using the cloud for AI processing.

What are your API rate limits?

Hourly API rate limits scale by tier, from 1,000 requests per hour on Foundation up to custom limits on Visionary, with a short-burst allowance above the base rate. The limit is a soft limit returning HTTP 429 responses rather than a hard cut-off, and there are no overage fees.

Do you have a CLI or SDK?

Yes. The platform provides a documented REST API, a GraphQL API on Growth and above with real-time subscriptions, a command-line interface, and SDKs for JavaScript/TypeScript, Python, Go, and Java. A Terraform provider lets you manage compliance as infrastructure-as-code.

Support and services

Support tiers, professional services, training, and migration help.

What support do you provide?

Support scales by tier. Foundation includes email support, a knowledge base, and a community forum. Essentials adds business-hours chat and monthly office-hours webinars. Growth adds priority support, quarterly business reviews, and a dedicated Slack channel. Visionary adds 24/7 phone support, a critical-response SLA, a dedicated Customer Success Manager, and a private Slack channel with engineering.

Do you offer professional services?

Yes. The services team provides compliance consulting (gap assessments, remediation planning, policy development, audit preparation, framework selection), implementation services (onboarding, integration setup, custom framework building, workflow design, team training), and managed services such as Compliance-as-a-Service, a virtual CISO, and continuous monitoring.

How do I get training?

Self-paced video tutorials, interactive walkthroughs, documentation, and webinar recordings are available to all tiers. Essentials and above add live webinars and office hours, and Growth and above add custom on-site or virtual sessions, team workshops, and an admin certification program.

Can you help me prepare for an audit?

Yes. The audit-preparation program covers pre-audit work such as AI Red Team review, gap remediation, evidence packaging, and a mock audit; in-audit support with a secure auditor portal, instant evidence search, and question tracking; and post-audit help with response generation, finding remediation, and continuous monitoring to prevent recurrence.

What if I need help migrating from another tool?

Migration support is included for all tiers and typically takes a week or two. The team imports your data from tools such as Vanta, Drata, or Secureframe, handles data mapping and validation, and runs the platform in parallel during the transition for no downtime. Growth and above add a dedicated migration engineer and custom data transformation.

Additional questions

White-labeling, multi-tenancy, and enterprise add-ons.

Can I white-label ComplyEasy AI?

Yes. White-labeling is available on the Visionary tier and includes custom branding (logo, colors, and domain), removal of ComplyEasy AI branding, custom email templates, and custom report headers and footers. It is a common fit for managed service providers, compliance consultants, and resellers.

Do you support multi-tenancy?

Yes. Multi-tenant features let you manage multiple organizations from a single account, view consolidated cross-organization dashboards, apply role-based access with separate permissions per organization, and consolidate billing into a single invoice. This suits consultancies, managed service providers, and holding companies.

What enterprise add-ons are available?

Add-ons include custom frameworks at $2,997/year per framework (Growth and Visionary), on-premise deployment at $3,200/year (Visionary), custom fine-tuned AI models at $1,920/year (Visionary), and a dedicated vCISO service at $9,997/year for 10 consulting hours per month (all tiers). An audit-bundling option provides pre-negotiated rates with a partner network of certified audit firms.

Still have questions?

Explore the platform on a free trial, or dig deeper into a specific framework, integration, or capability across our resources.