This document describes how Comply protects merchant and end-user data, the cloud foundation the service runs on, and our current certification status. It is intended to support security and governance reviews carried out by merchants and their partners. Our goal is to be transparent about both what we have in place and what is not yet in place.
Certification status
Comply does not currently hold a SOC 2 or ISO/IEC 27001 certification at the application level. We prefer to state this clearly rather than imply otherwise.
That said, Comply is built entirely on Microsoft Azure and inherits the independent controls and certifications of that platform (see section 2). On top of that certified foundation, we operate a deliberately minimalist, network-isolated architecture (section 3) and apply access governance based on the principle of least privilege (section 5).
Comply has obtained NF525 Category B certification in France through an Infocert audit, with certification number 525/0700-1, and fully meets the requirements currently in force in Spain.
Certified cloud foundation
The Comply application runs exclusively on Microsoft Azure infrastructure. Under the shared responsibility model in the cloud, the physical security of data centres, the underlying hardware, and the platform services we use are operated and independently audited by Microsoft.
Microsoft Azure (hosting)
The Azure platform maintains a broad set of independent certifications, including SOC 1, SOC 2, and SOC 3, as well as ISO/IEC 27001. These cover the infrastructure and platform layers on which Comply is built. Your team can verify the current scope and download audit reports directly from Microsoft:
Comply is responsible for the security of everything built on top of that foundation: application code, configuration, data management, and access controls, as described in the sections below.
Shopify (commerce platform)
Comply operates as an application within the merchant's Shopify store. The commerce, payment, and checkout layers are provided and secured by Shopify, which holds the following independent certifications:
PCI DSS Level 1. Shopify holds PCI DSS Level 1 certification, the highest level defined by the PCI Security Standards Council for the secure handling of payment card data.
SOC 2 Type II / SOC 3. Shopify has published SOC 2 Type II and SOC 3 reports covering the security and availability of its service.
Since payment card data is processed within Shopify's PCI-certified environment, Comply has no access to that data. Comply works only with the order and fiscal transaction data required for tax compliance, with no access to raw payment credentials.
Hosting and network architecture
Comply is designed to minimise its attack surface. The guiding principle is that no component is exposed to the public internet except for a single controlled entry point.
Single entry point. All incoming traffic passes through a single Azure Front Door instance, with a managed firewall and rules. No other platform component is accessible from the public internet.
Network isolation. Application services, background tasks, and data stores run inside an Azure private virtual network. Internal components communicate over private networks and have no public access points.
Compute. Application workloads run on Azure App Service and Azure Container Apps inside the isolated virtual network.
Data store. Application and transaction data is stored in Azure.
Layer | Implementation |
Edge / ingress | Single Azure Front Door instance. Single public entry point, protected with Azure managed firewall and rules |
Network | Azure private virtual network. No public access points on internal services |
Compute | Azure App Service and Azure Container App Jobs |
Data | Azure DB and Storage components |
Cloud provider | Microsoft Azure (SOC 1/2/3, ISO/IEC 27001 certified) |
Data protection
Customer and end-user data is protected both in transit and at rest:
Encryption. Traffic to and within the platform is encrypted using TLS. Data at rest is encrypted using Azure-managed encryption across all storage and database services used.
Key and secret management. Cryptographic keys and application secrets are stored in Azure Key Vault, with hardware security module (HSM) backing for sensitive signing operations.
Data residency. Comply operates from Azure regions in the EU, meeting the data residency requirements applicable to European merchants and their end users.
Immutable fiscal archive. Where tax regulations require it, transactional records are retained in write-once, read-many (WORM) immutable storage to preserve their integrity for the required retention period.
All data comes exclusively from Shopify or is entered directly within the Comply application itself, with no third-party data partners or data sharing.
Access control and governance
Managed identities. Azure Managed Identities are used instead of credentials or secrets, enabling secure identity-based authentication that minimises the management and exposure of sensitive credentials.
Restricted administration. Administrative access to the cloud environment is limited exclusively to authorised personnel.
Least privilege. Access to Azure resources is governed through Azure Role-Based Access Control (RBAC), applying the principle of least privilege.
Logging and monitoring. Platform and resource activity is logged using Azure's native monitoring and diagnostics services, ensuring operational visibility, auditability, and investigative capability.
Fiscal compliance context
Comply is a fiscal compliance platform. For regulated merchants, the integrity and auditability of fiscal records is typically a more relevant concern than a generic security certification.
Comply implements the technical requirements of the regimes it supports, covering record integrity (hash chaining), immutability, digital signing, and long-term archiving. These mechanisms are designed to ensure that fiscal records remain complete, sequential, and unalterable, which directly addresses the assurance objectives underlying information security governance reviews.
