Compli.ai is built around a single guarantee: the records of your CUI program never leave your tenant. There is no compli.ai cloud behind this product, no content delivery network, and no analytics endpoint receiving anything. Everything the hub needs to run lives in your own SharePoint site, inside the boundary you already defend for the CUI itself.
The hub talks only to your own SharePoint site, through Microsoft's standard client APIs, as the signed-in user. Every asset it needs, including scripts, styles, and charts, ships inside the app package, and nothing is fetched from the internet at runtime.
There is no compli.ai backend behind this product. The system of record for your CUI program is the set of 23 SharePoint lists and libraries in your site, owned and governed by you.
The hub adds no logins, no API keys, and no service accounts. SharePoint permissions are the authorization model, using three site groups on your existing Entra identities.
The current version removed every integration that required a stored secret. There is no credential in the product for an attacker to steal.
Your CUI inventory says what you hold, where it lives, and how it reaches you. Your SSP statements describe exactly how you protect it, your objective verdicts record where that protection has been verified, your POA&M items enumerate where it is not yet complete, and your evidence artifacts document the environment around it. Anyone who reads that material has a detailed picture of your CUI and its defenses, which is why it deserves the same handling discipline you apply to the CUI itself. Under DFARS 252.204-7012 and CMMC scoping, an external service holding that data becomes part of your compliance conversation.
Because the program sits inside the same assessed boundary you already defend, there is no new external service to scope, no flow-down analysis for a GRC vendor, and no data-processing addendum to negotiate. Your existing Microsoft 365 controls, including Conditional Access, DLP, retention, eDiscovery, and Purview labels, apply to your program records automatically, because those records are simply your own content.
The platform runs in Microsoft 365 Commercial, GCC, GCC High, and DoD environments, with the same features throughout, including the sovereign clouds many contractors use to hold CUI. Because nothing phones home, there is no commercial-endpoint dependency to break in a sovereign environment, and where Microsoft routes its own APIs to sovereign endpoints, the platform follows automatically.
The Environment Monitor is the only capability that reaches beyond the SharePoint site, and it reaches only into your own Microsoft cloud, read-only, to read Intune, Entra ID, Secure Score, and Conditional Access, so you can capture proof that the safeguards around your CUI are operating. Its guardrails are built in.
A freshly deployed tenant makes zero external calls until an administrator explicitly enables the monitor.
The permissions are declared in the package and approved once by your admin in the SharePoint admin center, and they run as the signed-in user. Someone who cannot read sign-in logs in the Entra portal does not gain that right through the hub.
The monitor uses the viewer's own identity. There is nothing to rotate, leak, or revoke.
Enabling or disabling the monitor, along with every evidence snapshot it saves, adds an entry to the change log, so the assessor-visible record shows when monitoring came online and what it produced.
We're glad to walk your security and compliance staff through exactly how the platform works and where the records of your CUI program live.