Data Handling
Compex is designed to reduce default raw-data handover by moving approved execution toward protected data under policy. Data handling must still be scoped for each sandbox or pilot environment.
Principles
- Keep protected data owner-controlled where possible.
- Define allowed workloads before execution.
- Separate owner, processor, reviewer, and user roles.
- Record evidence for policy, approval, execution, and outputs.
- Release only controlled outputs according to the agreed scope.
What this means
For business readers, Compex is not “send us your data.” The intended pattern is “define the work, approve the boundary, run under governance, and inspect evidence.”
Current status
Public sandbox data is synthetic. Pilot data handling depends on the client environment and must be documented before pilot execution.
Limitations
Compex does not independently classify client data, determine lawful basis, or guarantee that outputs are non-sensitive. Those decisions require client-specific review.
Read known limitations
Review the boundaries of current claims before planning a pilot.
Last updated on